Skip to content
All resources
Cybersecurity Intel · № 14 · 6 – 19 July 2026

AI on both sides: a record 622-CVE patch wall, an exploited AI-agent platform, and China's dual squeeze

Microsoft shipped a record 622 fixes in a single month as AI accelerates vulnerability discovery, an authorization flaw let attackers run other tenants' AI agent workflows in Langflow, and China tightened on multinationals from two directions at once: an amended Cybersecurity Law with extraterritorial fines, and state-linked actors caught using commercial AI tools for espionage.

Published 20 July 2026 By Blacklight Threat Intelligence Classification TLP:CLEAR · Public
622
Microsoft CVEs fixed in one July Patch Tuesday, a program record, with actively exploited zero-days in SharePoint and AD Federation Services
50%+
State-sponsored intrusions into technology and AI firms attributed to China-linked actors in the year to March (CrowdStrike)
RMB 10M
Top penalty under China's amended Cybersecurity Law, which now reaches foreign organisations extraterritorially
42
Countries hit in a single China-linked campaign that breached 50+ telecoms and government agencies via cloud-service abuse

Executive summary

  • AI is now industrialising vulnerability discovery. Microsoft's July Patch Tuesday fixed a record 622 of its own CVEs, more than the previous three months combined and a second successive monthly record, including at least two actively exploited zero-days in on-premises SharePoint and AD Federation Services. Microsoft openly credits AI-assisted scanning for the surge, and defenders cannot keep pace by CVE count alone.
  • The AI toolchain itself became the target. An actively exploited authorization-bypass in Langflow (CVE-2026-55255), an open-source platform for building AI agents, let an authenticated attacker run another tenant's AI workflows, credentials and integrations included. CISA added it to the KEV catalog and set a short federal patch deadline.
  • China tightened on multinationals from two directions. Its amended Cybersecurity Law now carries extraterritorial reach and immediate multi-million-RMB fines, while China-linked actors accounted for more than half of state-sponsored intrusions into technology and AI companies and were observed using Claude Code and the DeepSeek model as operational tooling for espionage.

Key findings

14 July 2026 CVE-2026-56164 / CVE-2026-56155 · ATT&CK T1190 / T1211

Microsoft patches a record 622 CVEs in one month, with SharePoint and ADFS zero-days under active attack

July's Patch Tuesday set a new program record at 622 Microsoft CVEs, larger than the previous three months combined, with 416 in Windows and at least two actively exploited zero-days: an on-premises SharePoint Server flaw and an AD Federation Services flaw at the identity layer. Microsoft has told customers to expect sustained higher volumes as AI-assisted scanning uncovers more issues. The signal for defenders is that triage by exploited status, not CVE count, is now survival-critical.

7 July 2026 CVE-2026-55255 · ATT&CK T1068 / T1528

Exploited authorization bypass lets attackers run other tenants' AI agent workflows in Langflow

CISA added CVE-2026-55255 to the KEV catalog and ordered federal agencies to patch within days. The insecure-direct-object-reference flaw in Langflow, an open-source AI-agent building platform, lets an authenticated attacker execute flows belonging to other users by supplying their flow identifier, exposing the credentials, integrations and data those AI workflows can reach. Researchers observed in-the-wild exploitation from late June; only version 1.9.2 and later are safe.

1 – 10 July 2026 KEV · ATT&CK T1190 / T1505

A KEV wave: SharePoint deserialization plus a cluster of web-CMS upload flaws

Alongside Langflow, CISA added a SharePoint Server deserialization RCE (CVE-2026-45659) exploited in the wild, then a run of unrestricted file-upload flaws in Joomla-ecosystem components (SP Page Builder, Joomlack Page Builder, iCagenda, Balbooa Forms). Upload flaws are web-shell factories: they convert an unauthenticated internet-facing endpoint into code execution, and they entered the exploited catalog within a single week.

In effect through the window Regulatory · China

China's amended Cybersecurity Law reaches foreign firms, with immediate fines and no grace period

The amended Cybersecurity Law, in force since 1 January 2026, is being enforced with materially harder edges: extraterritorial reach over overseas organisations whose activity is deemed to harm China's network security, penalties of up to RMB 10 million for operators and RMB 1 million for responsible individuals, and authority to fine without first requiring corrective action. For any multinational with a China data nexus, a compliance failure is now as material as a breach.

Disclosed in the window Espionage · ATT&CK T1071 / T1550

China-linked espionage scales, using commercial AI tooling and legitimate cloud features

Hunt.io exposed a suspected China-linked espionage operation that paired Claude Code, used as the execution engine, with the DeepSeek LLM as the reasoning model, hitting government systems in Afghanistan, Thailand and Taiwan with reconnaissance staged against US portals. An exposed operator directory held 2,431 files: web shells, cloned government login pages and logs written in Simplified Chinese. Separately, China-linked actors were reported to have breached 50-plus telecoms and government agencies across 42 countries by abusing legitimate cloud-service features, and CrowdStrike attributed more than half of state-sponsored intrusions into technology and AI firms over the past year to China-linked activity.

The broader pattern

  • AI now sits on all three sides of the ledger: discovering vulnerabilities faster than teams can patch them, becoming the attack surface itself (agent platforms, workflow tokens), and serving as operator tooling for state actors.
  • The exploited weakness keeps being an authorization boundary, not a memory bug: an IDOR in an AI platform, an identity-federation service, a cloud provider's legitimate APIs. None of it lives in endpoint telemetry.
  • Geopolitics is now an operational security variable. For any multinational with a China nexus, the threat is simultaneously regulatory (extraterritorial fines with no grace period) and adversarial (state-linked targeting of technology and AI assets).

Sector lens

Technology & AI
AI agent and orchestration platforms are now first-order targets. Inventory every Langflow-class tool for cross-tenant and IDOR exposure, and treat AI flows as privileged workloads with their own credential blast radius.
Multinationals with China operations
The amended Cybersecurity Law's extraterritorial reach and immediate fines make a compliance gap as material as a breach. Map your China data nexus and incident-reporting obligations before an incident forces the question.
Telecoms & government
China-linked campaigns are hiding inside legitimate cloud-service features across dozens of countries at once. Hunt for abuse of trusted cloud APIs and federation, not just malware signatures.
Microsoft on-premises estates
The two exploited zero-days hit SharePoint and ADFS, your identity fabric. In a 622-CVE month, prioritise by exploited/KEV status, not by scanning every CVE equally.
Web / CMS operators
A cluster of unrestricted file-upload flaws entered KEV in one week. Audit every internet-facing upload endpoint and watch for web shells landing in writable web roots.

Suggested priorities to consider

Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.

01

Triage the 622-CVE July release by exploited status, not volume. The two zero-days (SharePoint, ADFS) and the KEV entries are the ones under active attack; ranking by CVE count alone is unwinnable at this scale.

02

Inventory AI agent and orchestration platforms, then patch and segment them. The Langflow IDOR let attackers run other tenants' AI workflows with their credentials; version 1.9.2+ is the fix, and these platforms often hold live integration secrets.

03

If you have any China data nexus, review your exposure to the amended Cybersecurity Law. Extraterritorial reach, RMB-scale fines and no mandatory grace period mean the compliance question is best answered before an incident, not during one.

04

Hunt for abuse of legitimate cloud-service features, not just malware. The China-linked telco campaign hid in trusted cloud APIs across 42 countries; detections keyed only to known-bad files will miss it.

05

Audit internet-facing CMS file-upload endpoints. Multiple unrestricted-upload flaws reached the exploited catalog this fortnight; upload-to-web-shell is the fastest path from exposure to code execution.

These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.

How Blacklight handles this

This fortnight the attack surface, the tooling and the adversary were all AI-shaped, and none of it lived on an endpoint. Blacklight treats AI workflows, machine identities, OAuth grants and cloud-service calls as first-class telemetry: an AI agent flow executing outside its owner's pattern, a federation service issuing tokens it never issued before, or a cloud API abused from new infrastructure is investigated autonomously and correlated against KEV the day entries land, with the full reasoning trail ready for your team, and coverage that is auditable rather than asserted.

Book a Demo

Sources & methodology

Primary public sources this issue: Microsoft Security Response Center July 2026 Patch Tuesday, with reporting from The Hacker News, SecurityWeek, The Record, Malwarebytes, The Register and Cisco Talos · CISA Known Exploited Vulnerabilities alerts (1, 7 and 10 July 2026) and BleepingComputer, Qualys, NVD and Sysdig reporting on CVE-2026-55255 (Langflow) · Greenberg Traurig, Latham & Watkins, Mayer Brown, Covington and A&O Shearman analysis of China's amended Cybersecurity Law · CNBC and CrowdStrike reporting on China-linked targeting of technology and AI firms, Hunt.io original research on the China-linked AI-assisted espionage campaign (TencShell), and Cybersecurity Dive on the cloud-abuse telecoms campaign · MITRE ATT&CK v15 for technique mapping. Figures attributed to vendors or attackers are labelled as such.

Methodology. Findings are compiled from public reporting and Blacklight Threat Intelligence monitoring for the stated window, mapped to MITRE ATT&CK where applicable. Aggregate platform observations, where cited, are anonymised across the Blacklight customer base and never identify a customer environment. Corrections: intel@blacklightai.com.

Related reading

Blacklight AI · Cybersecurity Intel · № 14 TLP:CLEAR
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.