Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Jul 14, 2026·5m

Daily DefSec Brief - Cyber Security News for July 14 2026

Show notes

1. CISA adds 18-year-old Cisco IOS flaw to KEV catalog — CVE-2008-4128 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. Microsoft maps a year of ShinyHunters-style OAuth abuse against Salesforce and SaaS apps — no CVE — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/
3. SAP patches critical NetWeaver memory corruption flaw — CVE-2026-44747 (CVSS 9.9) — Cyber Security News — https://cybersecuritynews.com/sap-security-update-july-2026/
4. ServiceNow fixes unauthenticated sandbox-escape RCE in AI Platform — CVE-2026-6875 — Cyber Security News — https://cybersecuritynews.com/servicenow-remote-malicious-code/
Also mentioned:
- Google and Microsoft pull ModHeader extension over hidden history collector — The Hacker News — https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html
- CISA GitHub leak: admin keys and credentials exposed for six months — Krebs on Security — https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/
- 148 npm packages disguised as school Wi-Fi tools built a browser DDoS botnet — The Hacker News — https://thehackernews.com/2026/07/148-npm-packages-disguised-as-student.html
- Forg365 phishing-as-a-service targets Microsoft 365 — The Hacker News — https://thehackernews.com/2026/07/forg365-phaas-targets-microsoft-365.html