Microsoft’s Biggest Patch Tuesday Yet: 570 Vulnerabilities Fixed

Microsoft’s July 2026 Patch Tuesday delivered a record-breaking security update, addressing an unprecedented 570 vulnerabilities across its products and services. Among the fixes were three zero-day flaws, including two that were actively exploited in real-world attacks and one that had already been publicly disclosed.

The update includes 59 critical vulnerabilities, with remote code execution and privilege escalation issues making up a significant portion of the risks. Notable zero-days affected Active Directory Federation Services (AD FS), Microsoft SharePoint Server, and Windows BitLocker. The SharePoint vulnerability could allow attackers to gain elevated privileges remotely, while the BitLocker flaw could expose encrypted data if an attacker had physical access to a device.

Microsoft noted that the sharp increase in discovered vulnerabilities is partly due to its AI-powered security research efforts, which are helping identify weaknesses before cybercriminals can exploit them. Organizations are strongly encouraged to apply these updates promptly to reduce security risks

Spirals Ransomware Strikes Fast, Encrypting Networks in Under 24 Hours

A newly identified ransomware group known as Spirals has demonstrated a worrying ability to compromise and encrypt corporate networks in less than 24 hours. In a recent attack targeting an IT services company in South Asia, the threat actor gained access through an internet-facing IIS server before rapidly moving through the victim’s environment.

According to Symantec researchers, the attackers quickly established persistence, bypassed security controls, extracted credentials, and moved laterally across more than a dozen systems. They also disabled Microsoft Defender and stopped backup, database, and virtualization services to maximize the impact of the attack.

The ransomware itself is written in Rust and uses intermittent encryption to speed up the process, while stolen data is leveraged for double-extortion tactics. Victims are threatened with public exposure of their data within six days if a ransom is not paid.

The attack highlights the growing speed and sophistication of modern ransomware operations, reinforcing the need for vigilant monitoring, rapid detection, and layered security defenses.

Fake Security Alerts Target LastPass and Bitwarden Users

Users of popular password managers LastPass and Bitwarden are being targeted in a new phishing campaign that uses fake security notifications to lure victims to malicious websites. The emails are designed to look like legitimate company communications, claiming that users need to review updated security policies and terms of service.

Recipients are directed to fraudulent websites masquerading as DocuSign, where they are encouraged to download files supposedly compatible with Windows and macOS. Researchers identified suspicious domains such as lastpasscompliance.com and bitwardencompliance.com, both created to appear trustworthy while harvesting user information.

LastPass emphasized that its systems were not breached and that the phishing emails did not originate from its infrastructure. The company also reminded customers that it will never request a user’s master password via email.

The campaign highlights the growing sophistication of phishing attacks and serves as a reminder for users to verify sender addresses, avoid clicking unexpected links, and report suspicious communications immediately

Zoom Urges Users to Patch Critical Account Takeover Flaw

Zoom has issued a warning about a critical security vulnerability affecting its Windows desktop client and software development kit (SDK), urging users to update immediately. The flaw, tracked as CVE-2026-53412, carries a severity rating of 9.8 out of 10 and could allow an unauthenticated attacker to take over user accounts through network access.

According to Zoom, the vulnerability stems from improper input validation and affects multiple Windows-based products, including Zoom Workplace, the Windows VDI Client, and the Meeting SDK for Windows. While the company has not released technical details about the issue, it confirmed that security updates are available to address the risk.

The latest patch release also fixes several high-severity privilege escalation flaws affecting Zoom Workplace, Zoom Rooms, and VDI components. Fortunately, there is currently no evidence that any of these vulnerabilities are being actively exploited in attacks.

Organizations and individual users are strongly encouraged to apply the latest Zoom updates to reduce their exposure to potential account compromise and other security threats.

Analyst Insight

These incidents highlight how organisations face a dual challenge from both software vulnerabilities and increasingly sophisticated threat actors. Microsoft’s July Patch Tuesday addressed a record 570 vulnerabilities, including actively exploited zero-days, while Zoom disclosed a critical account takeover flaw affecting widely used collaboration software. Together, these cases demonstrate the persistent risk posed by vulnerabilities in core business platforms.

At the same time, the Spirals ransomware attack shows how rapidly cybercriminals can move from initial access to full network encryption, completing an attack in less than 24 hours. Meanwhile, phishing campaigns targeting LastPass and Bitwarden users reinforce that credential theft remains a highly effective attack vector.

Collectively, these developments underline the importance of timely patching, robust identity protection, user awareness training, and continuous monitoring. Organisations must be prepared to defend against both technical exploitation and social engineering as attackers continue to combine multiple tactics to maximise impact.


Need help managing patches? Our vulnerability management services help organizations prioritize and deploy patches efficiently while maintaining operational continuity. Contact us for a consultation.