The Signal
Must Know
SharePoint exploitation and machine-key theft
What happened
WatchTowr reported observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments after public exploit code was released, with attackers stealing IIS machine keys for long-term access. [1]
The vulnerability is described as a critical SharePoint remote code execution flaw, and attackers are reported to extract affected servers' IIS machine keys. [1]
Why it matters
WatchTowr's global honeypot network registered successful exploitation attempts on July 20, hours after proof-of-concept exploit release. [1]
Box AI governance and agent security
What happened
Box announced security capabilities intended to give organizations greater control over AI agents working with enterprise content. [2]
The announced capabilities include agent guardrails, oversight of third-party agent activity, prompt injection detection, and access policies based on agent classification. [2]
Why it matters
Box says the capabilities extend its security controls to Box Agents and third-party agents including Claude, ChatGPT, and Gemini. [2]
ThreatDown AI and machine-identity visibility
What happened
ThreatDown announced an expansion of AI and identity security capabilities focused on emerging, unmanaged risks. [3]
The company launched AI visibility, providing security and managed service provider teams with an inventory of AI tools operating across their environments. [3]
Why it matters
The source characterizes governance of non-human identities as addressing exposure points associated with service accounts, API tokens, OAuth credentials, and machine identities. [3]
Lookout mobile application vulnerability analysis
What happened
Lookout announced the Mobile Software Exposure Center (MSEC), integrated natively into its Mobile Endpoint Security platform. [4]
The source states that MSEC is intended to continuously detect, validate, prioritize, and remediate exploitable vulnerabilities across an organization’s mobile software ecosystem. [4]
Why it matters
The source characterizes frontier AI models, including Anthropic’s Claude Mythos, as marking a fundamental shift in cybersecurity. [4]
Also Worth Knowing
White House allegations of AI model distillation
What happened
White House technology official Michael Kratsios claimed Beijing-based Moonshot AI distilled Anthropic’s Fable model to develop its K3 model. [5]
World Cup streaming domain seizures
What happened
The US Department of Justice seized more than 1,000 internet domains that streamed FIFA World Cup 2026 matches without a license. [6]
Glow endpoint-security funding announcement
What happened
Glow emerged from stealth with $180 million in funding at a $1.2 billion valuation to advance a prevention-first endpoint-security approach. [7]