Microsoft Patches a Record 570 Security Flaws

2026-07-20T13:23:39Z44fa1d5cfe448dae83380a4bba76ef35cebeefd149d46978fff29ce808754783
AI-assisted vulnerability discoveryAWS GovCloud keysAlarum Technologies/NetNutCISA GitHub leakFBI seizureInstagram account takeoverMeta AI support-bot exploitMicrosoft Patch TuesdayNetNutNetherlands server seizurePopa botnetScattered SpiderThe Gentlemencriminal convictionscybercrime infrastructureexposed credentialsinfrastructure takedownoffensive-security startup controversypatchingransomwareresidential proxy abusethird-party/contractor riskvulnerability disclosurezero-day acquisition marketplace

What happened

Collection of KrebsOnSecurity reports (May–Jul 2026) covering a wide set of high-impact cyber events: Microsoft issued an unusually large set of patches (570 flaws in July; ~200 in June) driven in part by AI-aided vulnerability discovery; CISA leaked internal credentials (including AWS GovCloud keys) via a contractor's public GitHub repo; the FBI seized domains linked to NetNut and the Android-based Popa botnet tied to a publicly traded firm; convictions and disruptions of prominent cybercriminal groups (Scattered Spider guilty pleas, reporting on The Gentlemen ransomware); abuse and takeovert

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
44fa1d5cfe448dae83380a4bba76ef35cebeefd149d46978fff29ce808754783
Enrichment time
2026-07-20T13:23:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft Patches a Record 570 Security Flaws · Baitaphish