Microsoft Patches a Record 570 Security Flaws
2026-07-16T07:23:29Z•83094e2d2ae06b35a74ca04f1605e02b6e21aeac8e4cb5544b9c32ba66099382
account takeoverai-assisted discoveryalarum technologiesaws govcloudbotnetcisacredentialsexploit codefbi seizuregithub leakhosting seizuresinstagram compromisemeta ai support botmicrosoftnetherlands arrestsnetnutpatch tuesdaypopa botnetransomwareresidential proxyscattered spiderthe gentlemenvulnerabilitieszero-day
What happened
A collection of KrebsOnSecurity reports (May–Jul 2026) covering multiple high-impact cyber events: Microsoft disclosed a record 570 vulnerabilities (AI-assisted discovery) in its July Patch Tuesday, following a June release of ~200 fixes including dozens rated critical and some with public exploit code. CISA published a postmortem after a contractor exposed dozens of internal credentials (including AWS GovCloud keys) on GitHub for months. The FBI seized domains tied to NetNut and the Popa Android botnet (millions of infected devices) and researchers linked Popa to Alarum Technologies (NetNut).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 83094e2d2ae06b35a74ca04f1605e02b6e21aeac8e4cb5544b9c32ba66099382
- Enrichment time
- 2026-07-16T07:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.