Security Digest - July 21, 2026
Daily security intelligence briefing for infrastructure and endpoint management teams. Consolidated from authoritative research, vendor advisories, and community discussions.
- Generated (UTC): 2026-07-21 21:14:07 +00:00
- Lookback window: 7 days
🚀 Top Research & Advisories
- Critical Palo Alto VPN bug now exploited by Qilin ransomware gang - (BleepingComputer)
System.Xml.XmlElement
Action: Review VPN client version and deployment.
- CVE-2026-15764 - (CVE.org)
Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Cr…
Action: Validate Chrome coverage; update managed package if needed.
- CVE-2026-15765 - (NVD)
Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Action: Validate Chrome coverage; update managed package if needed.
🛠 Infrastructure & Endpoint Control
-
CVE-2026-15766 - (CVE.org) Validate Chrome coverage; update managed package if needed.
-
CVE-2026-15767 - (NVD) Validate Chrome coverage; update managed package if needed.
-
CVE-2026-15768 - (NVD) Validate Chrome coverage; update managed package if needed.
-
CVE-2026-15769 - (NVD) Validate Chrome coverage; update managed package if needed.
-
CVE-2026-15770 - (NVD) Validate Chrome coverage; update managed package if needed.
-
CVE-2026-15771 - (CVE.org) Validate Chrome coverage; update managed package if needed.
-
CVE-2026-15772 - (CVE.org) Validate Chrome coverage; update managed package if needed.
-
CVE-2026-15773 - (NVD) Validate Chrome coverage; update managed package if needed.
-
CVE-2026-15774 - (CVE.org) Validate Chrome coverage; update managed package if needed.
-
CVE-2026-15775 - (CVE.org) Validate Chrome coverage; update managed package if needed.
-
CVE-2026-15776 - (CVE.org) Validate Chrome coverage; update managed package if needed.
-
CVE-2026-15777 - (CVE.org) Validate Chrome coverage; update managed package if needed.
-
CVE-2026-15778 - (NVD) Validate Chrome coverage; update managed package if needed.
-
Has anybody evaluated the security risk of intrusive warning messages? Is there a paper or anything? - (Reddit r/cybersecurity) Review Office update channel health and security baseline compliance.
-
Microsoft found yet another place to put Copilot inside Windows 11 - (Neowin) Validate workstation security baseline and update compliance.
-
Microsoft stops death of Outlook Classic feature it was going to lock behind New Outlook - (Neowin) Review Office update channel health and security baseline compliance.
-
This new free light Windows 11 cleaning app looks just like one Microsoft really hated - (Neowin) Validate workstation security baseline and update compliance.
🔍 Quick Links (Watch Items)
- This pocket-sized TP-Link travel router keeps you safe on public Wi-Fi, and is now on sale - (Neowin)
- The quantum threat is what’s keeping “smart money” away, acording to BlackRock. why is Bitcoin doing nothing? - (Reddit r/cybersecurity)
- ‘Self-State Attacks’ Formalize a New Threat Class: AI Agents Poisoned via Their Own Memory Files, OS Defenses Structurally Insufficient - (Reddit r/cybersecurity)
- WP2Shell: Hands-On Lab Reproducing the Pre-Auth WordPress Core RCE - (Reddit r/cybersecurity)
- CVE maps to package and version. CWE maps to code weaknesses. Neither has a vocabulary for what agentic AI components actually do wrong - (Reddit r/cybersecurity)
- Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE) - (Reddit r/cybersecurity)
- European Password Manager Shares Origins and Updates with State-Certified Russian Firm - (Reddit r/cybersecurity)
- Closing the Identity Gaps in Critical Infrastructure Security - (BleepingComputer)
- Has anybody evaluated the security risk of intrusive warning messages? Is there a paper or anything? - (Reddit r/cybersecurity)
- SOC vs GRC career path at 24 need advice - (Reddit r/cybersecurity)