Security Digest - July 25, 2026
Daily security intelligence briefing for infrastructure and endpoint management teams. Consolidated from authoritative research, vendor advisories, and community discussions.
- Generated (UTC): 2026-07-25 14:56:29 +00:00
- Lookback window: 7 days
π Top Research & Advisories
- No high-priority security research detected in this window.
π Infrastructure
- Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain - (CybersecurityNews) Review server hardening and AD security posture.
π Infrastructure & Endpoint Control
-
ChonkyChicken Malware Steals Chrome Credentials, Moves Laterally and Spies on Victims - (CybersecurityNews) Validate Chrome coverage; update managed package if needed.
-
Microsoft Confirms No Bloatware Ads in Windows 11; LG Disables McAfee Pop-ups - (CybersecurityNews) Validate workstation security baseline and update compliance.
-
Microsoft shares some details on Azure outage that blocked Windows 11 update downloads - (Neowin) Validate workstation security baseline and update compliance.
-
Microsoft stops rollout of some Teams and Outlook features - (Neowin) Review Office update channel health and security baseline compliance.
-
Microsoft will soon let users disable Copilot key in Windows 11 - (Neowin) Validate workstation security baseline and update compliance.
-
Rufus alternate Ventoy improves upon one of Windows 11βs system requirements - (Neowin) Validate workstation security baseline and update compliance.
π Quick Links (Watch Items)
- I want to transition from an AppSec role to Cloud Security. How feasible is this and how should I study? - (Reddit r/cybersecurity)
- Foxit Updater Vulnerability Gives Standard Users SYSTEM-Level Control of Windows Devices - (CybersecurityNews)
- Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain - (CybersecurityNews)
- Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers - (CybersecurityNews)
- Cl0p Hackers Exploit Windchill Servers to Steal Companiesβ Secret Product Designs - (CybersecurityNews)
- Russian hackers exploit Zimbra zero-click flaw for email theft - (BleepingComputer)
- CVE-2026-16155 - (NVD)
- CVE-2026-16155 - (CVE.org)
- CVE-2026-16154 - (CVE.org)
- CVE-2026-16154 - (NVD)