Intelligence in Cyber Intelligence Weekly

Cyber Intelligence Weekly (July 19, 2026): Our Take on Three Things You Need to Know

By Dan Desko
Posted on Jul 19 / 2026
Cyber Intelligence Weekly Echelon

Welcome to our weekly newsletter where we share some of the major developments on the future of cybersecurity that you need to know about. Make sure to follow my LinkedIn page as well as Echelon’s LinkedIn page to receive updates on the future of cybersecurity!

To receive these and other curated updates to your inbox on a regular basis, please sign up for our email list here: https://echeloncyber.com/ciw-subscribe

Echelon Events & Thought Leadership Highlight

BREAKING: CMMC Phase II has been suspended.

If you're in the Defense Industrial Base, today's announcement changes the certification timeline but it doesn't eliminate your security obligations.

The verification process may be paused, but the contractual and cybersecurity requirements remain. Continuing to strengthen your security program now puts you in the best position regardless of what comes next.

Here's what you need to know: https://lnkd.in/e3RSjQWf

 

Away we go!

1.  Microsoft's Biggest Patch Tuesday Ever Signals a New Era for Vulnerability Management

Microsoft's July Patch Tuesday was unlike anything security teams have seen before. The company released fixes for an unprecedented 622 vulnerabilities, shattering the previous monthly record and underscoring just how rapidly software security is evolving. Among the updates were three vulnerabilities that are already being actively exploited, including two affecting Microsoft SharePoint and one targeting Active Directory Federation Services (AD FS). Microsoft also addressed a publicly disclosed BitLocker security bypass and dozens of additional critical vulnerabilities with severity scores exceeding 9.0. For organizations that depend on Microsoft's ecosystem, this month's release is not simply another patch cycle. It is an immediate reminder that attackers are wasting little time weaponizing newly disclosed flaws.

While the sheer number of vulnerabilities is eye-catching, security leaders should resist the urge to focus solely on volume. Not every vulnerability carries the same level of risk, and organizations that attempt to patch hundreds of issues simultaneously without a strategy can introduce unnecessary operational disruption. Instead, prioritize vulnerabilities that are already being exploited in the wild, have proof-of-concept exploit code available, or have been added to CISA's Known Exploited Vulnerabilities catalog. Security teams should also leverage modern prioritization methods such as the Exploit Prediction Scoring System (EPSS), business criticality, and asset exposure rather than relying exclusively on CVSS scores.

Perhaps the most important lesson from this month's Patch Tuesday is that vulnerability management has entered a new phase. Artificial intelligence is dramatically increasing the speed at which researchers can discover software flaws, and unfortunately, it is doing the same for attackers. The result is a growing volume of vulnerabilities, shorter windows between disclosure and exploitation, and increasing pressure on defenders to automate patching, improve asset visibility, and mature their vulnerability management programs. Simply applying patches as they are released is no longer enough. Organizations need continuous visibility into their environments, risk-based prioritization, compensating controls such as segmentation and web application firewalls, and well-defined patching workflows that can respond quickly to emerging threats.

One additional consideration this month is Microsoft's temporary hold on the July updates for certain Dell systems using Intel Innovation Platform Framework (IPF) drivers due to reports of unexpected shutdowns, overheating, and battery issues. Enterprises should validate hardware compatibility before broad deployment while continuing to move quickly on high-risk systems that are not affected. As AI continues to reshape both software development and offensive security research, record-breaking Patch Tuesdays may soon become the norm rather than the exception. Organizations that invest today in disciplined, automated vulnerability operations will be far better prepared for the pace of tomorrow's threat landscape

Oracle E-Business Suite Under Active Attack: Patch Now, Investigate Immediately

Organizations running Oracle E-Business Suite should move this issue to the top of their priority list. Security researchers recently confirmed that attackers are actively exploiting CVE-2026-46817, a critical vulnerability affecting the Oracle Payments module. The flaw allows unauthenticated remote attackers to take control of vulnerable systems, and researchers observed exploitation attempts in the wild shortly after the May Critical Patch Update was released. In some cases, attackers began exploiting vulnerable systems before public proof-of-concept code was even available, highlighting how quickly sophisticated threat actors weaponize newly disclosed vulnerabilities.

The most effective remediation is straightforward: ensure the May 2026 Oracle Critical Patch Update has been fully deployed across development, staging, and production environments. Organizations should also verify whether Oracle E-Business Suite is exposed to the public internet. If external access is required, implement strong compensating controls such as a properly configured Web Application Firewall (WAF), continuous monitoring, and multifactor authentication for administrative access. Security teams should review authentication logs, monitor for unusual web requests targeting Oracle Payments, and validate that WAF policies are actively enforcing protections rather than operating in monitoring or learning mode.

Takeaway: Critical enterprise applications remain prime targets for attackers. Rapid patch management, minimizing internet exposure, and validating security controls are often the difference between an attempted intrusion and a successful compromise.

2.  Pentagon Suspends CMMC Phase II While Rethinking the Future of Defense Cybersecurity

The Department of War has announced an immediate suspension of CMMC Phase II, delaying the rollout of mandatory third-party cybersecurity assessments that were scheduled to begin on November 10, 2026. Instead, the Department has launched a comprehensive 60-day review of the program with the goal of reducing compliance costs, encouraging greater participation from small and non-traditional defense contractors, and aligning cybersecurity requirements with broader acquisition reform initiatives. While the certification timeline has been paused, organizations should understand that CMMC Phase I self-assessments remain in effect, and the underlying requirements to protect Controlled Unclassified Information (CUI) and comply with NIST SP 800-171 have not changed.

The decision reflects a growing concern that the current CMMC framework has become too costly and administratively burdensome for many companies across the Defense Industrial Base. Department leadership cited feedback from industry and the Small Business Administration indicating that compliance costs, limited availability of accredited third-party assessors, and complex regulatory requirements were discouraging innovative companies from pursuing defense contracts. The upcoming review will examine whether the government can achieve the same cybersecurity objectives through a more scalable and practical approach that preserves security while removing unnecessary barriers to entry.

For defense contractors, however, this announcement should not be viewed as permission to slow down cybersecurity initiatives. Nation-state adversaries are not pausing their efforts to steal sensitive defense information simply because certification deadlines have shifted. Requirements under DFARS 252.204-7012, NIST SP 800-171, and existing contractual obligations remain fully enforceable, and organizations will continue to be expected to demonstrate strong cybersecurity practices regardless of how the certification process ultimately evolves. Companies that continue investing in security controls, documenting compliance, and strengthening operational resilience during this pause will be in a far stronger position when the Department unveils its revised framework.

The broader lesson extends well beyond CMMC itself. Cybersecurity was never intended to become a paperwork exercise. The purpose has always been to protect the technologies, intellectual property, and sensitive information that provide America's military with its competitive advantage. Whether the future includes third-party assessments, enhanced self-assessments, or an entirely new certification model, the objective remains unchanged: strengthening the cybersecurity of the Defense Industrial Base so the nation's most critical innovations remain in American hands.

AI Is Becoming a Force Multiplier for Cyber Defenders and Attackers

The cybersecurity industry continues to reach an important inflection point as governments and technology companies accelerate efforts to harness AI for defensive security. This week, the White House announced a new AI and cybersecurity coordination initiative that will bring together frontier AI developers, critical infrastructure operators, and federal agencies to share AI-discovered vulnerabilities and coordinate remediation efforts. The initiative recognizes a reality many security teams are already experiencing: advanced AI models can identify software weaknesses dramatically faster than traditional manual techniques, but those same capabilities can also be abused by attackers.

For organizations adopting AI internally, this means security programs must evolve beyond simply governing employee use of chatbots. AI agents should be treated like privileged users with clearly defined permissions, least-privilege access, strong identity controls, comprehensive logging, and human approval for sensitive actions. Development teams should also establish governance around AI-generated code, ensuring it passes the same secure code reviews, vulnerability scanning, and testing as human-written software.

Takeaway: AI is no longer just another productivity tool. It is rapidly becoming a cybersecurity capability that can dramatically improve vulnerability discovery, incident response, and software assurance. Organizations that implement strong governance, identity controls, and human oversight today will be far better positioned to benefit from AI while minimizing its risks.

3.  CISA Releases New Guidance to Help Organizations Build Better Vulnerability Disclosure Programs

As cyber threats continue to evolve, one of the most valuable security resources available to any organization isn't another security tool. It's the global community of security researchers actively looking for vulnerabilities before attackers find them. Recognizing this, the Cybersecurity and Infrastructure Security Agency (CISA), together with the National Security Agency and cybersecurity authorities from Japan, the Netherlands, and the United Kingdom, has released comprehensive guidance to help software manufacturers and online service providers establish effective Coordinated Vulnerability Disclosure (CVD) programs. The guidance provides organizations with a practical roadmap for working constructively with external researchers while improving the security of their products and services.

At the heart of the guidance is the recommendation that every organization develop a clear Vulnerability Disclosure Policy (VDP). Researchers need to know exactly how to report security issues, what systems are in scope, what types of testing are permitted, and how organizations will respond. Just as importantly, the guidance encourages organizations to provide "safe harbor" protections for researchers acting in good faith. By removing uncertainty and fostering open communication, organizations are far more likely to receive responsible disclosures rather than discovering vulnerabilities after they have already been exploited by attackers.

The publication also emphasizes that accepting vulnerability reports is only one piece of the puzzle. Organizations need mature internal processes for triaging reports, validating findings, assigning CVEs when appropriate, communicating with researchers, and remediating vulnerabilities in a timely manner. For companies that lack these internal capabilities, the guidance outlines how third-party coordinators, CERT organizations, and bug bounty platforms can help manage the disclosure process while maintaining consistency and transparency.

This guidance arrives at an important time. Regulations such as the European Union's Cyber Resilience Act are raising expectations around vulnerability handling, while artificial intelligence is dramatically accelerating the pace at which both defenders and attackers can discover software flaws. Organizations that treat vulnerability disclosure as an opportunity rather than a liability will be better positioned to improve product security, strengthen customer trust, and reduce overall cyber risk. Responsible disclosure should no longer be viewed as an exception. It should be considered a fundamental component of every modern secure software development program.

Thanks for reading!

About us: Echelon is a full-service cybersecurity consultancy that offers wholistic cybersecurity program building through vCISO or more specific solutions like penetration testing, red teaming, security engineering, cybersecurity compliance, and much more! Learn more about Echelon here: https://echeloncyber.com/about

Are you ready to get started?