meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Wednesday, July 15th, 2026: Microsoft Patches; New MSFT Priv Escalation; Progress ShareFile 0-Day; Grok Exfiltration

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9755 Ratings

🗓️ 15 July 2026

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Wednesday, July 15th, 2026: Microsoft Patches; New MSFT Priv Escalation; Progress ShareFile 0-Day; Grok Exfiltration

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, July 15, 2006 edition of the Sands Inite Storm Center's Stormcast. My name is Johannes Ulrich, recorded a day from Washington, D.C.

0:17.7

And this episode is brought you by the Sands.edu graduate certificate program in penetration testing and ethical hacking.

0:26.0

Well, of course, it's patch Tuesday, and this was a special patch Tuesday.

0:31.0

We got 622 different vulnerabilities addressed by Microsoft, and that doesn't even include the 400 plus

0:42.0

vulnerabilities in chromium that also affect Microsoft Edge. Now, that of course, was a little

0:50.7

bit pre-announced by Microsoft. Microsoft stated to expect larger patch

0:55.8

Tuesdays because of AI helping them find more vulnerabilities. And I believe the largest

1:03.3

patch Tuesday we had before this one was probably something around 200 vulnerabilities. So

1:10.2

we got about a factor of three.

1:13.7

Now, it's hard to identify vulnerabilities that really stick out in this set, but there are

1:21.4

two vulnerabilities that are already being exploited. One is an active directory federation

1:26.4

services, elevation of privileges. Essentially,

1:29.3

the privilege aren't as fine-crowned as they should be, and that has already been exploited.

1:35.3

Microsoft rates this vulnerability as important. And then we do have another Microsoft SharePoint server

1:42.3

vulnerability. This is also an elevation of privilege

1:45.8

vulnerabilities. Microsoft only considers this vulnerability moderate. In addition to these two

1:52.4

exploited vulnerabilities, we have a third that is disclosed but not yet exploited, and that's

1:58.5

a Windows BitLocker security feature bypass vulnerability.

2:03.1

Now, we have heard a lot from Nightmare Clips on that topic. It's possible that this is

2:08.2

one of the Nightmare Clips Warnabilities. Doesn't state so in the advisory. It just credits

2:15.3

anonymous with discovering the vulnerability.

2:19.5

But the real question is, no, what does this really mean to you trying to apply these patches?

...

Transcript will be available on the free plan in 15 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.