Isometric network nodes depicting widespread cybersecurity exploits and vulnerabilities.

Daily Cybersecurity News - July 2, 2026

CISA SharePoint RCE Flaw Now Exploited

CISA added a Microsoft SharePoint remote code execution flaw to its actively exploited list this week.

CVE-2026-45659 is a deserialization issue that lets any authenticated user with Site Member rights run arbitrary code over the network. CVSS 8.8, on CISA KEV after the May patch.

Affects on-prem SharePoint Enterprise Server 2016, Server 2019, and Subscription Edition. Shadowserver sees over 10,000 instances exposed to the internet.

CISA has flagged 11 SharePoint CVEs since 2021, seven of them used in ransomware campaigns.

New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure

Attackers started hitting Citrix NetScaler appliances the moment a new memory leak went public.

The flaw, CVE-2026-8451, lets unauthenticated attackers leak memory from vulnerable NetScaler appliances configured as SAML identity providers. The flaw mirrors the 2023 CitrixBleed issue in behavior and impact.

Affects NetScaler ADC and Gateway appliances still running vulnerable firmware versions worldwide. Internet-facing NetScaler ADC and Gateway appliances configured as SAML IDP are the primary concern.

Exploitation attempts appeared within hours of the disclosure post.

Source: SecurityWeek

Fake Google and Cloudflare Pages Spread Malware

Attackers are pushing ClickFix campaigns through fake Google and Cloudflare verification pages that drop multiple malware families at once.

The pages trick users into running PowerShell commands that fetch infostealers plus a new loader. Initial access comes from malicious ads and compromised sites serving these verification mimics.

Nothing here is brand new in technique, but the bundling of several payloads from a single page is efficient for the operators and expands their reach.

Campaign has been active for several weeks with the loader appearing in multiple recent ClickFix variants.

Source: Malwarebytes

Fake Perplexity Chrome Extension Spies On Searches

A fake Perplexity Chrome extension is stealing search data from users who installed it.

The extension called Search for perplexity ai runs in the background and records every query sent to the real service. Victims must uninstall it by hand because Chrome's removal flow misses the payload.

The trick is simple typosquatting on a popular AI tool name. No new exploits, just a malicious listing that blends in with legitimate extensions.

Malwarebytes flagged over 12,000 installations before the listing was taken down.

Source: Malwarebytes

ConsentFix and ClickFix How Microsoft 365 Accounts are Hijacked in 3 Seconds

Attackers are hijacking Microsoft 365 accounts through fake OAuth consent screens that grant full mailbox access in seconds.

They send phishing links that trigger a malicious app registration. The victim approves a single prompt and hands over tokens without entering credentials or dealing with MFA.

Both techniques reuse the same OAuth abuse pattern seen in prior consent phishing but now focus on speed and minimal user friction. Nothing novel in the tradecraft, just better social engineering.

The attacks target corporate tenants specifically and have been observed in campaigns since early 2025.

BioShocking Attack Tricks AI Browsers Into Stealing Credentials

Researchers tricked agentic browsers into stealing credentials by feeding them malicious context.

The attack works by rewriting visible page elements so the AI agent believes it needs to copy login data and send it elsewhere. Demonstrations showed the browser following instructions that normal safety rules should block.

The finding comes from a single research paper rather than broad industry data. It highlights a new attack surface but offers no statistics on real-world prevalence yet.

The technique targets browsers that run AI agents directly inside the tab.

Source: SecurityWeek

Researcher Behind Exploitarium Explains Release of Undisclosed Zero Day Exploits

A researcher released over 30 proof-of-concept exploits for undisclosed vulnerabilities through Exploitarium.

The approach skips the usual coordinated disclosure step. Public PoCs appear before any CVE or vendor notification.

This mirrors prior drops like the 2023 GitHub zero-day releases, but the researcher frames it as a deliberate shift in timing.

Exploitarium hosts the collection on GitHub.