Cybersecurity Headlines — July 03, 2026
- Visa Lets Banks Access Its In-House Cybersecurity Capabilities — pymnts.com
- ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds — BleepingComputer
- US cyber agency warns over forgotten SharePoint flaw — ComputerWeekly.com
- Cognizant and OpenAI bring frontier AI cyber defense from vulnerability discovery to validated fixes — PR Newswire UK
- Cognizant and OpenAI bring frontier AI cyber defense from vulnerability discovery to validated fixes — PRNewswire
- Cisco finally confirms attackers exploiting Unified CM flaw — BleepingComputer
- Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation — HackRead
- Exploring the SoC as a Service Market: Growth Potential and Key Drivers Through 2031 — GlobeNewswire
- Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects — Securelist.com
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation — Internet
From the Trenches
The ConsentFix/ClickFix story is the one I’d actually sit with today — three seconds to hijack an M365 account is a workflow, not an exploit, and it’s built entirely around tricking a user into consenting to something that looks legitimate. No amount of patching stops that; it’s an awareness and conditional-access problem before it’s a technical one.
Sysdig’s JADEPUFFER writeup documenting the first confirmed agentic ransomware operation deserves attention beyond the novelty factor. An LLM-driven agent running the attack chain end to end changes the incident response calculus — the “human operator makes a mistake and tips their hand” assumption a lot of detection tuning relies on doesn’t hold the same way.
And SharePoint’s CVE-2026-45659 landing on CISA’s KEV list after active exploitation is a good reminder that “forgotten” vulnerabilities don’t stay forgotten — they just wait for someone to notice they’re still unpatched somewhere.
🔧 Patch Priority: SharePoint RCE (CVE-2026-45659) — added to CISA’s Known Exploited Vulnerabilities catalog, patch immediately if still exposed.
Compiled daily. Stay patched, stay vigilant.