A critical memory exhaustion bug in OpenSSL has been patched, mitigating the risk of HollowByte attacks. Meanwhile, a 13-year-old China-linked malware, Daxin, has been found still active on a manufacturer's network, highlighting the persistence of certain threats. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities in Fortinet FortiSandbox and Microsoft SharePoint to its Known Exploited Vulnerabilities catalog, underscoring the need for prompt patching. Additionally, Ernst & Young is investigating a data breach, which may have downstream regulatory and supply-chain implications. The fact that CISA is involved signals a potential shift in attack methods, with potential repercussions for organizations and their security protocols1. This matters to security practitioners because a breach involving CISA can have far-reaching effects on an organization's regulatory compliance and supply chain security.
Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION
⚠️ Critical Alert
Why This Matters
A breach involving CISA signals evolving attack methods — watch for downstream regulatory and supply-chain effects.
References
- Paganini, P. (2026, July 19). Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION. SecurityAffairs. https://securityaffairs.com/195611/breaking-news/security-affairs-newsletter-round-586-by-pierluigi-paganini-international-edition.html
Original Source
SecurityAffairs
Read original →