zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 15, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 15, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA Warns of Active Exploitation of SharePoint Vulnerabilities
  • Telegram Shortlink Domain T[.]me Restored
  • Doxbin Administrator Sentenced for Facilitating International Swatting Campaign

CISA Warns of Active Exploitation of SharePoint Vulnerabilities

Source: https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations

What we know: CISA has warned that threat actors are actively exploiting three SharePoint vulnerabilities—CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164—to gain unauthorized access to on-premises SharePoint Server instances. Additionally, CISA has also highlighted CVE-2026-55040 and CVE-2026-58644 as newly disclosed vulnerabilities that are not yet known to be exploited but should be patched promptly.

Context: The flaws reportedly involve remote code execution (RCE) and post-exploitation activities, including theft of Internet Information Services (IIS) machine keys, deserialization attacks, persistence, and malware deployment.

Analyst note: The exploitation of multiple SharePoint vulnerabilities indicates that internet-facing SharePoint servers are attractive targets for unauthorized access. Newly disclosed flaws CVE-2026-55040 and CVE-2026-58644 are also likely to attract threat actor interest in the near term.

Telegram Shortlink Domain T[.]me Restored

Source: https://techcrunch.com/2026/07/14/telegrams-shortlink-domain-is-back-online-after-day-long-suspension/

What we know: Telegram’s shortened t[.]me domain has been restored following a day-long serverhold suspension on July 13, 2026. The outage blocked the one-click t[.]me links used to join Telegram public groups.

Context: Domain registrar DomainMe clarified that the Telegram shortened domain was put on hold due to U.S. sanctions on First VPN, which also included a t[.]me link to First VPN's public Telegram group. First VPN is a service known to be used by cybercriminals in ransomware operations.

Analyst note: The domain registrar likely suspended the entire t[.]me domain instead of the single sanctioned URL as failing to adhere to U.S. sanctions attracts heavy fines for domain registrars.

Doxbin Administrator Sentenced for Facilitating International Swatting Campaign

Source: https://www.theregister.com/security/2026/07/14/welsh-doxbin-admin-jailed-for-egging-on-swatters-from-behind-a-screen/5271281

What we know: A Doxbin administrator has been sentenced to two years and three months in prison in the United Kingdom for encouraging and assisting swatting operations across the country, as well as in the United States and Canada.

Context: Doxbin is a dark web platform used to expose personally identifiable information (PII) to facilitate harassment and swatting attacks (hoax emergency calls to trigger armed police responses). The administrator was identified through a combination of seized Doxbin chat logs, a linked PayPal account, and digital forensics conducted by Wales police in cooperation with the FBI and Canadian authorities.

Analyst note: The successful attribution of a senior Doxbin figure very likely suggests that longstanding assumptions of anonymity within these communities are becoming less reliable. Although the conviction is unlikely to substantially disrupt the broader swatting ecosystem in the long term, other actors are likely to temporarily halt swatting activities to avoid law enforcement scrutiny in the near term.

DEEP AND DARK WEB INTELLIGENCE

Exploit user Citrix_one_love: A moderately credible threat actor, "Citrix_one_love," has advertised a dataset allegedly associated with the U.S.-based law firm Hastings & Hastings, on the predominantly Russian-language dark web forum Exploit. The actor claims the dataset includes the personal information of 4,500 individuals, including dates of birth and Social Security numbers (SSNs), as well as 3,500 court case records related to car incidents, including driver's licenses and passports.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Microsoft patch Tuesday July 2026: Microsoft has released security updates for a record 622 vulnerabilities, including three zero-day vulnerabilities, two of which are actively exploited. The actively exploited zero-days can enable attackers to elevate privileges and execute remote code, while the third is a security feature bypass vulnerability. The remaining vulnerabilities can enable RCE, privilege escalation, information disclosure, security feature bypass, denial of service, and spoofing.

Affected products: The affected products are listed here.

Tags: DIBtlp:green