By Nemuel Cruz, Incognito CyberSecurity™
Incognito CyberSecurity™ is a local Tucson, Arizona MSP company offering 24/7 services to small businesses across Southern Arizona. Here is the cybersecurity news that mattered this week (July 20–24, 2026) and what each story means for an owner who does not have a full-time security team. If any of this leaves you unsure where you stand, our cybersecurity services exist to close exactly these gaps.
1. CISA flags a Check Point admin-access flaw being exploited right now
On July 22, CISA added CVE-2026-16232, an improper-authentication flaw in Check Point SmartConsole, to its Known Exploited Vulnerabilities catalog. The bug carries a CVSS score of 9.3 and lets an unauthenticated attacker gain full administrative control of the management console — the exact tool used to run a company’s firewalls. CISA ordered federal agencies to patch by July 25, which tells you how urgent the government considers it.
What to do: If you or your IT provider run Check Point at the edge of your network, apply the vendor update this week — not next month. Then confirm your firewall management is not reachable from the open internet. A properly locked-down firewall is the front door of your network; if it is wide open, everything behind it is too.
2. On-premises Microsoft SharePoint servers are under active attack
The same July 22 CISA update added CVE-2026-50522, a critical SharePoint remote-code-execution flaw (CVSS 9.8) that requires no login or user interaction. It is part of a broader wave of exploitation against self-hosted SharePoint servers this month, alongside CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164. Attackers are scanning the internet for SharePoint login pages and chaining these bugs to take over the server. Important detail for owners: this hits on-premises SharePoint only — SharePoint Online inside Microsoft 365 is not affected.
What to do: If you host your own SharePoint server, install Microsoft’s patches immediately and assume it may already have been probed — check for unexpected files and accounts. If you don’t know whether you run one, that uncertainty is the problem; disciplined server and workstation management means someone is tracking and patching these systems for you before headlines like this appear.
3. Qilin ransomware is breaking in through Palo Alto VPNs
Researchers at Arctic Wolf reported this week that the Qilin ransomware gang is exploiting CVE-2026-0257, an authentication-bypass flaw in Palo Alto Networks GlobalProtect VPN, to walk into corporate networks without valid credentials. The uncomfortable part: Palo Alto shipped a fix back on May 13 and CISA flagged it in May, yet ransomware crews were still landing in unpatched networks in June. Once inside, they stole credentials and spread across Windows shares before deploying ransomware.
What to do: Patch your VPN appliances on the same urgency you’d patch a broken lock on your front door, and turn on multi-factor authentication for remote access. Just as important, make sure you have tested, offline secure data backups — a clean backup is the difference between a bad week and paying a ransom.
4. Fake “Claude” app ads are pushing password-stealing malware
Between July 21 and 22, a malvertising campaign nicknamed “FakeAgent” tricked at least 29 organizations into installing malware. Attackers bought search ads for the popular Claude AI desktop app, then used a malicious page hosted on a legitimate domain to serve a fake installer named ClaudeDesktop.exe. The download — grabbed roughly 7,100 times before it was removed — delivered SectopRAT, a remote-access trojan that steals passwords, credit-card data, and files straight off the machine.
What to do: Teach your team never to download software from a search ad — go to the vendor’s official site directly. Pair that habit with modern endpoint protection that can catch a trojan the moment it tries to run, because one employee installing the wrong “app” can hand an attacker the keys to everything.
5. Phishing kits that beat multi-factor authentication keep targeting Microsoft 365
A misconfigured attacker server exposed this month revealed three separate phishing operations built on the “Evilginx” toolkit, all aimed at Microsoft 365 logins. These kits sit between the victim and the real Microsoft login page, capturing not just the password but the session token — which lets attackers slip past multi-factor authentication entirely. A related device-code phishing campaign has racked up more than 200 victims, many of them small businesses using corporate email.
What to do: MFA is still essential, but treat it as one layer, not a force field. Add phishing-resistant sign-in where you can, watch for logins from odd locations, and filter the bait before it reaches inboxes. Strong spam and virus filtering stops most of these emails at the door, so your staff never has to make the judgment call.
6. A quiet, well-funded espionage campaign shows how professional attackers have become
On July 23, Group-IB detailed a China-nexus operation it tracks as “JadeProx,” uncovered after the attackers left a cloud server exposed. The group used a previously undocumented Windows loader to quietly infiltrate government, healthcare, and education targets across Asia and Latin America. Small businesses aren’t the direct target here, but the story is a useful reality check: today’s attackers are patient, organized, and reuse the same techniques — stolen credentials, custom malware, hidden infrastructure — against smaller victims too.
What to do: You can’t out-spend a nation-state, but you don’t have to — the fundamentals stop the overwhelming majority of attacks. Know what devices and software you have, patch them, enforce MFA, back up your data, and get an outside set of eyes on your defenses. Purpose-built small business cybersecurity solutions package all of that into something a busy owner can actually maintain.
The bottom line
The theme this week is consistent: known flaws are being exploited faster than businesses can patch them, and attackers are happy to walk through whichever door you left open — a firewall console, a VPN, a self-hosted server, an employee’s download, or a phished login. None of it requires a huge budget to defend against; it requires attention and follow-through. Incognito CyberSecurity™ is a local Tucson, Arizona MSP company offering 24/7 services to businesses across Southern Arizona. If this week’s news has you wondering whether your own doors are locked, Contact Incognito Cyber Security and we’ll help you find out.


