By Nemuel Cruz, Incognito CyberSecurity™
Incognito CyberSecurity™ is a local Tucson, Arizona MSP company offering 24/7 services. Each week we break down the security headlines that matter most to small businesses.
Here’s what happened in cybersecurity this week and, more importantly, what it means for your business. If your company runs any of the products below, the action items are at the end of each section.
1. Ransomware gangs are now exploiting the “BlueHammer” Windows Defender flaw
CISA confirmed that ransomware operators are actively exploiting CVE-2026-33825, a Microsoft Defender privilege-escalation vulnerability dubbed BlueHammer. It was abused as a zero-day earlier this year, and proof-of-concept exploit code has been public since April. That combination — public exploit code plus ransomware adoption — means attacks against unpatched systems are only going to increase.
What to do: Confirm Windows updates from the last patch cycle are actually installed across your fleet, not just approved. Defender is on nearly every Windows machine, so there’s no “we don’t use that product” exemption here.
2. CISA: SharePoint RCE bug under active exploitation
CISA added CVE-2026-45659, a Microsoft SharePoint Server remote code execution vulnerability (CVSS 8.8), to its Known Exploited Vulnerabilities catalog and gave federal agencies just three days to patch. The flaw lets an authenticated attacker run arbitrary code on the server — and “authenticated” is a low bar when credentials are this cheap on the dark web. Microsoft patched it in late May via an out-of-band update.
What to do: If you run on-premises SharePoint, verify the May out-of-band update is applied. If you can’t patch immediately, restrict access and watch for unusual activity from service accounts.
3. Citrix patches six NetScaler flaws, including the “HTTP/2 Bomb”
Citrix released fixes for six NetScaler ADC and Gateway vulnerabilities. Two stand out: the HTTP/2 Bomb (CVE-2026-49975, tracked by Citrix as CVE-2026-13474), a denial-of-service technique that can knock servers offline in seconds, and CVE-2026-8451, a memory-overread bug researchers compare to CitrixBleed — the flaw behind some of the most damaging breaches of recent years. Fixed versions include 14.1-72.61 and 13.1-63.18.
What to do: NetScaler appliances sit at the network edge and are a favorite target. Patch now — history says CitrixBleed-style bugs get exploited fast.
4. FortiBleed stolen credentials linked to ransomware operations
The FortiBleed credential-theft campaign has been tied to the INC and Lynx ransomware groups, indicating the stolen Fortinet credentials are being stockpiled for network intrusions. If your firewall or VPN credentials were exposed, patching alone doesn’t close the door — the attackers already have keys.
What to do: If you run Fortinet gear, rotate credentials on any device that was exposed before patching, and enforce MFA on all VPN access.
5. Fake software installers deliver AsyncRAT via ScreenConnect
A large multi-language campaign is using spoofed download sites for popular free tools — OBS Studio, DNS Jumper, DS4Windows, Bandicam — to push malicious installers. The installers deploy the legitimate ScreenConnect remote-access tool, which then delivers the AsyncRAT trojan. Because ScreenConnect is a trusted IT tool, this activity often slips past basic defenses.
What to do: Only download software from vendors’ official sites. Consider application allow-listing, and alert on remote-access tools installing outside your approved IT stack.
6. Adobe fixes seven maximum-severity ColdFusion and Campaign flaws
Adobe shipped patches for seven max-severity vulnerabilities in ColdFusion and Campaign Classic. ColdFusion bugs have a long track record of rapid exploitation once patches drop.
What to do: Patch immediately if either product is in your environment.
7. Breach roundup: Medtronic and Tata Electronics
Medical device maker Medtronic is notifying customers after personal data was exposed to an unauthorized third party. Tata Electronics confirmed a June incident after the World Leaks extortion group published more than 200,000 alleged internal files. Both are reminders that breach fallout lands on customers and partners downstream — vendor risk is your risk.
The bottom line
Every item above has the same theme: attackers move within days of a patch or leak, and small businesses without dedicated security staff are the easiest targets. If you’re not sure whether your systems are covered, that’s exactly what we do. Incognito CyberSecurity™ is a local Tucson, Arizona MSP company offering 24/7 services to businesses across Southern Arizona. Contact Incognito Cyber Security for a no-obligation review of your patch posture and remote-access controls.


