Cybersecurity News — 2026-07-03
Generated: 2026-07-03 | Sources: The Hacker News, BleepingComputer, SecurityWeek, CISA, Huntress
1. A Widely Used Office Filing System Has a Flaw Hackers Are Already Exploiting
Microsoft SharePoint Server — the version many businesses install and run themselves for internal file-sharing and intranets, separate from the cloud SharePoint bundled into Microsoft 365 — has a flaw that lets even a low-privileged logged-in user trick the server into running commands it shouldn't. The technique is called deserialization: feeding the server a corrupted data package that it unpacks and blindly trusts, rather than checking first. Microsoft patched it back in May, but the US government's cyber agency (CISA) confirmed this week that hackers are now actively exploiting unpatched copies and gave federal agencies until July 4 to fix it.
Why it matters for your business: if your business or an IT contractor runs an on-premises SharePoint server (not the Microsoft 365 cloud version), confirm today that May's update is actually installed — a two-month-old patch is already a long window for something now under active attack, and "we'll get to it" is no longer good enough once a flaw is on a government exploited-vulnerabilities list.
2. Office Phone Systems Are Being Hijacked Through a Feature Most Businesses Never Use
Cisco confirmed that hackers are exploiting a flaw in Unified Communications Manager, the software behind many businesses' office phone and voicemail systems, when a rarely-used "click to dial from a webpage" feature called WebDialer is switched on. The bug is a case of server-side request forgery — tricking the phone system into fetching a web address the attacker chooses on their behalf — which lets an outsider plant a file that can later be used to seize full administrator control of the whole system.
Why it matters for your business: ask whoever manages your office phone system whether it runs Cisco Unified Communications Manager and whether WebDialer is switched on; if nobody in your business uses click-to-dial-from-a-webpage, have it disabled, and confirm June's patch is installed either way.
3. Citrix Patches Six Flaws in Gear That Sits in Front of Many Business Websites
Citrix released patches for six flaws in NetScaler, hardware and software that many web hosts and IT providers use to manage traffic into a company's website or remote-access portal. One, in the "CitrixBleed" family of bugs (a known pattern where the device is tricked into leaking supposedly-private session data straight out of its own memory), can hand an attacker enough information to hijack an already-logged-in session with no password needed. Another, nicknamed "HTTP/2 Bomb," can knock a web server offline using only a small number of specially-crafted requests.
Why it matters for your business: you probably don't manage this appliance yourself, but ask your website host, VPN provider, or IT support company by name whether they run Citrix NetScaler and, if so, whether it's on the July 2026 patched release — get the answer in writing rather than assuming someone else already checked.
4. Adobe Rushes Out Fixes for Seven "Perfect Score" Flaws in Business Web and Marketing Software
Adobe issued emergency patches for seven flaws rated the maximum possible severity (10 out of 10) across ColdFusion, a platform used to build business web applications, and Campaign Classic, marketing-email software. Each flaw needs no user interaction to trigger and could let an attacker run their own code directly on the server — serious enough that Adobe is telling customers to patch within 72 hours instead of its usual timeline.
Why it matters for your business: if any part of your website, customer portal, or email marketing runs on Adobe ColdFusion or Campaign Classic, ask your web developer or agency by name whether they've already applied this month's update — this is one of the rare cases where "patch it this week" genuinely means this week, not next quarter.
5. A US Government Security-Sharing Network Sat Breached for Weeks Before Anyone Noticed
The US Department of Homeland Security confirmed that hackers had access to the Homeland Security Information Network — a platform federal, state, and private-sector partners use to share threat and event-security information — for several weeks between late May and June before the intrusion was detected and disclosed. Investigators still don't know who was behind it or exactly what data was taken.
Why it matters for your business: the "shared portal" model many industries rely on — supplier extranets, franchise or trade-association platforms, joint client databases — is only as safe as its slowest member to notice a break-in. Ask any shared platform you or your staff log into how quickly they'd tell you if it were breached, and don't read silence as proof nothing happened.
6. Insurance Giant Aflac Breached Again — 4.4 Million Customers' Details Stolen
Aflac's Japanese life-insurance arm disclosed that hackers accessed its systems repeatedly over roughly ten days in June before being caught, stealing names, addresses, dates of birth, and insurance account details belonging to 4.38 million customers — the company's second major hacking incident inside a year.
Why it matters for your business: many small businesses hold cyber, liability, or health insurance policies with large insurers who store exactly this kind of personal data about your business and staff. You can't secure the insurer's systems yourself, but you can ask what personal data they hold on you, avoid handing over more than a policy strictly requires, and treat any breach notice from them as something to act on immediately, not file away.
7. A Teenage Hacker Behind Attacks on UK Retailers Is Extradited to Face US Charges
A 19-year-old accused member of the hacking group Scattered Spider — linked to attacks on UK names including Marks & Spencer, Co-op, and Harrods, plus Transport for London — was extradited from Finland to the US to face fraud and computer-intrusion charges. The group's signature move isn't sophisticated malware; it's calling a company's IT helpdesk or an employee directly, impersonating someone with legitimate access, and talking their way past security checks to get a password or MFA device reset.
Why it matters for your business: an arrest slows one person down, not the playbook — make sure whoever handles password or MFA resets for your business (an IT provider, or a named staff member) has a fixed verification step, such as calling back a number you already have on file, before resetting access for anyone who simply sounds legitimate on the phone or in a chat.
8. Most IT Support Companies Have Been Breached at Least Once in the Past Year
A new industry survey found that roughly three in four managed service providers (MSPs) — the outsourced IT companies many small businesses rely on for email, backups, and day-to-day support — reported at least one breach in the past year, with more than half breached two or more times. Ransomware groups increasingly target MSPs on purpose, because compromising one gives them a foothold into every client it supports at once.
Why it matters for your business: if you outsource your IT, ask your provider directly what happened the last time they were breached (or how they'd know if they haven't been), whether your business's access is kept isolated from their other clients, and whether they use MFA on their own admin tools — the same questions you'd want a customer asking you.
Sources
- The Hacker News — SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
- The Hacker News — Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
- The Hacker News — Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
- The Hacker News — Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
- BleepingComputer — DHS Confirms Hackers Breached HSIN Info-Sharing Platform
- SecurityWeek — Aflac Japan Data Breach Impacts 4.38 Million
- The Hacker News — 19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges
- Huntress — MSP Security Trends: 2026 Guide to Market Growth & Threats