Future TechnologyFuture Technology
← Back to archive
Security Digest

[Security Digest] One bug just breached 100+ companies

17 July 2026

Before you read anything else: if your organisation runs SharePoint or Active Directory Federation Services, patch it today. The deadline is this afternoon, and two zero-days are already being used in the wild.

The Big 3

ShinyHunters hit 100+ companies through one Oracle PeopleSoft flaw

One vulnerability, more than 100 victims. ShinyHunters exploited a single flaw in Oracle PeopleSoft, the HR and payroll software countless large organisations run, to reach systems holding names, addresses, national insurance and social security numbers, and salary bank details. Nissan is among the confirmed victims, but the list runs wider. It's the same playbook the group used against HackerOne, Huntress, OneTrust and Snyk earlier this year: find one widely used platform, hit it once, extort everyone who used it.

Why this matters: if your employer uses PeopleSoft for HR or payroll, your data may already be out, whether or not you've been told yet. Be suspicious of any unexpected email referencing payroll, tax, or benefits this month.

Read more →

Microsoft's biggest Patch Tuesday ever includes two active zero-days

Microsoft shipped its largest Patch Tuesday on record this month, and two of the fixes were already being exploited before they shipped. CVE-2026-56164 hits SharePoint Server, CVE-2026-56155 hits Active Directory Federation Services. US federal agencies have until today, 17 July, to patch SharePoint and until 28 July for AD FS, under a binding government directive. That's a compliance deadline for federal bodies, but the urgency applies to any organisation running these systems.

What to do: IT admins, confirm the patches are applied today, not just scheduled. Everyone else, let Windows Update run and restart when it asks.

Read more →

Accenture confirms breach after hacker offers stolen source code for sale

A hacker calling themselves "888" put roughly 35GB of alleged Accenture data up for sale on 6 July, including source code, SSH keys, and Azure access tokens. Accenture confirmed the intrusion and says it's had "no impact on its financial position or operations." That's a line about Accenture's own books. It says nothing about the clients whose access keys might now be floating around.

Why this matters: if your organisation uses Accenture for consulting or managed services, ask whether shared credentials tied to that relationship have been rotated since 6 July. Don't wait to be told.

Read more →


Quick Hits

TRICARE West breach exposes health data of US military families. Hackers exposed health information belonging to thousands of TRICARE West beneficiaries. If you're covered, watch for an official notification letter and free credit monitoring offer. Read more → (source, 4 minute read)

CISA, NSA and allies warn of Russian state hackers targeting routers. A joint advisory from CISA, the NSA, FBI and international partners says Russian state-linked hackers are hitting poorly secured network gear across energy, government and healthcare sectors worldwide. The fix is unglamorous: change default credentials, patch firmware, disable unnecessary remote management. Read more → (source, 5 minute read)

EU's toughest AI Act rules take effect 2 August. High-risk AI provisions go into full force with fines up to €35 million or 7% of global turnover, steeper than GDPR's own ceiling. Applies to any organisation whose AI systems touch EU users, wherever they're based. Read more → (source, 3 minute read)

Ransomware halts production at Coca-Cola's Fairlife dairy business. An attack on the Fairlife subsidiary disrupted operations badly enough to temporarily suspend US production. No word yet on whether customer or employee data was touched too. Read more → (source, 3 minute read)


Tool of the Week

Proton Pass

A password manager from the team behind Proton Mail, with built-in two-factor codes and email aliasing so you're not handing out your real address to every site that asks.

Who it's for: anyone already using Proton Mail or Proton VPN who wants one account running their whole privacy stack, or anyone who specifically wants email aliasing built in rather than paid separately.

Honest caveat: the free tier only allows one signed-in device at a time. If you already like Bitwarden or 1Password, there's no urgent reason to switch.


Protect Yourself

Given this week's PeopleSoft breach, run your work email through haveibeenpwned.com now rather than waiting for a notification letter. If it comes back exposed, change your payroll portal password immediately and turn on two-factor authentication wherever HR systems allow it, most large employers do.


Forward this to someone who cares about staying secure. They'll thank you.

Free weekly security briefing: futuretechnologyhq.com/newsletter

Some links in this newsletter may be affiliate links. We only recommend products we genuinely think are worth your time.