[Security Digest] Patch this before tomorrow's deadline
Everyone's talking about the SharePoint bug racing toward a government patch deadline tomorrow. The story that should worry you more sat quietly inside a federal network for weeks before anyone said a word.
The Big 3
Cisco's SD-WAN bug just hit maximum severity, and it's already being exploited
Cisco has patched a vulnerability in its Catalyst SD-WAN Controller and Manager products that scored a perfect 10.0 on the CVSS scale, the highest rating possible. An unauthenticated attacker can impersonate a legitimate network peer and plant their own SSH key into the admin account's authorised keys file, no login required. Cisco Talos says a group it tracks as UAT-8616 is already exploiting it, and this isn't their first run at this exact product line.
What to do: if you run Catalyst SD-WAN Controller or Manager, on-prem or in the cloud, patch now and check for SSH keys you didn't add yourself.
Hackers sat inside a US government security network for weeks
DHS confirmed on 1 July that hackers breached the Homeland Security Information Network, the platform coordinating threat intelligence and emergency response across US law enforcement. The intrusion likely happened between late May and early June, during an active World Cup security operation, and it's still unclear whether anything was actually taken. DHS called it a breach. We'll call it what it is: a government network sat compromised for weeks before anyone outside noticed.
Why this matters: the data on HSIN is officially "unclassified" but operationally as sensitive as anything with a security stamp on it, protected with none of the rigour that label would normally demand.
Your on-prem SharePoint server has until tomorrow to get patched
CISA added a SharePoint remote code execution flaw, CVE-2026-45659, to its Known Exploited Vulnerabilities catalog this week and gave federal agencies until 4 July 2026, tomorrow, to patch it. That deadline only formally binds US federal agencies, but the exploitation behind it doesn't care who you work for.
What to do: this only affects on-premises SharePoint Server. If you're on SharePoint Online through Microsoft 365, Microsoft handles it and you can move on. If you run it yourself, patch today, not on your usual change-control schedule.
Quick Hits
Kemp LoadMaster's command injection bug is under active attack. A CVSS 9.6 flaw in Progress Kemp LoadMaster load balancers is already seeing exploitation attempts in the wild. If you run one, patch it and lock the management interface down to trusted networks only. Read more → (2 minute read)
Adobe quietly patched some maximum-severity bugs this week. ColdFusion and Campaign Classic both got critical fixes. ColdFusion has a long history of running quietly in enterprise stacks until someone remembers it exists, usually because an attacker found it first. Read more → (2 minute read)
The EU AI Act reaches full enforcement next month. From 2 August 2026, the higher-risk provisions become enforceable law with real penalties, and the Act applies to any company with EU users, wherever that company is based. Read more → (2 minute read)
Connecticut just added your brain to its list of protected data. From 1 July, neural data collected by consumer devices, think meditation headbands and focus wearables, counts as sensitive personal information under state law. One of the first US states to draw that line explicitly. Read more → (2 minute read)
Tool of the Week
A password manager that also stores and syncs passkeys across your devices, which increasingly matters as more services move to phishing-resistant authentication.
Who it's for: anyone with more than a handful of accounts still relying on password-plus-SMS-code MFA, which growing numbers of services are starting to treat as not good enough.
Caveat: it's a paid subscription with no permanent free tier, so if you only need basic password storage for one or two accounts, a free option will do the job just as well.
Protect Yourself
This week's phishing trend to know: fake renewal and delivery notices are showing up as calendar invites instead of emails, which slip past most spam filters entirely. In Google Calendar, go to Settings, then Event settings, then set "Automatically add invitations" to "No, only show invitations to which I've responded." That single change stops most of these before they ever reach your notifications.
Forward this to someone who cares about staying secure. They'll thank you.
Free weekly security briefing: futuretechnologyhq.com/newsletter
Some links in this newsletter may be affiliate links. We only recommend products we genuinely think are worth your time.