STRATQUAD
CYBER THREAT INTELLIGENCE BRIEF
Daily Brief · 18 July 2026 · 24h windowRISKCRITICAL
StratQuad CTI Daily Brief, 18 July 2026
Compiled from 52 monitored sources · 305 articles reviewed

Today’s Briefing

INC Ransom is exploiting two zero-day vulnerabilities in SonicWall SMA mobile access appliances to gain root-level access, marking active in-the-wild abuse of edge devices that sit on enterprise perimeters. Separately, Microsoft disclosed CVE-2026-58644, an unauthenticated remote code execution vulnerability in SharePoint Server already under exploitation, though the advisory does not yet identify the threat actor or campaign behind observed activity.

Top Stories

  1. Inc Ransomware Exploits SonicWall SMA Zero-Days
  2. CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
  3. AutomationDirect Productivity Suite
  4. Rockwell Automation Arena
  5. Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

Full brief available to subscribers

The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.

Get the brief at 07:00, every weekday.

The day's UK security intelligence, read and ranked so you start informed: the stories that matter, the IOCs your SIEM needs, and the actions worth taking first.

← All briefs