Critical SharePoint Bug Under Attack
The flaw (CVE-2026-50522) affects SharePoint Enterprise Server 2016 and 2019 as well as SharePoint Subscription service. Microsoft released the fix for this vulnerability on July 14.
All topics
The flaw (CVE-2026-50522) affects SharePoint Enterprise Server 2016 and 2019 as well as SharePoint Subscription service. Microsoft released the fix for this vulnerability on July 14.
This week we have some old-school disclosure drama when a researcher used full disclosure after months of silence from Cursor, then we discuss the enormous Patch Tuesday from Microsoft–662 bugs–and what it might mean going forward, and finally some news about DoJ sanctions and Scattered Spider members being sentenced. Links Cursor bug: https://decipher.sc/2026/07/15/bug-in… First VPN […]
This exploit occurs entirely in the background, requiring no user approval, dialogue prompts, or interaction.
The bug is a modern twist on a Clinton-era piece of known Unix badness: following symbolic links.
Hacker and legendary vulnerability disclosure expert Katie Moussouris of Luta Security joins Dennis to talk about the Fable 5 munitions classification controversy, the recent re-emergence of the disclosure debate, how AI-assisted bug hunting is reshaping the defensive landscape, and what the future holds for attackers and defenders.
This week was blessedly free of any major supply chain compromises, so we start by talking about new research from Anthropic on the shrinking window between bug disclosure and exploitation, then we discuss the changing patch schedule for Cisco and how all of this is changing the prioritization process for security teams, and finally we […]