vCISO Cybersecurity Intelligence Brief: July 2026

vCISO Cybersecurity Intelligence Brief July 2026 tracesecurity

Executive Summary

This month’s brief addresses the record-breaking July Microsoft Patch Tuesday release (621 vulnerabilities, the largest single-month release in Microsoft history) with two flaws already being exploited, an ongoing Qilin ransomware campaign against Palo Alto Networks firewalls hitting financial institutions, a critical SharePoint vulnerability affecting on-premises deployments, and lessons learned from the Nacha ACH fraud monitoring Phase 2 deadline that took effect June 22.

Financial services ransomware incidents were up 76% in Q1 2026 versus Q1 2025. We provide staff training on recognizing suspicious VPN and remote access activity, and outline best practices leadership and IT teams can use together to strengthen defenses.

621

Vulnerabilities Fixed in
July Patch Tuesday (Record)

76%

Increase in Financial
Ransomware Incidents Q1 YoY

78%

of Financial Vendors Have
Critical Patching Failures

Emerging Threat Landscape

The following threats have been identified as having significant relevance to community banks, credit unions, and savings institutions during the current reporting period.

CRITICAL: Record-Breaking Microsoft Security Update Release

On July 8, Microsoft released the largest single-month security update in the company’s history—fixing 621 vulnerabilities across Windows, SharePoint, Office, and other products. Two of these vulnerabilities are already being actively exploited by attackers, meaning criminals were using them before the patches were even available. Security researchers have described this month’s release as a “bug apocalypse” and are urging institutions to prioritize patching rather than waiting for their regular monthly cycles.

What this means for your institution: Every institution running Microsoft products—which is essentially every financial institution—has significant patching work this month. The volume of updates makes it harder for IT teams to prioritize, and delaying any of the actively exploited flaws increases the risk of a successful attack. Two of the exploited flaws affect Active Directory Federation Services and SharePoint, both of which are commonly used by community banks and credit unions.

For Leadership: This month’s patching volume warrants a special conversation with your IT team or TSP. Ask specifically about the two actively exploited vulnerabilities (CVE-2026-56155 and CVE-2026-56164) and confirm patching timelines. Given the scale of this release, expect IT to need more time than usual to test and deploy—but the highest-risk items should still be addressed within your 72-hour emergency patching SLA. Document the response in your risk register.

For IT/Operations: Prioritize patches based on active exploitation and CVSS scores. Immediate priorities: CVE2026-56155 (AD FS elevation of privilege, exploited in the wild), CVE-2026-56164 (SharePoint elevation of privilege, exploited in the wild), CVE-2026-57092 (Windows VMSwitch/Hyper-V, CVSS 9.9), and CVE-2026-50522 / CVE-2026-58644 (SharePoint RCE pair, CVSS 9.8, demonstrated at Pwn2Own Berlin). Also review CVE-2026-55040 (SharePoint auth bypass) and CVE-2026-50661 (BitLocker bypass). Verify TSP patching status and document timing for examination evidence.

CRITICAL: Qilin Ransomware Group Exploiting Palo Alto Firewall Flaw

The Qilin ransomware group—a criminal operation similar to the DragonForce group covered last month—has been actively exploiting a serious flaw in Palo Alto Networks firewalls to break into corporate networks and deploy ransomware. The flaw affects the GlobalProtect VPN feature, which allows employees to work remotely. Attackers can bypass the login process entirely and establish a VPN connection as if they were a legitimate employee. Once inside, they typically deploy ransomware across an entire Windows network within hours, and in some cases also steal data before encrypting it.

Security researchers at Arctic Wolf documented multiple financial and business sector victims in June 2026. Palo Alto Networks released a fix for this flaw on May 13, and CISA added it to its Known Exploited Vulnerabilities catalog on May 29. Any institution that has not yet applied the fix is at significant risk.

What this means for your institution: If your institution uses Palo Alto Networks firewalls with GlobalProtect VPN —very common in community banks and credit unions—this is a direct and urgent threat. The attack does not require any employee to click a link or enter credentials; the attackers simply exploit the firewall directly. If your VPN is compromised, attackers have the same level of access as your remote employees

For Leadership: Ask your IT team or TSP whether your institution uses Palo Alto Networks GlobalProtect VPN. If yes, confirm in writing whether the May 13 patch (CVE-2026-0257) has been applied. If not applied, ask why and what compensating controls are in place. Given active exploitation, this should be treated as an emergency. Also review whether authentication override cookies are enabled on your firewalls—the flaw is only exploitable in specific configurations.

For IT/Operations: Verify PAN-OS is updated to a patched version. Affected versions include PAN-OS 12.1, 11.2, 11.1, and 10.2 prior to specific patched builds, plus certain Prisma Access releases. Review whether authentication override cookies are enabled alongside certificate-based configurations (the exploitable combination). Review VPN session logs for suspicious hostnames (Arctic Wolf reports attackers self-identifying as “kali”), unfamiliar geolocations, and unauthorized access. Look for indicators of Qilin post-exploitation: AnyDesk/LogMeIn, Ngrok tunneling, rclone to MEGA cloud storage. Panorama and Cloud NGFW deployments are not affected.

HIGH: Multiple Critical SharePoint Vulnerabilities Actively Being Exploited

Microsoft SharePoint—the platform many financial institutions use to share documents and collaborate internally—has been the target of multiple serious vulnerabilities this month. One of the newly patched flaws is already being exploited in the wild, and separate SharePoint attacks from earlier this year (initially reported in July) continue to affect on-premises SharePoint servers. Attackers who successfully compromise a SharePoint server can access every document stored there, including potentially sensitive customer information, contracts, and internal communications.

What this means for your institution: If your institution uses on-premises SharePoint (rather than SharePoint Online through Microsoft 365), this is a significant exposure. SharePoint often contains highly sensitive documents that would trigger customer notification obligations under GLBA if exposed. Even institutions moving to cloudbased SharePoint should review what data currently sits on on-premises servers.

For Leadership: Ask your IT team whether your institution uses on-premises SharePoint or SharePoint Online (part of Microsoft 365). If on-premises, ask when the July patches were applied and whether the server has been reviewed for signs of compromise from any prior SharePoint incidents. Consider whether migration to SharePoint Online is appropriate—it eliminates this category of on-premises exposure.

For IT/Operations: Identify all on-premises SharePoint Server deployments (Subscription Edition, 2019, 2016). Apply July patches immediately, prioritizing CVE-2026-56164 (actively exploited), CVE-2026-55040 (auth bypass), and CVE-2026-50522/58644 (RCE pair, CVSS 9.8). Review server logs for signs of compromise. Evaluate migration to SharePoint Online. Document remediation for examination evidence.

HIGH: Financial Services Ransomware Attacks Up 76% Year Over Year

Industry data from the first half of 2026 confirms a dramatic increase in ransomware attacks against financial services organizations. Black Kite’s 2026 Financial Services Cybersecurity Report documented 65 finance-sector ransomware incidents in Q1 2026 alone, a 76% increase over the same quarter in 2025.

Total finance-sector ransomware incidents grew from 156 in 2024 to 202 in 2025, and the pace is accelerating in 2026. Vendor-related exposures continue to be the biggest risk multiplier—the same report found that 78% of financial services vendors have critical-level patch management failures, and 50% of the broader ecosystem of 17,000+ financerelated vendors has similar issues.

What this means for your institution: The financial services sector is now among the most targeted industries for ransomware, and your vendor ecosystem is a bigger risk than your own institution’s controls. A successful attack against a single service provider can affect dozens or hundreds of institutions simultaneously, as demonstrated by the Korean Leaks campaign earlier this year (32 South Korean financial institutions compromised through a single managed service provider).

For Leadership: Request updated SOC 2 Type II reports from all critical vendors. Ask specifically about patch management timing—this is where 78% of vendors have gaps. Review your vendor contracts for incident notification language: does the contract require notification within 24 hours of a security event affecting your institution’s data? Review your fourth-party risk (your vendors’ vendors)—this is where concentrated risk hides

For IT/Operations: Review vendor management program controls: SOC 2 exceptions, CUEC compliance status, and patch management SLA performance. Verify that critical vendors patch Critical and Known Exploited Vulnerabilities within 30 days. Evaluate fourth-party concentration risk—identify which of your vendors share the same downstream providers. Review email authentication for all critical vendors (DMARC, DKIM, SPF); Black Kite found 47 finance vendors with misconfigured DMARC and 37 with misconfigured DKIM.

MEDIUM: Nacha ACH Fraud Monitoring Phase 2 — Now In Effect

The second phase of Nacha’s ACH fraud monitoring rules took effect on June 22, 2026 (the practical compliance date, since the formal June 19 date fell on a federal holiday). Phase 2 removes the previous volume threshold, meaning the fraud monitoring requirements now apply to ALL non-consumer originators, third-party service providers, and third-party senders regardless of transaction volume—and to all remaining RDFIs for credit monitoring.

The rule requires institutions to establish written, risk-based fraud monitoring processes designed to detect ACH entries initiated due to fraud, including business email compromise and “false pretenses” schemes. Regular fraud detection monitoring establishes baseline activity, making unusual activity easier to spot.

What this means for your institution: Every community bank, credit union, and savings institution that originates or receives ACH transactions is now subject to Phase 2 requirements—even those below the Phase 1 volume threshold. Examiners will begin looking for evidence of compliance immediately. The rule specifically calls out business email compromise, vendor impersonation, and payroll diversion as the fraud types institutions must be prepared to detect.

For Leadership: Confirm with your core processor and ACH service provider that Phase 2 fraud monitoring processes are documented and operational. Ask for evidence of the written procedures and how they are reviewed annually. Coordinate with your BSA/AML team so ACH fraud monitoring is integrated with existing suspicious activity detection. Update your policies to explicitly reference the “false pretenses” fraud category. Brief your Board on Phase 2 compliance status.

For IT/Operations: Verify implementation of risk-based fraud monitoring covering velocity checks, anomaly detection, and behavioral baselines. Ensure standardized Company Entry Descriptions (“PAYROLL” and “PURCHASE”) are properly used for applicable transaction types. Document the written fraud monitoring process, the annual review schedule, and the escalation procedures. Coordinate with core processor and third-party providers to confirm their compliance status.

Recognizing Suspicious VPN and Remote Access Activity

This month’s ransomware attacks against financial institutions all share a common starting point: attackers used a flaw in remote access technology (VPN) to break in as if they were a legitimate employee working from home. Once inside, they had the same access an employee would have. This means every employee who uses remote access—or who supports employees who do—has a role in noticing when something isn’t right. This training module is designed to be shared with all staff, including non-technical employees.

What We Used to Assume

  • VPN means the connection is safe
  • Firewalls block everything bad
  • IT would tell us if something was wrong
  • Password + MFA is enough by itself

What We Know Now

  • Attackers can exploit VPN flaws to log in as employees
  • Firewalls have flaws that need immediate patching
  • Employees often see suspicious activity before IT does
  • Anyone can be the first line of defense

5 Actions Every Employee Can Take

REPORT – Unexpected Login Alerts, No Matter How Small

If you get a login notification, MFA prompt, or password reset alert that you did not initiate, report it to IT immediately—even if you dismiss it and nothing else happens. These small alerts are often the first sign an attacker has your credentials. Never approve an MFA prompt you didn’t start yourself. When in doubt, deny and report.

CHECK – Where You’re Logged In From

Most email and cloud services (Microsoft 365, Google Workspace) show you a list of recent logins. Occasionally review this list. If you see a login from a city, state, or country you weren’t in, or from a device you don’t recognize, report it to IT immediately. This is one of the earliest signs of a compromised account.

NOTICE – If Your Remote Session Feels Different

If you connect to work remotely and something feels unusual—a longer than normal connection time, files opening on their own, unexpected pop-ups, cursor movement that isn’t yours—that’s a signal. Disconnect immediately and call IT from a separate device (like your phone). Attackers who have taken over a remote session can watch and control everything you’re doing.

SPEAK UP – If Someone Claims to Be from Support

Attackers frequently call employees claiming to be from IT, a software vendor, or the bank’s VPN provider.
They may ask you to install remote access software, approve an MFA prompt, or share a verification code.
Legitimate IT will never ask you to do these things without a scheduled request. When in doubt, hang up
and call IT back at a number you know is real.

PROTECT – Keep Your Devices Updated

The attacks described in this month’s bulletin all exploited software that was out of date. This applies to
your personal devices too, especially if you access work email or systems from them. Turn on automatic
updates for your phone, tablet, and computer. When your device prompts you to restart to complete an
update, do it. Small habits protect the whole institution.

Information Security Best Practices

The following practices should be continuously reinforced across your organization. These recommendations are aligned with FFIEC IT Examination Handbook guidance and represent foundational controls that examiners expect to see in every financial institution. Each section includes guidance for both leadership oversight and IT/operations implementation.

VPN and Remote Access Security

Every ransomware attack described in this month’s brief started with a flaw in remote access technology. VPNs, firewalls, and remote access tools now sit at the front line of your institution’s defenses—they must be treated as some of the most critical assets to patch and monitor.

For Leadership:
  • Ask your IT team for a complete inventory of remote access tools in use, including those managed by TSPs
  • Require quarterly reporting on VPN and firewall patch status; make this a Board-level metric
  • Confirm your institution has phishing-resistant MFA (hardware tokens or passkeys) for VPN access
  • Include VPN compromise scenarios in your annual tabletop exercise
For IT/Operations:
  • Maintain a current inventory of all remote access tools, including vendor-managed instances
  • Apply patches to VPN and firewall devices within 72 hours of Critical/KEV disclosure
  • Require phishing-resistant MFA for all remote access; disable authentication override cookies where possible
  • Review VPN session logs weekly for unusual hostnames, geolocations, or session patterns
  • Segment VPN-accessible networks; do not grant broad access from remote connections
Managing High-Volume Patch Releases

July’s record-breaking Patch Tuesday release of 621 vulnerabilities is not an anomaly—vulnerability disclosure volumes continue to grow. Institutions need a scalable approach to patching that prioritizes based on realworld risk rather than trying to patch everything equally.

For Leadership:
  • Ensure your IT team has access to threat intelligence sources that identify actively exploited vulnerabilities (CISA KEV, FS-ISAC)
  • Approve a risk-based patching prioritization framework: actively exploited first, then Critical, then High/Medium
  • Recognize that high-volume months may require additional IT resources or extended maintenance windows
  • Include patch management performance in your IT steering committee agenda
For IT/Operations:
  • Subscribe to CISA KEV catalog updates as your primary prioritization signal
  • Deploy automated patch management tooling for standard endpoints and servers
  • Establish and document patch prioritization tiers with defined SLAs (72 hours for KEV/actively exploited; 30 days for other Critical)
  • Maintain a current, accurate asset inventory—the foundation of effective patching
Vendor and Third-Party Risk

With 78% of financial services vendors having critical patch management failures and 76% year-over-year growth in financial ransomware incidents driven largely by vendor compromises, third-party risk is the fastest growing exposure for community banks and credit unions.

For Leadership:
  • Review vendor contracts for 24-hour incident notification language; renegotiate contracts without adequate provisions
  • Request updated SOC 2 Type II reports from all critical vendors and review exceptions
  • Understand your fourth-party concentration risk—who your vendors depend on
  • Ensure vendor risk is a recurring Board agenda item
For IT/Operations:
  • Verify critical vendor compliance with your patch management SLA expectations
  • Review vendor DMARC/DKIM/SPF configurations; require enforcement-level email authentication
  • Assess and document CUEC (complementary user entity control) compliance status
  • Maintain a fourth-party dependency map for critical vendor relationships

Add a vCISO to your team today

Let’s see how we can help meet your cybersecurity and compliance goals

Resources

FFIEC IT Examination Handbook: ithandbook.ffiec.gov
CISA Alerts & Advisories: cisa.gov/known-exploited-vulnerabilities-catalog
CISA Ransomware / Scattered Spider Advisory: cisa.gov/news-events/cybersecurity-advisories/aa23-320a
Microsoft May 2026 Patch Tuesday: msrc.microsoft.com/update-guide
Cisco SD-WAN Security Advisory: sec.cloudapps.cisco.com/security/center/publicationListing.x
FS-ISAC Threat Intelligence: fsisac.com

Feel free to share our content.