Software vulnerabilities, particularly input validation flaws, can enable attackers to take over user accounts without requiring login credentials or user interaction, as demonstrated by Zoom's critical Windows software flaw that exposed account data including meetings, chats, and contacts.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
Zoom's wake-up call, zero-day SonicWall patch, 23andMe's growing breach bill
Added:From the CISO series, it's cybersecurity headlines.
>> [music] >> These are the cybersecurity headlines for Thursday, July 16th, 2026. I'm Sarah Lane.
Zoom's account takeover wake-up call.
Zoom patched a critical input validation flaw in its Windows software that could let an attacker take over a Zoom account over the network. The attack doesn't require a login, and the victim doesn't have to click anything. The bug affects older versions of Zoom Workplace for Windows, the Windows VDI client, and the Windows Meeting SDK. Zoom hasn't said the flaw is being exploited, but because a successful attack could expose meetings, chats, contacts, and other account data, the company is urging customers to update.
Two zero-days, one urgent SonicWall patch. SonicWall says attackers are exploiting two flaws in its SMA 1000 remote access appliances, the boxes that companies use to give employees and contractors secure access to internal networks. One is a maximum-severity server-side request forgery bug that can be reached without authentication. The other is a code injection flaw that can let an authenticated administrator run operating system commands on the device.
CISA has added both bugs to its known exploited vulnerabilities catalog.
Federal agencies have until July 17th to patch. Private organizations are being asked to treat this with the same urgency.
23andMe's breach bill keeps growing.
23andMe's 2023 breach has produced another settlement with a coalition of 42 state attorneys general. The states will receive $18 million from the company's bankruptcy funds to resolve claims tied to the breach, which exposed genetic and personal information belonging to 6.9 million people around the world. Attackers initially broke into about 14,000 accounts using reused passwords, then used the DNA relatives feature to reach data connected to millions more profiles, which included ancestry details, birth years, locations, family connections, and some health and genetic data. This comes after a June $46.75 million class action settlement for US customers.
The e-card with remote access.
Researchers at Forescout have detailed seasonal invite, a phishing campaign that turns the familiar e-card into a remote access trap. Since at least January, attackers have been sending fake holiday and party invitations that persuade Windows and Mac users to install legitimate remote monitoring and management software. Tools that are normally used by IT teams, which means they're signed, trusted, less likely to set off the same alarms as custom malware. But once installed, they give the attacker persistent control of the computer and a path to steal data or deploy more malicious software.
Forescout says parts of the campaign appear to have with AI assistants, making them easier to create and change as the calendar moves from one seasonal event to the next.
>> [music] >> Huge thanks to our sponsor, ThreatLocker. Every security leader is being asked the same question [music] right now. How do we enable innovation without creating unnecessary risk?
That's [music] the challenge behind cloud adoption, behind AI, behind automation, and behind every major technology decision. ThreatLocker helps organizations [music] take a zero trust approach to that challenge, giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's [music] why ThreatLocker is proud to support cybersecurity headlines, because security [music] works when innovation and control move together.
>> Okobot goes seed hunting. Kaspersky researchers say Okobot is not a single piece of malware, but a modular framework with more than 20 payloads for stealing files, browser data, credentials, and cryptocurrency. One component known as seed hunter waits for a Ledger or Trezor hardware wallet to be connected, then injects a fake recovery screen directly into the legitimate desktop wallet app. Because these surrounding software is real, the request for the recovery phase can look much more convincing than an ordinary phishing page. If the user enters the words, Okobot sends the seed phrase and device details to its command and control server, giving the criminals everything they need to drain that wallet. The campaign has reached hundreds of victims in more than 25 countries, with infections spreading through click fixlers and fake software packages on GitHub.
Patch Tuesday breaks the bug counter.
Microsoft's July Patch Tuesday set a new record with fixes for 570 security flaws, nearly three times the previous month's total. The release included 59 critical bugs, 145 remote code execution flaws, and 254 privilege escalation issues. Two zero days were already being used in attacks. One in Active Directory Federation Services and another in SharePoint, both of which can help an attacker gain higher privileges after getting a foothold. Microsoft also fixed a publicly disclosed BitLocker bypass, bringing the month zero-day count to three. The big total doesn't mean that 570 bugs are being actively exploited, that would suck, but it does give Windows and enterprise administrators an unusually large testing and patching job.
IBM rallies cybersecurity, accidentally?
Cybersecurity stocks surged after IBM CEO Arvind Krishna described customers as being distracted by rapidly changing security threats. Companies are still pouring a lot of money into scarce AI servers and storage and memory, but Krishna's comments suggested those projects aren't pushing cybersecurity out of the budget. Investors apparently took that as a signal the AI boom is creating more systems, data, and identities that need protection.
CrowdStrike, Okta, Palo Alto Networks, and Fortinet stocks all rose as a result, even though IBM's own shares fell on disappointing preliminary results.
Gemini gets a botnet side hustle. Trend Micro researchers say a Russian-speaking attacker used Google's open-source Gemini CLI as a hands-on assistant for building and running a small botnet. It wasn't a flaw in Gemini itself, instead the attacker supplied a jailbreak prompt and a detailed playbook that told the tool it was doing authorized penetration testing. Then Gemini helped write code, move the command and control system to a new server, configure a Cloudflare tunnel, and troubleshoot the migration when infected machines failed to reconnect. This all took about 6 minutes, and the attacker later used ordinary natural language prompts to check which computers were online, list files, and generate new infection links.
In practice, the botnet controlled eight machines at a dental clinic and had access to its open dental database.
If you have any thoughts on the news from today or about our show in general, be sure to reach out to us [email protected].
We'd love to hear from you. I am Sarah Lane reporting for the CISO Series. Stay cool and stay safe.
>> [music] >> Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
Related Videos

TOP 15 Data compression Interview Questions and Answers 2019 Part-2 | Data compression | Wisdom jobs
wisdomjobs
281 views•2019-06-28

CTS 158: 802.11w Management Frame Protection
ClearToSend
4K views•2019-02-04

NDSS 2019 Send Hardest Problems My Way: Probabilistic Path Prioritization for Hybrid Fuzzing
NDSSSymposium
496 views•2019-04-02

How realistic is Cities: Skylines?
CityBeautiful
159K views•2019-02-14

GUIs & TUIs: Choosing a User Interface for Your Python Project | Real Python Podcast
realpython
2K views•2025-04-04

The OSI Model - Explained by Example
hnasr
225K views•2019-05-12

Cloud Computing - Introduction
elithecomputerguy
98K views•2019-10-07

From Traveler's Dilemma to Dynamic Routing | Demystifying Networking
IITBombayJuly
5K views•2019-08-04
Trending

WOW! Judge TURNS THE TABLES on Trump in His OWN $10B LAWSUIT!!!
MeidasTouch
197K views•2026-07-23

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Steam and Xbox Just Dropped The Hammer On PlayStation
OhNoItsAlexx
9K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23