Security Signal Weekly: July 18-24, 2026 0 ▲ CybersecKyle 6 hours ago · 9 min read1700 words · Tech · hide · 0 comments OverviewThis edition is landing Thursday because last Friday got away from me. The July 18-24 window was defined by a familiar but uncomfortable pattern: security and management platforms became the attack path. SharePoint, firewall consoles, VPN gateways, IT service management, AI workflow builders, routers, and product lifecycle systems all demanded more than a routine patch checkbox.Reality check: When the vulnerable product controls identity, policy, remote access, support workflows, or engineering data, patching is only step one. Verify the fixed version, review exposure, and look for evidence that somebody arrived first.Top 10 Security Signals1. Attackers used a new SharePoint RCE to steal machine keysWhat happened: Attackers began exploiting CVE-2026-50522 shortly after public proof-of-concept code appeared. The critical deserialization flaw affects on-premises SharePoint Server 2016, 2019, and Subscription Edition; Microsoft’s July security update fixes it, while CERT-EU says… No comments yet. Log in to reply on the Fediverse. Comments will appear here.