ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
Defused Cyber reported that adversaries are actively chaining the authentication bypass flaw CVE-2026-55040 with the code execution vulnerability CVE-2026-63520 to target Microsoft SharePoint environments. While full remote code execution has not yet been confirmed in honeypot tests, the observed probing indicates an imminent risk for unpatched deployments.
In other infrastructure threats, the Shadowserver Foundation identified the Dysphoria botnet as controlling nearly 296,000 compromised IoT devices primarily for DDoS operations, recently adding residential proxy capabilities. Additionally, CISA detailed a series of July cyber attacks attributed to Iranian actors that targeted more than 100 internet-exposed U.S. water and wastewater systems via vulnerable programmable logic controllers.