Microsoft patches 570 flaws as ransomware and WordPress exploits surge
In July, a wave of cyber threats combined classic ransomware schemes, new WordPress remote‑code‑execution flaws and the misuse of AI‑enabled development tools. Attackers compromised repositories and AI environments to steal credentials and data, while large‑scale ransomware extortion and WordPress‑related DoS attacks were reported.
Microsoft responded with its largest monthly update to date, fixing 570 security flaws, including 59 rated critical. The patch addresses three zero‑day vulnerabilities in Active Directory Federation Services, SharePoint and BitLocker, and a high‑severity Remote‑Code‑Execution issue in Microsoft Copilot (CVE‑2026‑48561). Security experts advise organisations to maintain strict patch discipline, secure identities and monitor supply‑chain risks.