decrypted · 15 july 2026 · vulnerabilities and patching · surveillance and privacy · digital sovereignty
The AD FS zero-day hiding inside a record Patch Tuesday
Microsoft's July Patch Tuesday landed this week as its largest security update on record, well over 600 fixes, and two of the vulnerabilities in that pile were already being exploited before the patch arrived. One was in SharePoint, which UK IT teams have learned to expect by now. The other was in Active Directory Federation Services, the identity system a large share of British organisations use to let staff sign into Office 365, Azure and on-premises applications with one login. That second bug matters more than the SharePoint one: it is not a story about a sloppy web app, but about what happens when the system that vouches for everyone else's identity can be rewritten from the inside.
The passport office, not the passport
CVE-2026-56155 is rated "Important", not "Critical", and on paper it needs an attacker who already has a foothold on the AD FS server itself. Microsoft's own Detection and Response Team found it while cleaning up after real intrusions, which tells you it was not a theoretical bug hunt. Think of AD FS as the passport office every other application in the estate trusts without checking further: if a border guard sees a stamp from that office, they wave the holder through. This flaw lets someone who has already slipped into the building start stamping their own diplomatic passports. The privilege escalation happens locally, but the trust it forges travels everywhere the federation service is plugged in.
The Secure by Design lesson here is about blast radius, not patch speed. A bug that "only" grants local privilege escalation on a server most people never think about is easy to under-triage, precisely because identity infrastructure is designed to be invisible when it works. The NCSC's own guidance on patch waves makes the same point in general terms: know which systems, once compromised, let an attacker mint trust for everything downstream, and treat those differently from an ordinary application server, whatever the CVSS score says.
A familiar platform, and a bypass for when the laptop is gone
The SharePoint flaw in the same batch, CVE-2026-56164, is a missing-authentication bug reachable over the network with no login at all, and it too was caught in active use. SharePoint's repeat appearances this year carry their own lesson: patching one deserialisation bug does not retire the platform's attack surface, and Microsoft's advice this time is to enable antimalware scanning for SharePoint traffic, not just install the update. The same release also disclosed, though did not report as exploited, a BitLocker bypass that works with physical access to a device. For UK organisations with laptops that travel, the quieter reminder is that disk encryption is only as strong as the assumption that nobody gets their hands on the hardware, an assumption that fails first when a device is lost or stolen.
Also this week
A UK chip designer's name on a leak site, unconfirmed. The ransomware group D1R has claimed Arm, the Cambridge-based chip designer whose architecture sits inside most of the world's phones, saying it obtained an internal tool used to bypass two-factor checks after working from a leaked Synopsys database. Arm has not confirmed the claim, and this remains an extortion group's assertion, not a verified breach. It is worth watching regardless: attackers increasingly build access to one target from unrelated leaks at another, which is its own argument for not assuming a supplier's breach is irrelevant to you.
The Bank of England starts watching the cloud. From 13 July, HM Treasury's designation of AWS, Microsoft Azure, Google Cloud and Oracle as Critical Third Parties took effect, giving the Bank of England, the PRA and the FCA new powers to demand information and resilience testing where these providers underpin UK financial services. Deputy Governor Sarah Breeden noted that such providers "can introduce new forms of systemic risk" precisely because so much now depends on so few of them. It is not a data protection regime and does not touch firms outside financial services, but it is a template other UK regulators will be watching.
A line in the sand, and a register behind it. The Prime Minister this week described new legislation barring under-16s from social media as "a line in the sand", with rules expected in force from spring 2027. The harder question, pushed onto Ofcom with an October deadline, is what "highly effective age assurance" means in practice. Every credible method on the table ties a real identity to browsing behaviour at internet scale, which is why child safety campaigners and privacy groups are, for once, asking the same question: who holds that data once it exists, and for how long.
Sources
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
- Zero Day Initiative: The July 2026 Security Update Review
- NCSC: Preparing for a 'vulnerability patch wave'
- FCA: UK financial regulators to begin overseeing Critical Third Parties announced by Treasury
- D1R Ransomware Attack on ARM: Compromise of UK Tech Giant
- UK government draws legal line in the sand on social media age minimum
If any of this touches your own identity infrastructure or patch process, get in touch.
More like this
- The SD-WAN orchestrator that needed no login, and the one before it 29 july 2026
- A mislabelled maintenance job, and the outage it exported to Britain 27 july 2026
- The Zimbra bug that needed no click, and the year it went unpatched 24 july 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.