Microsoft's July Patch Tuesday landed at 570 CVEs with two actively exploited zero-days, more than four times the forecasted volume, because AI code scanning is now generating vulnerabilities faster than the industry can triage them. Gold Eagle is the government's acknowledgment that the system is breaking.
CVE-2026-53359 (Januscape), a 16-year-old Linux KVM flaw enabling VM-to-host escape, landed patches July 4 while the North Korean PolinRider supply chain campaign hit 100+ legitimate packages through stolen maintainer credentials, graduating beyond typosquatting into a method that subverts the trust signals defenders rely on.
Three independent threat actors operating simultaneously on npm this week confirm that adversaries have collectively assessed its namespace trust model as a high-yield, structurally undefended attack surface.
GitHub OIDC trusted-publishing solved the stored-credential problem and created a new attack surface in the same motion: three independent actors exploited it in a single week, producing malicious packages carrying valid provenance attestations.
The rapid exploitation of CVE-2026-42208 in LiteLLM marks the first confirmed weaponization of the AI API proxy layer, while TeamPCP's new ransomware partnership turns out to be a wiper with no recovery path.