SAMURAI CYBER WATCH

Issue #10 — July 3, 2026

Practical Cyber Intelligence for Business Leaders in Non-Superpower Nations

THIS WEEK'S BRIEFING

SharePoint Zero-Day and the Patching Gap Nobody Warned You About

A delayed advisory left SharePoint servers worldwide exposed for weeks. IoT routers with no patch in sight. Nation-state APTs refining kernel-level tradecraft. This week's incidents share one thread: the gap between knowing and acting.

THE KEY DEVELOPMENT

MICROSOFT SHAREPOINT SERVER VULNERABILITY CONFIRMED ACTIVELY EXPLOITED — AN UNUSUAL DISCLOSURE PROCESS CREATED A DANGEROUS PATCHING GAP

On July 1, 2026, U.S. authorities formally confirmed active exploitation of a vulnerability in SharePoint Server. Dismissing this as yet another case of a known vulnerability being exploited, however, would be missing the real issue.

The core problem here is not the vulnerability itself — it is the irregularity of the disclosure process. A fix had already been delivered in the May 2026 Patch Tuesday update. Yet no advisory accompanied the release at launch. The advisory appeared only later, through an out-of-band process I have rarely seen in more than 20 years in this industry.

Why does that matter? Patch prioritization decisions always begin with risk perception. Without an advisory, many system administrators had no reliable way to gauge the severity of that fix. The reasoning that "it is just the monthly patch — we can handle it at the next scheduled maintenance window" likely spread quietly across organizations worldwide. As a result, SharePoint servers around the globe may be under active attack at this very moment.

SharePoint is far more than a file-sharing tool. It serves as a corporate intranet portal, an approval and workflow management platform, and a repository for sensitive documents. A successful compromise creates a natural pivot point for lateral movement. Now that exploitation has moved from theoretical to confirmed, there is no time left for deliberation.

JAPAN LENS: THIS WEEK'S JAPAN-SPECIFIC RISKS THROUGH 20 YEARS OF EXPERIENCE

The two incidents I want to flag most urgently for readers in Japan this week are a tech support scam campaign and a phishing operation targeting the hotel industry. What sets these apart is not technical sophistication — it is their scale and targeting precision. In my assessment, these represent qualitatively distinct threats.

A support scam distributing more than 13 million spoofed emails has long since left the category of individual consumer nuisance. Once businesses enter the target pool, a realistic scenario emerges: one employee calls a phone number displayed on a fake support screen, and the attacker walks away with access to the corporate network. With the cost of generating natural-sounding Japanese-language phishing emails falling dramatically, I expect this threat to accelerate. The quality of attacks is improving faster than organizational security awareness training can keep up.

The abuse of the TON blockchain — The Open Network, a decentralized blockchain linked to the Telegram messaging app — in phishing attacks against the hotel sector also deserves serious attention. Because traffic to the TON network routes through decentralized infrastructure, traditional detection systems often lack the visibility to identify or block command-and-control communications. That technical blind spot is compounded by a human one: frontline hospitality staff, working under the pressure of rising inbound tourism demand, represent a high-value, high-vulnerability entry point. For a country that has staked a significant part of its economic strategy on tourism, cybersecurity hygiene in the hospitality sector is no longer a matter for individual businesses — it is a national infrastructure conversation.

The attack on Kanafuku Hyoka Guide, a care-fee calculation support system used in Japan's long-term care sector, is another reminder of how exposed healthcare and social care systems remain. These systems are prime targets precisely because disruption carries immediate human consequences, giving attackers enormous leverage. That structural asymmetry — the cost of stopping is enormous, the cost of attacking is low — is especially acute in life-critical services.

BEYOND THE EPICENTER: WHAT SMALL AND MIDSIZE BUSINESSES SHOULD TAKE AWAY THIS WEEK

"We do not use SharePoint." "ColdFusion has nothing to do with us." If those are your first reactions, I would encourage you to pause for a moment before moving on.

The incidents this week share a consistent pattern. Attackers consistently pursue systems that are widely deployed but routinely under-managed. That risk surfaces most sharply in organizations that have outsourced IT management or rely on a single internal staff member. When responsibility is delegated without oversight, the true severity of a vulnerability can get lost in translation — and time passes without anyone realizing it.

The Seiko Solutions IoT routers, SkyBridge MB-A110 and MB-A100, are a textbook example. These devices, widely deployed in manufacturing facilities and healthcare environments, are operating with no patch available and no fix scheduled. "It is still running, so there is no problem" is one of the most dangerous judgments I have encountered in this field. A system being operational and a system being secure are entirely different things.

My message to small and midsize business owners is straightforward. Right now, verify the support status of every system and network device your organization relies on. If you are running even one end-of-life device, you are already hosting a known entry point inside your own network. If budget is a constraint, physically isolate that device from the rest of the network or cut its internet connection. There is always something you can do without spending money.

STATE ACTOR WATCH: THIS WEEK'S NATION-STATE ACTIVITY — GAMAREDON AND FISHMONGER REFINE THEIR TRADECRAFT

Two advanced persistent threat groups were reported active this week. I am not here to assign geopolitical blame, but documenting shifts in technical tradecraft has real defensive value.

On Gamaredon, assessed as a Russia-affiliated group, ESET Research published an analysis describing how the group is abusing legitimate online services as command-and-control infrastructure, combining tunneling and dead-drop techniques to evade detection. Tunneling involves encapsulating malicious traffic inside legitimate protocols. Dead-drop resolvers involve embedding command data into legitimate web services for malware to retrieve. Because traffic to legitimate platforms typically passes freely through firewalls and data loss prevention systems, this approach is exceptionally difficult to defend against. Ukraine is cited as the primary target, but the same techniques are transferable to any organization operating in a geopolitically sensitive environment.

On FishMonger, an APT group with reported links to China, researchers confirmed exploitation of Windows kernel drivers via a backdoor called SprySOCKS. The kernel is the core layer of an operating system. Malware operating at that level can potentially disable the detection logic of conventional endpoint detection and response solutions. FishMonger has a documented track record of targeting government agencies and research institutions across the Asia-Pacific region. Organizations in Japan involved in research or defense-adjacent supply chains should be clear-eyed about the possibility that they are indirect targets.

DEFEND WITHOUT CHOOSING SIDES

Practical defensive actions drawn from this week's incidents

① Verify whether the May 2026 Patch Tuesday update has been applied to all SharePoint Server instances. If it has not, initiate an emergency change management process immediately. Given the delayed advisory, also check whether the significance of this patch was accurately communicated internally. In my experience, situations where the technical team knew but leadership did not — or vice versa — are far more common than organizations expect.

② Apply out-of-band patches to all Adobe ColdFusion environments without delay. ColdFusion has been embedded in core business systems for decades, and Adobe has officially characterized the exploitation risk as high. Waiting for the next scheduled maintenance window is not an acceptable option at this stage.

③ For Cisco Unified Communications Manager (CVE-2026-20230), patching alone is not sufficient. Combine it with firewall restrictions to limit external access. Server-side request forgery exploitation enables internal network reconnaissance — revisit access controls on every network segment with visibility into UCM.

④ For AI and machine learning workloads running the NVIDIA Container Toolkit, confirm your version and update to the latest release. GPU Operator is also within the affected scope. Ensure both infrastructure and application teams are aware. In siloed organizations, this type of cross-functional information frequently falls through the cracks.

⑤ Any organization running Seiko Solutions SkyBridge MB-A110 or MB-A100 should immediately assess those devices' internet exposure and begin planning a migration to supported alternatives. With no patch available, network isolation and blocking external access are the top priorities. The most dangerous state of all is one where nobody has made a decision and the device simply keeps running. That needs to end.

NEXT ISSUE

Next week, we continue tracking the evolving threat landscape — including any further developments on the SharePoint exploitation campaign and ongoing APT activity across Asia-Pacific. See you Friday.

About us: This newsletter is written from Japan — a country that has been simultaneously targeted by three nation-states (China, Russia, and North Korea) for over a decade. Two of these three (China and Russia) are UN Security Council permanent members with veto power; one is a nuclear-armed state operating outside the international rules-based order. We are not American. We are not Chinese. We have no geopolitical agenda except one: helping ordinary people and small businesses in non-superpower countries protect themselves from digital warfare they never signed up for.

Written by a Japan-based information security professional with over 20 years of experience, in collaboration with AI assistants.

© 2026 Samurai Cyber Watch. Redistribution with attribution permitted for non-commercial use.