CISA warned Wednesday that attackers are exploiting CVE-2026-45659, a SharePoint RCE flaw patched by Microsoft in May, and added it to its KEV catalog on July 1 with a July 4 deadline for federal agencies. The deserialization vulnerability lets low-privileged authenticated users execute code remotely over the network, and more than 10,000 SharePoint servers remain exposed online.

Since then CISA has cataloged 11 Microsoft SharePoint bugs exploited in the wild, seven of which also featured in ransomware campaigns.
Federal agencies now have three days to patch or face compliance violations under BOD 26-04, underscoring how quickly CISA escalates actively exploited SharePoint flaws into mandatory remediation.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
A US judge has given Google one week to reduce friction in finding and installing third-party app stores on the Play Store after ruling the current process anticompetitive. The order stems from the company's 2025 settlement with Epic following the 2023 monopoly finding on app distribution.
Google released Gemini 3.7 Flash with enhanced capabilities in coding, web development, document analysis and automated agent execution while cutting token prices by 50% through the end of the year. The model is now live in 160 countries and powers the Gemini Spark agent exclusively for AI Pro and Ultra subscribers.
Apple has placed the iPhone X and the 2018 15-inch MacBook Pro on its obsolete products list, ending eligibility for hardware repairs at Apple and authorized providers. The move follows the company's seven-year policy after it stopped distributing the devices, with iOS 16 having been the last major iOS version for the iPhone X.