Insikt Group's July 2026 CVE landscape report identifies 85 high-impact vulnerabilities requiring prioritization, 36 of which received a Very Critical Recorded Future Risk Score — a 44% increase from the prior month. Key trends include China-nexus threat actors (UAT-7810, Dysphoria) exploiting Ruckus device vulnerabilities to build operational relay box networks, and targeted attacks on email and collaboration platforms via malicious Office documents and Roundcube exploits. Campaigns from Cloud Atlas, UNK_MassTraction, CL-STA-1114, TA488, and Armored Likho leveraged CVEs ranging from 2018 to 2026 to deliver malware including CloudAtlasGo, IceCube, OWAReaper, and BusySnake Stealer. The report promotes Recorded Future's vulnerability prioritization, attack surface intelligence, and third-party risk products.
Questions this post answers
Which CVEs did UAT-7810 exploit to compromise Ruckus devices and expand the LapDogs ORB network?
UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network. The compromised devices were repurposed as relay infrastructure to support operations by other China-nexus threat actors, similar to the Dysphoria campaign which used infected hosts to proxy traffic and obscure backend C2 infrastructure. Security teams tracking China-nexus ORB network activity find the latest campaign details on daily.dev.
How many high-impact CVEs were identified in July 2026 and how does that compare to the previous month?
85 high-impact vulnerabilities were identified in July 2026 that should be prioritized for remediation, 36 of which received a Very Critical Recorded Future Risk Score. This represents a 44% increase in Very Critical-scored vulnerabilities compared to the prior month. Vulnerability management teams keeping pace with monthly CVE volume shifts track these trends on daily.dev.