/
사이버 복원력

Patch Tuesday Fixed 622 Flaws. But It Didn't Fix Lateral Movement.

Microsoft’s July 2026 security release set a new record. The company fixed 622 flaws, tripling the old record of 200 addressed just a month earlier.

Two were already under attack, and Microsoft disclosed both as zero-day flaws:

  • CVE-2026-56155 in Active Directory Federation Services. An attacker who already has local access on an AD FS server can reach administrator privileges. Microsoft rated it 7.8.
  • CVE-2026-56164 in SharePoint Server. An unauthenticated attacker can escalate privileges over the network, no credentials needed. Microsoft rated it 5.3, or Moderate, and CISA confirmed active exploitation the same day.

The volume of vulnerabilities is just a symptom of the larger issue. As Mythos and other frontier AI systems advance, AI is helping security teams find hidden flaws faster and at a much greater scale. Every one of those flaws will eventually get patched. But patching does nothing about an attacker who's already inside the network.

Microsoft has warned that this progress will increase the operational demands on security teams. More flaws found means more updates to assess, test, rank, and deploy.

Finding vulnerabilities faster is undoubtedly good for security. But it doesn’t mean teams can fix every system at the same machine speed.

“Existing patch cycles already didn’t match the pace of vulnerability discovery and exploitation before Mythos,” said Michael Adjei, director of systems engineering at Illumio. “It certainly won’t match it now.”

Patching can close the entry point, but the real risk begins after attackers gain a foothold — when they chain weaknesses, steal credentials, escalate privileges, move laterally, and reach critical systems.

That’s a crucial distinction. A breach is defined not by the flaw an attacker used to get in, but by how far they travel afterward. Patching is a race defenders can’t win, and winning it wouldn’t change the outcome anyway. The one variable defenders actually control is the distance an intruder can cover once inside. And that distance is set by visibility, segmentation, and containment.

The patching window is closing

As we covered in  The Race to Stop AI From Turning Vulnerabilities Into Breaches, attackers have far less time to wait, and defenders have far less time to respond.

The Zero Day Clock shows that the median time from disclosure to confirmed exploitation fell from about 10 months in 2021 to just three hours in 2026.

Disclosure-to-exploitation collapsed from months to hours in five years. 출처: Zero Day Clock

Faster patching still matters because it narrows the window. But it doesn’t close it.

Teams should prioritize known exploited vulnerabilities, automate where possible, and shorten testing and approval cycles for urgent updates.

But patching has limits.

“Many organizations have legacy debt,” Adjei said. “They can’t just take down critical systems to apply a patch. Patching requires acquisition, regression testing, integrity checks, deployment, and validation.”

Those steps take time. Critical systems can’t always go offline, and updates must be tested before they reach production. Patching faster isn’t the whole answer.

That leaves an unavoidable gap between the day a patch ships and the day it’s deployed.

When attackers get there first

CISA’s July warning included an already exploited Microsoft SharePoint vulnerability, which raises a big question: What happens when an attacker reaches the vulnerable system before a patch is deployed?

A series of attacks a year earlier, the July 2025 ToolShell SharePoint campaign, shows what can happen. Attackers exploited SharePoint flaws across internet-facing, on-premises servers.

Microsoft identified three China-based threat actors exploiting the vulnerabilities:

  • Linen Typhoon: A Chinese state-backed espionage group that used the SharePoint flaws for initial access. The group has historically relied on existing exploits to compromise organizations and steal intellectual property.
  • Violet Typhoon: A Chinese state-backed espionage group that exploited the SharePoint flaws against exposed servers. The group is known for scanning internet-facing infrastructure, exploiting weaknesses, and installing web shells.
  • Storm-2603: A China-based actor that exploited the SharePoint flaws and attempted to steal SharePoint MachineKeys. Microsoft observed the group using the access to deploy Warlock ransomware and had previously seen it use LockBit.

Microsoft’s reporting shows that exploitation didn’t stop at the vulnerable SharePoint server. Storm-2603 used its access for discovery, credential theft, lateral movement with tools including PsExec and Impacket, and ultimately ransomware deployment.

The ToolShell campaign shows why exploiting a vulnerability is only the beginning. The flaws gave attackers a way in. What they did after gaining access determined how far the attack could spread.

How a vulnerability becomes access

A vulnerability is only a weakness. Attackers must still find a way to use it.

An attacker finds a flaw and builds or adapts an exploit. If the exploit works, it can let the attacker run code inside the vulnerable program. That code may open a remote connection, giving the attacker control of the system. From there, the attacker can install malware, raise privileges, or prepare to move further into the environment.

Not every exploit follows these exact steps. Some attacks use stolen credentials, built-in tools, or direct commands instead of shellcode and a reverse shell. But the goal is the same: turn a software flaw into access.

“There are two main things an attacker needs to do,” Adjei said. “First, exploit a vulnerability to gain a foothold. Second, use that foothold to spread through the environment and reach an objective.”

One common path looks like this:

  1. Discover the vulnerability. Attackers find weaknesses by reverse engineering, fuzzing, or analyzing code and dependencies.
  2. Exploit the vulnerable program. They use or adapt an exploit to take advantage of the flaw. This may enable remote code execution, bypass security controls, raise privileges, or expose information.
  3. Take control of program flow. In some attacks, shellcode or other malicious code lets the attacker control how the vulnerable program runs.
  4. Establish remote access. The attacker may open a reverse shell or another connection back to their infrastructure, giving them remote control of the compromised system.
  5. Deploy malware or additional exploits. With access established, the attacker can install malware, raise privileges, and prepare for lateral movement.

The foothold isn’t the final goal

Getting in doesn’t mean attackers have reached what they came for.

They begin by learning how the environment works. They may look for users, credentials, systems, services, and network connections. That discovery helps them find a path beyond the first compromised system.

Attackers can then move laterally with stolen credentials, trusted protocols, remote administration tools, or more vulnerabilities. They may also establish command and control so they can maintain access and direct the attack.

The final objective may be data theft, disruption, domain control, or ransomware.

“At that point, defenders should assume breach,” Adjei said. “Attackers rarely land directly on the system they want.”

“They may compromise a web front end or an endpoint, but their real target may be a critical database, a lab server, a high-value application, or a system connected to something more useful.”

After gaining a foothold, attackers discover the environment, move laterally, maintain access, and work toward their objective.

The risk is what attackers can reach next

Adjei sees a key difference between a vulnerability and a breach.

“The vulnerability is the means to get in; the goal is what they can reach next,” he said.

This is why severity scores and patch status are the wrong scoreboard. A CVSS rating describes a flaw in isolation; it says nothing about whether the vulnerable system is exposed, what it can connect to, or which critical assets sit one hop away. Those are the questions that determine whether an intrusion stays an incident or becomes a breach.

Patching closes the flaw. Breach containment stops the spread.

Patching remains essential, but it can’t always happen before attackers act — and it can’t remove access they have already gained.

That is where visibility, segmentation, and breach containment matter. Visibility shows how a compromised system connects to the rest of the environment. Segmentation limits unnecessary paths. Breach containment helps stop attackers from moving deeper.

“That does not mean patching is unimportant,” Adjei said. “It means reducing the ability of an attacker to exploit a foothold and move through the environment while patching is underway — or when a vulnerability is still unknown.”

침해 방지에 있어 가시성과 세분화가 필수적인 이유를 알아보세요. Schedule a breach containment demo today.

관련 문서

지금 일루미오 인사이트 체험하기

AI 기반 관찰 가능성을 통해 위협을 더 빠르게 탐지, 이해, 차단하는 방법을 알아보세요.