Notes from the Chief Security and Trust Officer: July 2026 in Review

July was a busy month at Blackpoint Cyber, with new product capabilities, research, and customer-focused improvements across the business. Blackpoint keeps investing in the platform, our Security Operations Center (SOC) keeps stopping attacks around the clock, and our Adversary Pursuit Group (APG) keeps finding the threats nobody else has named yet. Each layer depends on the one above it. Here is how that played out this month, from the top down. 

Blackpoint: Platform and Trust 

The biggest platform news is that our AI SOC Agent for ITDR is now generally available. This is our first autonomous response capability, and it is built to shut down credential-based attacks on Microsoft 365 and Google Workspace in under two minutes on average, sometimes in as little as 21 seconds, at no extra cost on any ITDR tier. Autonomous response only works if the SOC and the intelligence behind it are good enough to trust it, so this is as much a statement about our people as it is about the technology. It is also the clearest example yet of what I mean when I say AI acts faster while human judgment secures the outcome. The agent is fast because the people who trained it already knew what right looks like. 

We also passed our SOC 2 Type II audit again, with zero exceptions, our fourth consecutive clean year, covering May of 2025 through April of 2026. It is not flashy, but it is proof that we handle your data and your customers’ data the way we say we do.

And Microsoft’s July Patch Tuesday tested every layer of that trust at once. A record 570 fixes came down, two of them already being exploited in AD FS and SharePoint, and Progress had to scramble an emergency zero-day fix for ShareFile’s Storage Zone Controller. Guidance went out to partners the same week we saw it, because a platform is only as trustworthy as how fast it moves when things break. 

The SOC: stopping it in real time 

This is where the platform meets the fight, every week, without exception. Four Threat Pulses went out in July, more than 395 incidents observed, and the SOC disrupted 84 to 88 percent of them before a single payload deployed. Half a year into 2026, we are past 1,900 incidents observed with better than two thirds stopped cold. 

Every one of those weeks carried a ClickFix style lure wearing a new disguise such as week one with CastleLoader and CastleRAT and week two with HijackLoader alongside a resurfaced NodeSnake tied to the Interlock ransomware crew. Week three had a STX RAT chain hidden inside a fake browser update task. Week four brought an in-memory Overlord RAT variant paired with a RAT that resolves its command and control through an Ethereum smart contract, which was a technique we had not seen in the wild before that. Different costume every week, but the same tricks underneath. The lure targets people rather than software, and our SOC caught it in every instance regardless of the disguise. This consistency reflects the fact that the SOC operates from intelligence that already anticipates what the next disguise is likely to look like. 

APG: The Research Behind the Reflex 

The SOC moves that fast because APG keeps feeding it things nobody else has found yet. Anyone can forward you a CVE number. What we built this team to do is find the things nobody has named yet, and July delivered three of them. 

Avalon is a malware framework APG identified that shows real signs of being built with AI assistance. It arrived through a spoofed legal document lure and used a legitimate Microsoft build tool to quietly launch a ransomware and extortion payload we are tracking as CrownX, one built specifically to go after backup infrastructure, Veeam, Acronis, NetApp, Synology, Hyper-V, vCenter. Attackers know backups are the reason a company can say no to a ransom, so they are neutralizing them first. We named this malware before anyone else did, and the pickup from The Hacker News and other outlets confirms the importance of this research 

LabubaRAT is a Rust based remote access tool dressed up as NVIDIA software right down to the file metadata, running three separate communication channels at once so that if defenders catch one, the operator still has two more to fall back on. We published the full technical breakdown and hunting guidance the same week we found it. 

The one I am proudest of is TaskWeaver and Djinn Stealer. APG traced an intrusion back to CVE-2026-48558, a critical SimpleHelp authentication bypass, and named a Node.js loader and a cross-platform credential stealer built to harvest cloud credentials, source code, SSH keys, crypto wallets, and increasingly, the stored tokens behind AI coding assistants. Our disclosure of this chain is what led CISA to add that CVE to its Known Exploited Vulnerabilities catalog. That is research changing the industry response, not just describing it after the fact. 

Why the Order Matters 

Blackpoint builds the platform partners trust. The SOC uses it to stop attacks in real time, every week, no exceptions. And APG makes sure both stay ahead of what is coming next instead of reacting to what already happened. Three layers executing one job.  

See you next month.

DATE PUBLISHEDAugust 5, 2026
AUTHORWil Santiago, Chief Security and Trust Officer

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY