AI and IT News Recap: July 15, 2026: Microsoft's Record 570-Flaw Patch Tuesday, Claude Goes to School, and SonicWall's Perfect-10 Zero-Day

By Noah Smith, Owner & Consultant, KeyChange Technologies · July 15, 2026

Pen-and-ink illustration of a tiny worker on a ladder patching one hole in an enormous stone wall riddled with hundreds of leaks, symbolizing a record-breaking Patch Tuesday.

Welcome to your AI and IT news recap for July 15, 2026. It was a heavy day for anyone who runs software: Microsoft shipped the single largest Patch Tuesday in its history, a SonicWall appliance flaw hit a perfect 10.0 severity score while under active attack, and Anthropic pushed Claude into K-12 classrooms. Here is what actually matters for your business, sorted and verified.

📌 The AI and IT news at a glance

  • 🛡️ Microsoft's July Patch Tuesday breaks every record: 570 flaws and 3 zero-days in one go.
  • 🛡️ A SonicWall SMA1000 zero-day scores a perfect CVSS 10.0 and is already being exploited.
  • 🛡️ Nearly 300 fake GitHub repos are quietly pushing an infostealer at developers.
  • 🤖 Anthropic launches Claude for Teachers, giving verified US K-12 educators a free year of premium Claude.
  • 🤖 GPT-5.6 becomes the preferred model inside Microsoft 365 Copilot.
  • 🤖 Anthropic is in talks with Samsung to build its own custom Claude inference chip.
  • 🧰 Claude Artifacts get public sharing and real-time multiplayer editing, buildable straight from Slack.

🔝 Top story: Microsoft's biggest Patch Tuesday ever

Microsoft's July 2026 Patch Tuesday, released on July 14, fixed a record-breaking 570 flaws, shattering the previous high of roughly 200 set just last month. Buried in that pile are three zero-days: two that attackers are already exploiting in the wild, and one that was publicly disclosed before a fix existed. The two under active attack are CVE-2026-56155, an Active Directory Federation Services bug that lets an attacker elevate to administrative privileges, and CVE-2026-56164, a SharePoint Server flaw that lets an unauthenticated attacker gain elevated privileges over the network. The publicly disclosed one, CVE-2026-50661, is a BitLocker bypass that an attacker with physical access could use to read encrypted data.

The sheer volume is the story here as much as any single flaw. A separate 468 Edge and Chromium fixes were handled by Google and left out of this count, and Adobe, Cisco, and Progress Software all shipped their own urgent patches the same week. For IT teams, a 570-flaw month is not a "get to it eventually" event; the two exploited zero-days sit in identity and collaboration infrastructure that most companies expose in some form.

In short: Microsoft patched a record 570 vulnerabilities this month, including two zero-days already being used in attacks and one publicly disclosed BitLocker bypass.

What it means for your business: If you run Windows, SharePoint, or AD FS, this is a prioritize-now update, especially the two actively exploited identity flaws that can hand an attacker admin rights. Do not let the record patch count become an excuse to defer.

My take: Volume records make for scary headlines, but the practical move is boring and unchanged: patch the actively exploited ones first, this week, and let the other 567 follow on your normal cycle. The AD FS and SharePoint bugs are the ones that would ruin a Monday.

Source: BleepingComputer


🛡️ IT and security

A SonicWall SMA1000 zero-day scores a perfect 10.0 and is under attack

SonicWall is warning that two flaws in its SMA1000 secure-access appliances are being exploited together in zero-day attacks. The headliner, CVE-2026-15409, is a server-side request forgery bug rated a maximum CVSS 10.0 that lets a remote, unauthenticated attacker force the appliance to make requests to places it should not. It is paired in real attacks with CVE-2026-15410, a post-authentication command-injection flaw that lets an admin-level attacker run arbitrary operating-system commands. CISA has added both to its Known Exploited Vulnerabilities catalog, and federal agencies have until July 17 to patch or pull the appliances offline.

Fixes are available in SonicWall's platform-hotfix builds 12.4.3-03453 and 12.5.0-02835 and later. Because these are internet-facing remote-access boxes, an exploited SMA1000 is effectively a front door into the corporate network.

In short: Two SonicWall SMA1000 zero-days, one rated a perfect 10.0, are being actively exploited and are now on CISA's must-patch list.

What it means for your business: If you use SonicWall SMA1000 appliances for remote access, patch to the fixed builds immediately; a maximum-severity, internet-facing flaw under active exploitation is about as urgent as security work gets.

My take: Remote-access gateways keep being the softest entry point in the modern network, and a CVSS 10.0 on one is the kind of thing that should trigger an out-of-band change window, not a ticket in the backlog.

Source: BleepingComputer


Nearly 300 fake GitHub repos are pushing an infostealer at developers

Researchers at Arctic Wolf uncovered a campaign in which an unattributed threat actor has published at least 292 fake GitHub pages and repositories since late June, impersonating legitimate software and even security vendors, including a bogus Arctic Wolf page. Each repo carries a polished, marketing-style README with a hidden download link that routes victims to a fake "secure download" page. The lures are tuned to search traffic for security products, crypto services, financial tools, developer utilities, and macOS software.

The payload, from the BoryptGrab infostealer family, harvests data from more than 19 browsers, 32 cryptocurrency wallets, and a range of messaging and social apps before shipping it to a command-and-control server. The operators appear financially motivated, with hosting and language artifacts pointing to a Russian-speaking group.

In short: A threat actor stood up nearly 300 brand-impersonating GitHub repos that quietly deliver the BoryptGrab infostealer to anyone who downloads them.

What it means for your business: Developers and IT staff who grab tools from GitHub are the target here; treat an unfamiliar repo like an unfamiliar email attachment and verify the publisher before you run anything.

My take: "It was on GitHub" has never meant "it is safe," and this is a clean reminder. A one-line policy of only pulling from verified organization accounts would neutralize most of this.

Source: BleepingComputer


🤖 AI

Anthropic launches Claude for Teachers with a free year of premium access

Anthropic introduced Claude for Teachers on July 14, giving verified US K-12 educators a full year of free premium Claude, including paid-tier tools like Claude Code and Claude Cowork. The product is built around the actual work of teaching, lesson planning, differentiation, assessment review, and classroom prep, and it connects to a Learning Commons that maps academic standards across all 50 states along with curricula like OpenSciEd and Illustrative Mathematics. It launches with nine education connectors, from Canva Education to MagicSchool, and ships with a K-12 data processing agreement built to align with FERPA, with a promise that teacher and student data will not be used to train Anthropic's models.

This lands squarely in a broader race to get AI tools into schools, and the free-through-June-2027 sign-up window is an aggressive way to build habit among educators. It is also a notable expansion beyond the student-focused tools that have dominated the classroom AI conversation so far.

In short: Anthropic is giving verified US K-12 teachers a free year of premium Claude, complete with standards-aligned lesson planning and FERPA-conscious data handling.

What it means for your business: Not directly a business tool, but if you employ or support educators, or sell into education, this reshapes what "free AI in the classroom" looks like and sets a data-privacy bar competitors will be measured against.

My take: Giving away the premium tier for a year is a land-grab, plain and simple, and the FERPA-aligned data agreement is the smart part that will matter more than any feature. Teachers should still read that agreement before uploading anything with student names in it.

Source: Anthropic


GPT-5.6 becomes the preferred model in Microsoft 365 Copilot

Microsoft has made OpenAI's GPT-5.6 the preferred model inside Microsoft 365 Copilot, the assistant baked into Word, Excel, Outlook, and Teams. GPT-5.6, the family OpenAI opened to the public on July 9 with its Sol, Terra, and Luna variants, now underpins the day-to-day Copilot experience for the enterprise customers who rely on it. It is a quiet but meaningful signal that Microsoft is keeping OpenAI's newest generation at the center of its productivity stack even as it experiments with its own in-house models elsewhere.

In short: Microsoft 365 Copilot now defaults to OpenAI's GPT-5.6 across the Office apps.

What it means for your business: If your team uses Copilot, you are getting a model upgrade without lifting a finger; it is worth re-testing your common prompts and workflows, since output quality and behavior can shift with a new default model.

My take: Model swaps under the hood are becoming routine, which is convenient but also means the tool your staff used last month may behave differently this month. Spot-check anything where consistency matters, like templated reports.

Source: Nextgov/FCW


Anthropic is in talks with Samsung for a custom Claude chip

Anthropic is reportedly in early discussions with Samsung to design a custom inference chip tuned specifically to its Claude models, according to reporting around July 14. The move would put Anthropic on the same path as Google, Amazon, Meta, and OpenAI, all of which have pursued in-house silicon to cut their dependence on Nvidia and rein in soaring compute costs. Anthropic's compute bill has been reported in the range of well over a billion dollars a month, so custom chips are as much a margin story as a performance one.

In short: Anthropic is exploring a custom, Samsung-built inference chip designed around its own Claude models.

What it means for your business: Nothing changes for you today, but the industry-wide push toward custom silicon points to more stable and potentially cheaper AI pricing over time as the big labs stop paying full retail for someone else's GPUs.

My take: Every major lab building its own chips is the clearest sign yet that inference cost, not model quality, is becoming the real competitive battleground. That is good news for buyers eventually, though "eventually" is doing some work in that sentence.

Source: Tech Startups


🧰 New tooling for builders and business

Claude Artifacts get public sharing and real-time multiplayer editing

Alongside the classroom news, Anthropic shipped a set of collaboration upgrades to Claude Artifacts. Teams can now publish live, interactive artifacts, not just static text, behind secure shareable links, and multiple people can edit the same artifact in real time instead of passing versions back and forth. The company also wired this into Claude Tag, so you can spin up and share an artifact directly from a Slack thread by tagging Claude. The collaboration features are aimed at Team and Enterprise plans.

In short: Claude Artifacts now support public sharing, real-time multiplayer editing, and creation from inside Slack via Claude Tag.

What it means for your business: For teams already on Claude, this turns one-off AI outputs into shareable, editable working documents and small apps, which is a real workflow upgrade for prototyping dashboards, calculators, and internal tools without a developer.

My take: Meeting people inside Slack, where the work already happens, is the smart bet here. The public-sharing piece is handy, but double-check what you are publishing; "shareable link" and "accidentally public" are uncomfortably close neighbors.

Source: Crypto Briefing


That is the AI and IT news for July 15, 2026. Missed yesterday? Catch up on the July 14 recap. We will be back tomorrow with another rundown.