Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, Azure, and connected third-party apps. Tracked as CVE-2026-69836, with the maximum CVSS score of 10.0, the vulnerability was discovered by Microsoft Principal Security Engineer Robert Fitzpatrick and could allow an una
Cybersecurity Intelligence Report — 22 August 2026
CRITICAL 1
KEV 1
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability - Synacor Zimbra Collaboration Suite (ZCS). Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-08-24
DLS VICTIMS 0
No newly collected entries.
NEWS 20
A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Patches Exploited Entra ID Vulnerability appeared first on SecurityWeek .
Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. “We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,” Anil Shetty, se
The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek .
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server. The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek .
Enterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography (PQC), according to new research from Axiad. Who owns PQC migration? (Source: Axiad) Organizations need to know where certificates, cryptographic keys and algorithms are used before they can plan a PQC migration. About 75% of respondents said they maintain a continuously updated inventory of t
Victim: First Commerce LLC | Group: pear | Website: firstcommercellc.com | Country: US | Details: Privately held real estate investment and development company
Victim: Oceanica Internacional | Group: thegentlemen | Website: oceanica.ws | Country: WS | Details: oceanica.ws Oceanica Internacional is a comprehensive logistics and freight forwarding company operating across Central America. They serve as a strategic logistics partner, providing international trade and supply chain solutions in countries like Costa Rica, Panama, and Guatemala. The company spec
Victim: Hogan Omidi P.C. | Group: dragonforce | Website: hoganomidi.com | Country: US | Details: Hogan Omidi, P.C. is a boutique law firm specializing in family law, including divorce, child custody, and property division, with a focus on high-asset cases. The firm is led by experienced attorneys who have authored key reference materials on Colorado family law, providing them with a unique adva
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [...]
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage. Nothing here needs
Here’s a look at the most interesting products from the past week, featuring releases from F5 Networks, Intezer, Netscout, and Tufin. NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation NETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP) solution enabling service providers to automatically detect and mitigate outbound DDoS attack traffic. By extending protection from the attack target towards its source, NETSCOUT helps operators prevent compromised
Victim: cedarridge.org | Group: L Group | Website: cedarridge.org | Country: US | Details: [AI generated] N/A
Victim: Nteitalia | Group: Panzer | Details: NTE Italia, an engineering and telecommunications service provider based in Catanzaro, Italy. Sensitive thousands of documents are compromised.
Victim: TEST | Group: emperador | Details: Test [Size: 740.0 KB | Sector: Other]
Victim: Quaker State Mexico | Group: qilin | Website: www.quakerstate.com.mx | Country: MX | Details: N/A
Victim: iPic | Group: qilin | Website: www.ipic.com | Country: US | Details: N/A
Victim: Coming soon | Group: rhysida | Details: Coming soon Total capacity 5.79 TBLegal/Complaints/Offenses 77,939 OWi proceedings, lawsuits, legal opinionsFinance 55,553 Budget, invoices, ProFISKAL, debt collectionContracts 46,522 Contracts, NDAs, procurementHR/Personnel 27,299 Personnel files, payroll, performance reviewsOversight/Government 13
Victim: JC Sales | Group: akira | Website: jcsalesweb.com | Details: JC Sales is a leading full-service wholesaler based in Los Angeles, California, specializing in a vast array of wholesale products including health and beauty items, food and beverages, gene ral merchandise, and seasonal items. We will upload 206gb of corporate data soon. Detailed personal employee
Victim: Cinépolis | Group: qilin | Website: www.cinepolis.com | Country: MX | Details: N/A
Victim: Fairview Dental Group | Group: rhysida | Details: Fairview Dental Group Fairview Dental Group offers a range of dental services including family dentistry, cosmetic treatments, dental implants, and invisible braces.We are pleased to present:Full patient database, patient X-rays, scanned forms/consents/invoices, health records (PHI) of the entire pr