HERMES // CYBER INTELLIGENCE // 2026-08-22

Cybersecurity Intelligence Report — 22 August 2026

CRITICAL 1

[14] Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)

Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, Azure, and connected third-party apps. Tracked as CVE-2026-69836, with the maximum CVSS score of 10.0, the vulnerability was discovered by Microsoft Principal Security Engineer Robert Fitzpatrick and could allow an una

KEV 1

[6] [CISA KEV] CVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability - Synacor Zimbra Collaboration Suite (ZCS)

Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability - Synacor Zimbra Collaboration Suite (ZCS). Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-08-24

DLS VICTIMS 0

No newly collected entries.

NEWS 20

[8] Microsoft Patches Exploited Entra ID Vulnerability

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Patches Exploited Entra ID Vulnerability appeared first on SecurityWeek .

[8] Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. “We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,” Anil Shetty, se

[7] Nearly half of enterprises have no one leading PQC migration

Enterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography (PQC), according to new research from Axiad. Who owns PQC migration? (Source: Axiad) Organizations need to know where certificates, cryptographic keys and algorithms are used before they can plan a PQC migration. About 75% of respondents said they maintain a continuously updated inventory of t

[7] [RANSOMWARE] thegentlemen leaked Oceanica Internacional

Victim: Oceanica Internacional | Group: thegentlemen | Website: oceanica.ws | Country: WS | Details: oceanica.ws Oceanica Internacional is a comprehensive logistics and freight forwarding company operating across Central America. They serve as a strategic logistics partner, providing international trade and supply chain solutions in countries like Costa Rica, Panama, and Guatemala. The company spec

[7] [RANSOMWARE] dragonforce leaked Hogan Omidi P.C.

Victim: Hogan Omidi P.C. | Group: dragonforce | Website: hoganomidi.com | Country: US | Details: Hogan Omidi, P.C. is a boutique law firm specializing in family law, including divorce, child custody, and property division, with a focus on high-asset cases. The firm is led by experienced attorneys who have authored key reference materials on Colorado family law, providing them with a unique adva

[6] ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More

A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage. Nothing here needs

[6] New infosec products of the week: August 21, 2026

Here’s a look at the most interesting products from the past week, featuring releases from F5 Networks, Intezer, Netscout, and Tufin. NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation NETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP) solution enabling service providers to automatically detect and mitigate outbound DDoS attack traffic. By extending protection from the attack target towards its source, NETSCOUT helps operators prevent compromised

[5] [RANSOMWARE] Panzer leaked Nteitalia

Victim: Nteitalia | Group: Panzer | Details: NTE Italia, an engineering and telecommunications service provider based in Catanzaro, Italy. Sensitive thousands of documents are compromised.

[5] [RANSOMWARE] emperador leaked TEST

Victim: TEST | Group: emperador | Details: Test [Size: 740.0 KB | Sector: Other]

[5] [RANSOMWARE] rhysida leaked Coming soon

Victim: Coming soon | Group: rhysida | Details: Coming soon Total capacity 5.79 TBLegal/Complaints/Offenses 77,939 OWi proceedings, lawsuits, legal opinionsFinance 55,553 Budget, invoices, ProFISKAL, debt collectionContracts 46,522 Contracts, NDAs, procurementHR/Personnel 27,299 Personnel files, payroll, performance reviewsOversight/Government 13

[5] [RANSOMWARE] akira leaked JC Sales

Victim: JC Sales | Group: akira | Website: jcsalesweb.com | Details: JC Sales is a leading full-service wholesaler based in Los Angeles, California, specializing in a vast array of wholesale products including health and beauty items, food and beverages, gene ral merchandise, and seasonal items. We will upload 206gb of corporate data soon. Detailed personal employee

[5] [RANSOMWARE] rhysida leaked Fairview Dental Group

Victim: Fairview Dental Group | Group: rhysida | Details: Fairview Dental Group Fairview Dental Group offers a range of dental services including family dentistry, cosmetic treatments, dental implants, and invisible braces.We are pleased to present:Full patient database, patient X-rays, scanned forms/consents/invoices, health records (PHI) of the entire pr