vulnerability Microsoft Rolls Out 22 Fresh Security Patches Microsoft released 22 security patches addressing critical and high-severity vulnerabilities across its Azure, Entra ID, Exchange, Fabric, and Defender products. Several of these flaws, including a zero-day exploit dubbe… SecurityWeek · Aug 21, 2026 Critical CVE-2026-69502CVE-2026-69555CVE-2026-65816vulnerabilitypatchzero-day
vulnerability Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution Microsoft has patched a critical vulnerability in Entra ID, which has been exploited in the wild. The flaw allows remote code execution, and while Microsoft has addressed it, it highlights the ongoing need for vigilance… The Hacker News · Aug 21, 2026 Critical CVE-2026-69836CVE-2026-68820entria idazure adremote code execution
threat-intel Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5. This article is a collection of cybersecurity and technology news snippets from The Register. It covers a range of topics including a vulnerability in Microsoft SharePoint, a phishing campaign impersonating Signal suppor… The Register · Aug 21, 2026 Medium CVE-2026-20315CVE-2026-20317CVE-2026-20231vulnerabilityphishingransomware
threat-intel Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st) This script identifies users within an organization who have not yet been enrolled in multi-factor authentication (MFA) using the Microsoft Graph API. It leverages a beta command to efficiently list un-registered users,… SANS Internet Storm Center · Aug 21, 2026 Info mfamicrosoftgraph
threat-intel ISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Aug 21, 2026 High phishingransomwaresupply-chain
threat-intel Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st) This article details a method for identifying password spray attacks and unusual login activity within Microsoft Entra (formerly Azure Active Directory) logs. By analyzing login events and filtering for unexpected countr… SANS Internet Storm Center · Aug 21, 2026 Medium entragraphpassword sprayconditional access
threat-intel Russian snoops add OAuth abuse to targeted phishing campaigns Google has identified three distinct groups of Russian cyber-spies – UNC6293, UNC7005, and UNC5976 – that are aggressively targeting individuals in academia, defense, government, and think tanks across Europe and the US.… The Register · Aug 21, 2026 High RUUKWEphishingoathsocial engineering
vulnerability Vulnérabilité dans Microsoft Entra ID (21 août 2026) A critical vulnerability (CVE-2026-69836) has been identified in Microsoft Entra ID, allowing for remote code execution. While initially reported as actively exploited, Microsoft has clarified that it is currently not be… CERT-FR · Aug 21, 2026 Critical CVE-2026-69836entria idremote code executioncve
vulnerability Multiples vulnérabilités dans les produits Microsoft (21 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, allowing attackers to bypass security policies and cause denial-of-service conditions. Microsoft has released security bulletins detailing the issues a… CERT-FR · Aug 21, 2026 Medium CVE-2026-55013CVE-2026-55015microsoftvulnerabilitysecurity
vulnerability Vulnérabilité dans Microsoft Office (21 août 2026) A vulnerability has been discovered in Microsoft Office that could allow an attacker to compromise data confidentiality. Affected versions of Office, including Office 365 and Office 2019, require immediate patching to pr… CERT-FR · Aug 21, 2026 Medium CVE-2026-70105vulnerabilitymicrosoftpatch
vulnerability Multiples vulnérabilités dans Microsoft Edge (21 août 2026) Microsoft Edge is experiencing multiple vulnerabilities, as detailed in security advisories released by CERT-FR. These vulnerabilities could allow an attacker to trigger an unspecified security issue. Users of Microsoft… CERT-FR · Aug 21, 2026 Medium CVE-2026-76033CVE-2026-76034CVE-2026-76035vulnerabilitymicrosoftedge
threat-intel Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts Three distinct clusters of suspected Russian cyber espionage groups – UNC6293, UNC7005, and UNC5976 – are leveraging legitimate authentication flows to target individuals in academia, aerospace/defense, governments, and… The Hacker News · Aug 20, 2026 High UKARRUoauthapp passworddevice linking
threat-intel US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline A US bank is investigating claims by LockBit ransomware operators that they have stolen sensitive data and are threatening to leak it unless a ransom is paid. This follows a pattern of LockBit extortion attempts targetin… The Register · Aug 20, 2026 Medium ransomwarecybersecuritydata breach
threat-intel ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More This week’s ThreatsDay bulletin highlights a diverse range of security threats, including a Remote Code Execution vulnerability in Gogs, a sophisticated Mabna Institute cyber espionage campaign targeting universities and… The Hacker News · Aug 20, 2026 Critical CVE-2026-52813CVE-2026-52810CVE-2026-43774IRUSrcecyber espionagegit hooks
threat-intel Using Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th) This article details how to use Microsoft Graph PowerShell commands to identify risky login attempts. By leveraging the `Get-MgRiskDetection` command, security analysts can detect logins originating from unusual location… SANS Internet Storm Center · Aug 20, 2026 Medium SOCOMArisk detectionidentity protectionmicrosoft graph
threat-intel Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th) This article details a PowerShell script leveraging the Microsoft Graph API to extract detailed information about Microsoft 365 users, including their last password change date, login activity, and assigned licenses. The… SANS Internet Storm Center · Aug 20, 2026 Medium microsoft graphentaralicense management
threat-intel Identity Abuse Through Trusted Communication Channels Threat actors are increasingly leveraging trusted collaboration platforms – like Microsoft Teams and Slack – to conduct sophisticated identity phishing attacks. Instead of relying solely on traditional email phishing, at… Palo Alto Unit 42 · Aug 20, 2026 High PONOidentity phishingcollaboration platformssocial engineering
threat-intel AI agent suggested installing a malware package. Engineer almost took its advice A security researcher was nearly tricked into installing malware by an AI agent. The AI, mimicking a support tool, suggested installing a package that would have installed malicious software, highlighting a growing risk… The Register · Aug 20, 2026 Medium aisocial engineeringphishing
threat-intel ISC Stormcast For Thursday, August 20th, 2026 https://isc.sans.edu/podcastdetail/10060, (Thu, Aug 20th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques to steal credentials. The threat landscape is evolving rapi… SANS Internet Storm Center · Aug 20, 2026 High phishingcredential theftlateral movement
vulnerability Multiples vulnérabilités dans Microsoft Windows (20 août 2026) Multiple vulnerabilities have been discovered in Microsoft Windows, allowing an attacker to elevate privileges and compromise data confidentiality. These vulnerabilities affect a wide range of Windows versions and server… CERT-FR · Aug 20, 2026 High CVE-2026-62727CVE-2026-69550securitypatchvulnerability