Daily News
Microsoft Entra ID RCE Vulnerability Exploited
Microsoft disclosed a maximum-severity Microsoft Entra ID RCE vulnerability on August 20, 2026, and confirmed the flaw was already being exploited in the wild before the advisory went public. CVE-2026-69836 carries a CVSS score of 10.0, needs no authentication and no user interaction, and sits in the identity backbone underneath Microsoft 365, Azure AD sign-in,…
Read MoreMedusa Ransomware 500 Victims — What the CISA Advisory Means
Medusa ransomware 500 victims is now the official U.S. federal tally: CISA, the FBI and the Department of Health and Human Services updated their joint advisory on August 18, 2026, confirming the ransomware-as-a-service group has breached more than 500 U.S. critical infrastructure organizations since June 2021 — up from the 300-plus figure in their original…
Read MoreWindows IKE RCE: Patched in April, Exploited Now
CVE-2026-33824 Windows IKE RCE has gone from a quietly patched bug in April to an actively exploited flaw four months later: CISA added it to its Known Exploited Vulnerabilities catalog on August 18, 2026, giving U.S. federal agencies until August 21 to patch — while Microsoft’s own advisory still lists it as not exploited. What…
Read MoreProgress LoadMaster CVE-2026-8037: 792 Attacks Logged
Progress LoadMaster CVE-2026-8037, a CVSS 9.6 unauthenticated command-injection flaw, has already been hit with 792 confirmed exploitation attempts from 65 IP addresses over 41 days — and CISA added it to its Known Exploited Vulnerabilities catalog on August 7. If your load balancer is still running an unpatched build, the scanning has almost certainly already…
Read MoreVMware vCenter CVE-2026-59310: Germany Hit Hardest
VMware vCenter CVE-2026-59310, a maximum-severity path-traversal vulnerability scoring 9.8 on CVSS, is being actively exploited across 47 countries — and Germany is the single most-affected country of all of them. German incident-response firm QUIRSO uncovered the campaign live during an IR engagement, tracing 361 distinct victim IP addresses back to a directory-traversal flaw in vCenter’s…
Read More
