Microsoft patched an Entra ID RCE vulnerability exploited in attacks that required no authentication or user interaction.
Category: eSecurity Planet
Critical Patches, AI-Driven Attacks, and Data Theft Define the Week in August 2026
Weekly summary of Cybersecurity Insider newsletters in August 2026.
Alation Confirms Cyberattack: What Security Teams Need to Know
Alation confirms unauthorized activity in one of its systems, leaving key questions about customer exposure, stolen data, and the attack’s scope.
Medusa Ransomware Hits 500-Plus Victims as Agencies Warn of Rapid Exploitation
Federal agencies warn that Medusa ransomware has hit more than 500 victims and can exploit newly disclosed vulnerabilities within 24 hours of release.
Researchers Use Remote Spectre Attack to Leak JWT From Cloudflare Worker
Researchers used a remote Spectre attack to leak a JWT between co-located Cloudflare Workers. Cloudflare says the technique is now mitigated.
6 Best Identity and Access Management (IAM) Software Solutions in 2026
Compare the 6 best IAM solutions for 2026, including JumpCloud, Okta, OneLogin, ManageEngine, CyberArk, and Microsoft Entra ID, features, pros, and cons.
Oracle Patches 943 Vulnerabilities, Including Critical WebLogic Bugs
Oracle patched 943 vulnerabilities, including critical remotely exploitable flaws.
Apple Patches Critical iPhone Flaws: Attackers Could Run Malicious Code
Apple patched critical iPhone flaws that could allow malicious code execution, including an ImageIO vulnerability. Here’s what users should know.
T-Mobile Cuts Network Cable to Stop Salt Typhoon Hackers
T-Mobile physically cut a network cable to disrupt Salt Typhoon’s access.
NetScaler CVE-2026-19490 Lets Attackers Bypass Authentication
NetScaler flaws could enable authentication bypass and DoS attacks.
OpenAI Slows Frontier AI Training as Astra Nears Critical Cyber Threshold
OpenAI slows frontier AI training as Astra nears a critical cyber threshold, raising new questions about AI security, autonomy, and defense.
Microsoft Links More Than 30 Domains to MacSync Stealer
Microsoft linked more than 30 rotating domains to MacSync Stealer by correlating endpoint and network behavior across the malware’s attack chain.
Bluesky Hit by Second Major DDoS Attack in Months
Bluesky suffered its second major DDoS attack in months, causing hours of disruption as a threat group claimed responsibility for the outage.
GitLab Patches Critical CVE-2026-19478 GraphQL Vulnerability
GitLab patched a critical GraphQL flaw as researchers observed exploitation attempts.
Crypto Scammer Uses Claude Code to Screen 100,000+ Phone Numbers in Phishing Operation
Rapid7 found a crypto scammer used Claude Code on more than 100,000 phone numbers in a phishing and vishing operation targeting cryptocurrency holders.
Microsoft’s August Patch Tuesday: 400+ Bugs Fixed, One Zero-Day Under Attack
Microsoft’s August Patch Tuesday fixes about 400 security flaws, including an actively exploited Windows zero-day and multiple 9.8-rated RCE bugs.
Hacker Claims 3.6 Million Azure Records Stolen From McDonald’s, Vodafone and Others
A hacker claims to be selling 3.6 million Azure-linked employee records from McDonald’s, Vodafone, TCS, and others, but no breach is confirmed.
DDoS Attack Knocks Threema Messaging Service Offline for Hours
A large-scale DDoS attack disrupted Threema for hours, knocking hosted messaging offline as OnPrem deployments stayed online and attackers remained…
Microsoft Confirms ShieldBreak Defender Flaw, Windows Defender Fix Still Pending
Microsoft is working on a fix for the ShieldBreak Windows Defender vulnerability as a public proof of concept raises privilege-escalation concerns.
8 Best EDR Solutions & Software for 2026
Compare the 8 best EDR solutions for 2026, including Microsoft, CrowdStrike, SentinelOne, Palo Alto, and more, based on security features and use cases.
