Skip to main content
Microsoft Entra ID Agent ID Administrator Role – Service Principal Takeover

Scope: Microsoft Entra ID (All Tenants Using Agent Identities)

GitHub Enterprise Server Command Injection RCE via Git Push (CVE-2026-3854)

Scope: GitHub Enterprise Server / GitHub Enterprise Cloud

Linux Kernel Local Privilege Escalation – "Copy Fail" (CVE-2026-31431)

Scope: Linux Kernel (All Major Distributions – Kernels Built Since 2017)

PAN-OS User-ID Authentication Portal Buffer Overflow Zero-Day Under Active Exploitation (CVE-2026-0300)

Scope: Palo Alto Networks PAN-OS (PA-Series and VM-Series Firewalls)

Cloudz RAT "Pheno" Plugin Hijacking Windows Phone Link to Steal OTPs and Credentials

Scope: Microsoft Windows Phone Link (Windows 10 and 11)

Severity: High

MuddyWater Iranian APT Deploying "False Flag" Ransomware via Microsoft Teams (Darkcomp RAT)

Scope: Microsoft Teams (Enterprise Environments)

Severity: Red

Google Android Binary Transparency Expanded to All Production Apps

Scope: Google Android (All Production Apps and Mainline Modules)

BlueKit Phishing-as-a-Service Platform – AI-Assisted Credential Theft Campaigns

Scope: Enterprise Platforms and Online Services (Broad)

Severity: High

ConsentFix v3 – OAuth Consent Phishing Campaign Targeting Microsoft Azure and M365

Scope: Microsoft Azure / Microsoft 365 (Entra ID)

Severity: Red

Subscribe to