Microsoft 365
Huntress Documents 81M+ Azure CLI Password-Spray Attempts Against 78 Microsoft Accounts
A scale-significant Azure CLI credential-attack campaign — defender teams stay in account-hardening posture this week.
Explore strategies and technologies for protecting enterprise networks. Learn about threat detection, network monitoring, access control, and defenses against modern cyberattacks targeting corporate infrastructure.
Microsoft 365
A scale-significant Azure CLI credential-attack campaign — defender teams stay in account-hardening posture this week.
Vulnerabilities
Six NetScaler flaws, one with echoes of CitrixBleed — defender teams stay in patch-verification posture this week.
Vulnerabilities
A critical remote monitoring and management vulnerability is under active exploitation to deliver an infostealer that hunts cloud and AI development credentials — and it is now on CISA's KEV list.
Vulnerabilities
Another Oracle product line under active exploitation — high-priority patch verification this week.
Vulnerabilities
Two critical NGINX Open Source patches — defenders running reverse-proxy and web-tier deployments should verify the patched versions this week.
Vulnerabilities
A large-scale credential-harvesting campaign across Fortinet deployments — sector-wide patch verification and credential rotation are the defender priority.
Vulnerabilities
Cisco's SD-WAN patch cycle continues this week — defender verification stays the priority.
Vulnerabilities
Patch verification across Catalyst SD-WAN Manager deployments is the high-priority cycle this week.
Vulnerabilities
The SIEM at the center of many SOCs gets a critical-priority patch — verify deployments.
Vulnerabilities
A logic-flow weakness in Check Point's Remote Access VPN gave a Qilin ransomware affiliate and other attackers a month to operate before a patch arrived.
Vulnerabilities
Cisco warns that CVE-2026-20245, a zero-day in Catalyst SD-WAN Manager, is being exploited to gain root, with no patch available. Exploitation needs netadmin access — obtainable by chaining CVE-2026-20182 — making it Cisco's seventh exploited SD-WAN zero-day of 2026.
Cyber Attacks
Hunt.io found that a threat actor called PCPJack hijacked about 230 AWS, Google Cloud and Azure servers into a covert SMTP relay network — quietly converting business servers into verified mail proxies synced to a downstream consumer every five minutes.