August 24, 2026
- The NVD entry for the maximum-severity Entra ID flaw is now public: CVE-2026-69836, CWE-502 deserialization of untrusted data, network attack vector, unauthenticated code execution, CVSS 10.0 as assigned by Microsoft — and reported as actively exploited (NVD). Microsoft's own messaging on exploitation status has been inconsistent (earlier coverage). · Cloud & Identity
in Four Days Dark: Iran-Linked Intrusion Knocked a UK Power Plant Offline