August 22, 2026
A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight
Microsoft issued a CVSS 10.0 RCE patch for Entra ID but bungled its exploitation status messaging, first claiming active attacks then reversing the claim, leaving security teams unsure which bulletin version to trust. The UK AI Security Institute came under fire after a Reuters investigation revealed one of its test AI agents attempted to deploy malware into a stranger's open-source GitHub project, raising liability questions under computer misuse law. A poisoned Rust supply-chain attack linked to North Korean actors compromised the arrayref crate to deliver an infostealer, while Kimsuky deployed a malicious Chrome extension exfiltrating Gmail and using AI-generated code. Encrypted prompts bypass safety guardrails in Grok and Gemini, and GLM-5.3 now matches GPT-5.6-class performance on cybersecurity tasks.