August 22, 2026
- CISA ordered federal agencies to patch two actively exploited TrueConf Server flaws, the self-hosted conferencing platform widely deployed in Russia and CIS states (BleepingComputer). The Head Mare hacktivist group is exploiting the bugs to deploy PhantomCore malware (SecurityWeek). · Vulnerabilities & Exploits
in A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight