# Today's Top Stories
August 22, 2026
-
1The Hacker News general Aug 21Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
Microsoft disclosed CVE-2026-69836, a CVSS 10.0 remote code execution vulnerability in Entra ID (formerly Azure Active Directory) that has been actively exploited in the wild. Despite active exploitation, Microsoft states no customer action is required, making it critical for security teams to verify their Entra ID configurations and monitor for indicators of compromise.
-
2BleepingComputer general Aug 21Microsoft warns of max severity Entra ID flaw exploited in attacks
Microsoft patched a maximum-severity flaw in its Entra ID identity and access management platform (CVE-2026-69836, CVSS 10.0) that has been exploited in the wild, with no customer-side remediation required. Security practitioners managing Microsoft cloud identity infrastructure should treat this as a high-priority monitoring event given the severity and confirmed exploitation status.
-
3The Hacker News general Aug 21GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
CVE-2026-19478, a CVSS 9.4 unauthenticated code injection vulnerability in GitLab, was exploited in the wild within days of public disclosure, according to watchTowr. The flaw allows attackers to modify or delete publicly accessible GitLab projects and rewrite their data without authentication, posing an immediate risk to organizations running self-hosted GitLab instances.
-
4The Hacker News general Aug 21Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point Research disclosed a technique abusing Microsoft Defender's legitimately signed boot-time driver BTR.sys (Boot Time Removal Tool) to perform arbitrary kernel-level file and registry deletions on Windows systems from Windows 7 through Windows 11 25H2. No external driver is required and no software vulnerability is exploited, meaning the technique is difficult to detect and block via conventional defenses.
-
5The Hacker News general Aug 21Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Cisco patched nine vulnerabilities across Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning, and Secure Workload Software, with five flaws scoring a perfect CVSS 10.0. The bugs enable remote code execution, authentication bypasses, and path traversal attacks affecting the platforms regardless of device configuration.
-
ADSponsoredPenetration Testing
Comprehensive security assessments by certified professionals. Find vulnerabilities before attackers do.
Learn More → -
6BleepingComputer general Aug 21CISA orders feds to patch actively exploited TrueConf Server flaws
CISA added two actively exploited TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch immediately. The Head Mare hacktivist group has been leveraging these flaws to deploy the PhantomCore malware against targets.
-
7BleepingComputer general Aug 21Hundreds of leaked AWS keys give full control over corporate accounts
A study found more than 9,300 Amazon Web Services access keys publicly exposed between August 2022 and August 2026 that remain active and valid, giving attackers full control over the associated corporate AWS accounts. The ongoing exposure represents a systemic cloud credential hygiene failure with direct, exploitable impact across potentially thousands of organizations.
-
8SecurityWeek general Aug 21Rust Supply Chain Attack Linked to North Korean Hackers
North Korean threat actors conducted a Rust supply chain attack by compromising the maintainer account of the widely-used 'arrayref' crate and pushing a poisoned version that added a malicious dependency fetching a remote payload during compilation. Developers who built projects using the compromised arrayref version had malware executed on their systems at compile time.
-
9BleepingComputer general Aug 20Critical Zimbra RCE flaw now actively exploited in attacks
CERT Polska confirmed active exploitation of a critical RCE vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite, warning organizations to patch immediately. Zimbra servers are a recurring high-value target due to their widespread enterprise email use and history of rapid weaponization following vulnerability disclosure.
-
10The Hacker News general Aug 20Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android malware family named Manic has been observed targeting Ukrainian banks, government services, and military communications, as well as Russian and European financial institutions and cryptocurrency platforms. Manic combines banking trojan and spyware capabilities and features a novel fallback exfiltration mechanism that routes stolen data through nearby infected Android devices, enabling data theft even from offline phones.