Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.
Each item includes our perspective on why it matters to your security posture.
CVE-2026-50656, a race condition in the Microsoft Malware Protection Engine, let local attackers spawn a SYSTEM-level shell on fully patched Windows hosts. Microsoft has shipped a fix.
Why it matters: The irony here is the attack surface: your endpoint protection engine itself. Confirm the Malware Protection Engine has auto-updated to 1.1.26060.3008 or later across your fleet — this doesn't wait for a normal patch cycle, but it's worth verifying rather than assuming.
Read source →A ransomware family tied to the Hyadina group (rebranded from Beast) uses a Microsoft-signed malicious kernel driver, AnyDesk, and PsExec to disable security tooling before encrypting data.
Why it matters: A signed kernel driver bypassing your EDR is a detection-layer problem, not a patching problem. Make sure your monitoring flags unexpected kernel driver loads and known dual-use remote access tools like AnyDesk and PsExec running outside of change-managed maintenance windows.
Read source →Ubiquiti shipped fixes for seven critical UniFi OS vulnerabilities, including CVE-2026-50746, an unauthenticated CVSS 10.0 command injection bug reachable by any device on the same network segment.
Why it matters: Confirm your UniFi Connect, Access, Protect, Talk, and OS deployments are on the patched builds — CVE-2026-50746 needs no authentication and no more than network adjacency, which describes most guest or IoT VLANs that share a segment with management infrastructure.
Read source →Sysdig researchers found JadePuffer, a ransomware operation where an autonomous LLM agent handled recon, credential theft, lateral movement, and encryption without a human operator.
Why it matters: The individual steps here aren't new — the automation is. If your detection rules assume a human operator's pacing and mistakes, this incident is a signal to test them against faster, self-correcting behavior, and to prioritize patching internet-facing AI tooling like Langflow before attackers' agents get there first.
Read source →A maximum-severity path traversal bug in Adobe ColdFusion, tracked as CVE-2026-48282, is under active exploitation and now sits in CISA's Known Exploited Vulnerabilities catalog.
Why it matters: If you run ColdFusion anywhere in your stack, patch or isolate it now and pull server access logs for the exploitation window — path traversal bugs like this are trivial to weaponize once public, and the KEV listing means opportunistic scanning has already started.
Read source →Accenture acknowledged a security incident after a threat actor posted claims of stealing 35GB of source code, RSA and SSH keys, and Azure access tokens from an internal DevOps repository.
Why it matters: This is a supply-chain exposure, not just an Accenture problem — if Accenture is a vendor or systems integrator in your environment, ask them directly whether any of your credentials, access keys, or integration code were stored in the affected repository.
Read source →A phishing-as-a-service platform dubbed DEBULL is using collaboration-themed lures and the legitimate Microsoft device-code login flow to take over Microsoft 365 accounts without ever touching a password.
Why it matters: Device-code phishing bypasses your password and MFA prompts entirely by tricking users into authorizing a real Microsoft session — if you haven't already, restrict or disable the device code auth flow in Entra ID via Conditional Access unless a specific business case requires it.
Read source →Attackers are exploiting CVE-2026-20896, a reverse-proxy trust misconfiguration in Gitea Docker images, to bypass authentication with one crafted HTTP header and reach private repositories and secrets.
Why it matters: If you self-host Gitea in Docker, check your REVERSE_PROXY_TRUSTED_PROXIES setting today — the default in vulnerable images trusts every source IP, which means anyone on the network can impersonate an admin with a single header.
Read source →Check Point Research uncovered Cavern, a previously undocumented .NET-based C2 framework used by an Iranian MOIS-linked group to breach Israeli IT providers and government targets.
Why it matters: This is a supply-chain campaign first and an Israel-specific campaign second — the group reaches its real targets by hopping through trusted IT providers. If you're an Israeli startup working with external MSPs or IT vendors, ask them directly what monitoring they have on outbound connections from their management tooling.
Read source →4,700 victims were listed on ransomware leak sites in H1 2026, up 16% year-over-year and nearly 65% versus the same period in 2024.
Why it matters: A steady year-over-year rise in leak-site postings means ransomware groups are successfully breaching and extorting more organizations, not fewer — this is the moment to confirm your detection coverage for lateral movement and data staging, not just initial access, since that's where most of these incidents are still caught too late.
Read source →