Security & Threat Intelligence

The Watch

The Signal

Microsoft says an exploited CVSS 10.0 in Entra ID requires no action from you.

CVE-2026-69836 lives in vendor-side code. That means nothing on your side closes it, and nothing you've been handed proves your tenant went untouched. No exploitation window has been published. No per-tenant exposure telemetry either. The only place a clean identity plane can still be demonstrated is sign-in and audit logs, which makes your retention setting the deciding variable.

In Play

  1. An Exploited Identity Plane With No Customer Patch

    Microsoft disclosed CVE-2026-69836, a CVSS 10.0 Entra ID remote code execution flaw already exploited in the wild, then told customers no action is required, per The Hacker News. Nothing on your side is patchable, so the only proof your tenant went untouched is a hunt you run and document yourself. Google is separately tracking three Russian espionage clusters that never break MFA — they get victims to approve app passwords, OAuth grants and device codes instead.

  2. Edge Exposure You Cannot Scope by Build Version

    Citrix's NetScaler authentication bypass, CVE-2026-19490, is scoped by running-config strings rather than build version, and ShadowServer counts more than 22,000 ADC and 1,800 Gateway instances answering on the internet. A fleet-wide answer of "we're on a supported build" tells you nothing about which appliances are exposed. Zimbra's actively exploited command injection, CVE-2026-73570, has had a fix since July, so exploitation is landing on patch latency rather than on a true zero-day.

  3. The Patch Queue Became an Arithmetic Problem

    Oracle shipped 943 new patches across more than 1,000 CVEs on Aug 18, Atlassian disclosed 10 critical and 162 high issues in third-party dependencies, and Splunk published over 150, per SANS NewsBites. Counting Microsoft's 421 from the prior month, that is roughly 1,700 patchable items in 30 days. Five of nine new Cisco advisories in Crosswork and Secure Workload are CVSS 10.0, and those two products enforce your microsegmentation policy. Sequence by internet exposure, not CVSS order.

  4. Coercion as an Insider Recruitment Model

    Kyle William Spitze, an original member of the 764 network and leader of its Harm Nation offshoot, received 77 years, the longest sentence imposed on a nihilistic violent extremist offender, per CyberScoop. The leverage was doxing and swatting threats, and prosecutors built the case on device forensics rather than platform telemetry. The FBI reports a 500% year-over-year rise in these arrests, which pushes the networks into invite-only channels your threat intel team cannot observe.

  5. The Permission Dialog Is Now the macOS Perimeter

    OpenAI's ChatGPT for Mac iMessage plug-in requires Full Disk Access, Contacts and Apple Events automation, surrendering the whole macOS TCC privacy boundary for that application in three user clicks, per Techpresso's reporting. The plug-in reads inbound messages and can also send them, putting untrusted input and an outbound write primitive in the same trust context. Separately, coding agents persist every session in plaintext under ~/.claude and ~/.codex, paths no EDR rule currently watches.

Deep Dives

  1. Nothing to Patch, Everything to Prove

    Microsoft holds the only remediation lever for an exploited identity-plane flaw, which leaves your tenant's innocence as something you have to manufacture out of logs you may not still hold.

    What the advisory removes, and what it leaves behind Read precisely, "no customer action required" means the vulnerable code is Microsoft's and there is nothing on the customer side to apply. It does not mean the tenant went untouched, and…

    3 action items

  2. Your NetScaler Fleet Cannot Be Scoped by Build Number

    Two of the edge flaws covered here had published fixes before exploitation began, which makes the failure a scoping and sequencing problem rather than a threat-intelligence one.

    Scope by configuration, not by version The normal vulnerability workflow fails here because exposure is configuration-dependent . Citrix publishes grep-able configuration strings, and the split matters. Recent builds are affected only where a SAML action is configured. Older builds are…

    3 action items

  3. The Insider Who Is a Victim Before They Are a Violator

    Record sentencing in the 764 network documents a recruitment model that runs on threats rather than payment, arriving the same week two large involuntary-departure cohorts hit the workforce.

    Read the prosecution as a tradecraft document The case is a threat report on leverage. The mechanism was exposure, not content : doxing and swatting threats applied to dozens of victims. That distinction decides which control matters. Content takedown is…

    3 action items

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn