Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft App Quietly Installs Bing as Default Search in Browsers
August 23, 2026
Critical Azure and Entra ID Flaws Let Attackers Steal Credentials, Gain RCE
August 23, 2026
Iran-linked hackers force UK power plant offline in 4-day cyberattack
August 23, 2026
Home/CyberSecurity News/Critical Azure and Entra ID Flaws Let Attackers Steal Credentials, Gain RCE
CyberSecurity News

Critical Azure and Entra ID Flaws Let Attackers Steal Credentials, Gain RCE

Key Takeaways Multiple critical vulnerabilities across Microsoft Azure, Entra ID, SCCM, and Copilot have been disclosed, potentially allowing credential theft, remote code execution, and data...

Emy Elsamnoudy
Emy Elsamnoudy
August 23, 2026 11 Min Read
4 0

Key Takeaways

  • Multiple critical vulnerabilities across Microsoft Azure, Entra ID, SCCM, and Copilot have been disclosed, potentially allowing credential theft, remote code execution, and data exfiltration.
  • Citrix NetScaler ADC/Gateway devices are affected by critical authentication bypass and denial-of-service flaws, requiring immediate patching.
  • Microsoft is moving to make passkeys the default MFA method in Entra ID, retiring SMS/voice options due to their susceptibility to phishing attacks.
  • Ransomware groups like Medusa and criminal AI services like MessiahGPT are actively exploiting known vulnerabilities and lowering the barrier for sophisticated attacks.

Cybersecurity News Roundup: Critical Flaws, AI Threats, and MFA Evolution

Azure and Entra ID Flaws Expose Credentials and Enable RCE

Recent disclosures have unveiled critical vulnerabilities impacting Microsoft’s cloud ecosystem, including Azure and Entra ID. Attackers are leveraging obfuscated HTML, XHTML, and SVG attachments, often delivered via Amazon SES and disguised as HR-related communications, to steal session tokens. A significant concern is that these stolen tokens remain valid even after password resets. To counter this, security teams must proactively invalidate active sessions, implement FIDO2 keys, and activate Continuous Access Evaluation within Entra ID.

Table Of Content

  • Key Takeaways
  • Cybersecurity News Roundup: Critical Flaws, AI Threats, and MFA Evolution
  • Azure and Entra ID Flaws Expose Credentials and Enable RCE
  • GitHub Experiences Widespread Outage
  • Critical Vulnerabilities Found in Citrix NetScaler
  • Anthropic’s Mythos 5 Enhances Claude Security Capabilities
  • Microsoft SCCM Flaw Chained for Remote Code Execution
  • Windows Defender Update Addresses 0-day Vulnerability
  • Critical CoSnitch Vulnerability in Microsoft Copilot
  • Microsoft to Default to Passkeys in Entra ID
  • Critical 0-day Vulnerability in Cursor IDE
  • Defender Driver Can Be Weaponized to Disable EDR
  • Microsoft 365 MFA Bypass and Session Hijack
  • CISA Warns of Medusa Ransomware Data Theft
  • Minimalist Windows Backdoor Hides C2 Domain
  • “Zombie Card” Flaw Revives Expired Visa Cards for Purchases
  • MessiahGPT Fuels Ransomware and Phishing Attacks
  • Shell Investigates Data Breach Following Cl0p Ransomware Claim
  • Hackers Hijack Thousands of WordPress Sites for C2 Network
  • What You Should Do

GitHub Experiences Widespread Outage

On August 17, 2026, GitHub experienced a substantial global outage starting around 13:40 UTC. The disruption affected core functionalities such as Pull Requests, Issues, Actions, Webhooks, and Copilot, leading to approximately 20% error rates across general traffic. Archive and raw content downloads saw an even higher failure rate, reaching 50%. Enterprise users relying on SAML/OIDC authentication and SCIM provisioning also faced impacts, potentially hindering single sign-on access for organizations utilizing GitHub Enterprise Cloud.

Microsoft acknowledged the global extent of the issue, though the specific root cause was not publicly revealed. The progression of status updates suggested a system-wide infrastructure overload rather than an isolated software defect. Developers encountered stalled continuous integration/continuous deployment (CI/CD) pipelines and unreliable issue tracking, with no immediate workarounds available beyond postponing non-essential operations.

Critical Vulnerabilities Found in Citrix NetScaler

Cloud Software Group has revealed two critical security flaws affecting NetScaler ADC and Gateway products. The first, CVE-2026-19490, carries a CVSS score of 9.3 and represents an authentication bypass vulnerability. This flaw impacts configurations involving SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA vservers. The second vulnerability, CVE-2026-19489, rated 8.8 CVSS, is a memory overflow issue that can be triggered when SIP ALG is enabled within LSN groups, potentially leading to a denial-of-service. The exploitability of the authentication bypass depends on the specific build version and SAML configuration.

Both vulnerabilities affect NetScaler versions predating 14.1-73.32 and 13.1-63.21, including FIPS/NDcPP variants. These issues were responsibly disclosed by a penetration tester from JPMorgan Chase. Given that authentication gateways serve as primary access points for remote users, Cloud Software Group is strongly advising immediate software upgrades, noting that threat actors typically begin scanning for newly disclosed vulnerabilities once technical details become public.

Anthropic’s Mythos 5 Enhances Claude Security Capabilities

Anthropic has integrated its Claude Mythos 5 model into Claude Security, currently in public beta for Enterprise customers. This enhancement allows for advanced codebase scanning, providing findings classified by Common Weakness Enumeration (CWE) along with severity, confidence levels, and suggested remedies. All proposed fixes require human review before implementation. The design deliberately restricts users to predefined defensive outputs, preventing open-ended prompting of Mythos 5 to mitigate the risk of the model being repurposed for offensive operations.

In a related initiative, Anthropic has launched the $35 million Defender Advantage Fund (0xDAF), offering Claude credits to support open-source security remediation efforts. The company is also expanding its Cyber Verification Program, which provides vetted organizations with reduced safeguards for authorized security tasks. These moves reflect an industry-wide trend toward delivering dual-use AI cyber capabilities through structured and controlled workflows.

Microsoft SCCM Flaw Chained for Remote Code Execution

XM Cyber has detailed the complete attack chain for CVE-2026-47301, a vulnerability in SCCM’s AdminService REST API that was patched on July 14, 2026. This flaw involved a chunked CAB upload endpoint that bypassed the authorization checks applied to standard uploads, enabling any authenticated domain user to submit malicious archives. When combined with inadequate signature validation and a “CabSlip” path traversal vulnerability, attackers could write files outside their designated extraction directories.

The attack culminates in a DLL hijacking scenario targeting the SYSTEM-privileged SMS Executive service through an unsigned adsource.dll, ultimately achieving SYSTEM-level code execution from a standard domain account. While Microsoft’s July patch addressed the primary exploitation path, users with the Operations Administrator role can still leverage downstream components of the exploit. A comprehensive fix is anticipated with ConfigMgr 2609, slated for release in October 2026.

Windows Defender Update Addresses 0-day Vulnerability

On August 18, 2026, a series of Security Intelligence updates caused Microsoft Defender’s Quick, Full, and Offline scans to crash. The MsMpEng.exe process failed within mpengine.dll due to an access violation. Community researchers speculated that this problematic rollout might have been a hurried effort to counter “ShieldBreak,” a Defender local privilege-escalation zero-day that emerged shortly after Patch Tuesday, capable of elevating a low-privileged user to SYSTEM privileges.

Microsoft has not officially confirmed any link between the crashes and ShieldBreak, nor had it issued a formal bulletin at the time of reporting. Security Intelligence Update 1.457.236.0, followed by 1.457.238.0, restored scanning functionality for many systems. However, testing indicated the fix was not universally effective, leaving some users to rely on alternative antivirus solutions.

Critical CoSnitch Vulnerability in Microsoft Copilot

Varonis Threat Labs has disclosed CoSnitch (CVE-2026-24301), a critical vulnerability in Copilot Personal that was patched on August 18, 2026. This flaw combined an undocumented URL parameter, Copilot’s integrated URL-fetching capability, and its persistent memory feature to surreptitiously exfiltrate data from linked accounts such as Gmail and Google Drive after a single user click. The stolen data was disguised as routine outbound browsing traffic. A variant involving poisoned memory could even persist through password resets and device re-enrollment.

Notably, Varonis uncovered this exploit through “meta-hacking”—repeatedly querying Copilot about why the attack “wasn’t possible” until its own explanations revealed the precise undocumented parameter required. Microsoft found no evidence of pre-patch exploitation. However, this case highlights the increasing risks as AI assistants gain extensive access to enterprise data, prompting Varonis to recommend treating Copilot as a privileged insider that requires regular access audits.

Microsoft to Default to Passkeys in Entra ID

Effective September 1, 2026, Microsoft will begin automatically enrolling Entra ID users currently utilizing SMS or voice-based multi-factor authentication (MFA) into passkey registration prompts. This initiative aims to transition away from MFA methods susceptible to phishing, SIM swapping, and number portability attacks. Microsoft plans to fully discontinue native SMS/voice MFA delivery on February 1, 2027, after which affected users will face a mandatory, non-optional passkey registration prompt with no opt-out.

Organizations wishing to retain SMS/voice MFA must migrate to customer-managed telecom providers via the Microsoft Security Store. Provider information will be available from September 18, with configuration options starting October 30, 2026. While administrators can temporarily defer this change using the passkeyDynamicMigration property in Microsoft Graph, this only delays, rather than prevents, eventual enforcement. Therefore, early adoption of passkeys, Windows Hello for Business, and FIDO2 keys is the recommended approach.

Critical 0-day Vulnerability in Cursor IDE

Mindgard has disclosed CVE-2026-63093, a critical binary-planting vulnerability (CVSS 8.7) in the Cursor IDE. This flaw allows a malicious git.exe file placed at the root of a repository to automatically execute on Windows the moment the project is opened, without any user prompts, AI involvement, or prior access. Initially, Cursor deemed the report out of scope under a shared-responsibility model but quietly patched the issue on July 13, 2026, one day before public disclosure, without issuing a formal security advisory.

Further investigation revealed that the same auto-execution flaw applies to hatch.exe, triggered by pyproject.toml files. This variant is stealthier, as build files typically do not raise immediate suspicion. Cursor ships with Workspace Trust disabled by default, meaning that merely opening a folder can trigger code execution. This vulnerability joins other Cursor flaws discovered in 2026, such as the DuneSlide sandbox escape, highlighting the expanding attack surface in AI-powered Integrated Development Environments.

Defender Driver Can Be Weaponized to Disable EDR

Check Point Research has demonstrated that Microsoft Defender’s legitimate, signed BTR.sys remediation driver can be exploited by attackers with administrative privileges. By reproducing its undocumented, RC4-encrypted transaction protocol, attackers can leverage BTR.sys to perform kernel-level file and registry operations. Since BTR.sys loads early in the “Boot Bus Extender” group, preceding the initialization of many user-mode security agents, researchers identified a “golden window” during which it could potentially remove security binaries undetected.

Unlike typical Bring-Your-Own-Vulnerable-Driver (BYOVD) attacks, this technique utilizes a built-in Microsoft component with a valid signature, thereby undermining signature-based trust mechanisms. While no in-the-wild abuse has been confirmed, Check Point’s proof-of-concept tool (BTR_CLI) underscores the importance of proactive detection using Sysmon Event IDs 15 and 6.

Microsoft 365 MFA Bypass and Session Hijack

TrendAI has documented a cloud-centric Business Email Compromise (BEC) campaign that did not involve malware. A finance employee received a fraudulent “PTO Request Denied” email, which led them through redirects to an Adversary-in-the-Middle (AiTM) relay. This relay successfully captured a fully authenticated Microsoft 365 session, bypassing MFA and conditional access policies. Investigators detected suspicious “impossible travel” logins from Amsterdam and Los Angeles occurring within minutes of each other, indicating a compromised session.

Over approximately 30 days, attackers impersonated a vendor and later a senior Accounts Payable colleague using look-alike domains. They then pushed fraudulent bank detail changes for roughly 20 legitimate invoices, while simultaneously creating malicious inbox rules to conceal vendor collection notices. Defenders should monitor for impossible travel alerts in conjunction with mailbox rule modifications and enforce dual approval and out-of-band verification before processing any changes to vendor payment details.

CISA Warns of Medusa Ransomware Data Theft

CISA, FBI, and HHS have jointly updated their advisory (AA25-071A) on Medusa ransomware, confirming that the Ransomware-as-a-Service (RaaS) operation has compromised over 500 critical infrastructure organizations across sectors including healthcare, education, legal, and manufacturing. Affiliates gain initial access either through Initial Access Brokers, who pay up to $1 million for credentials, or by exploiting known vulnerabilities such as ScreenConnect (CVE-2024-1709), Fortinet FortiClient EMS, and a newly identified BeyondTrust RCE (CVE-2026-1731). Exploitation often occurs within 24 hours of public disclosure.

Medusa employs living-off-the-land techniques, abuses vulnerable drivers to disable Endpoint Detection and Response (EDR) solutions, and utilizes tools like Mimikatz, CrackMapExec, and Rclone for credential harvesting and data exfiltration. Following these steps, it deploys its gaze.exe payload, which deletes shadow copies and encrypts files using AES-256, appending the .medusa extension. Ransom demands have reached $15 million, with victims given 48 hours to negotiate via Tor or Tox. Agencies are urging immediate patching, network segmentation, and the implementation of phishing-resistant MFA.

Minimalist Windows Backdoor Hides C2 Domain

Analysts at Gen Digital discovered a minimalist 12,288-byte Windows backdoor, disguised as Realtek audio software. This implant cleverly conceals its Command and Control (C2) domain by counting trailing whitespace characters on lines within a fake desktop.ini file. This technique is simple enough to evade conventional string-based and entropy-based scanning methods. The implant, found on a single Windows 7 SP1 workstation, communicates via an ICMP ping followed by HTTP POST commands.

Persistence for this backdoor relies on a Windows Management Instrumentation (WMI) event subscription that triggers at a specific clock time, rather than at system boot, keeping it dormant until its scheduled activation. Although its C2 infrastructure expired in 2021, researchers emphasize that low-prevalence, structurally unusual malware warrants careful examination beyond mere hash and domain matching, particularly concerning WMI filters and configuration files padded with whitespace.

“Zombie Card” Flaw Revives Expired Visa Cards for Purchases

Researchers from the University of Massachusetts Amherst presented “Zombie Card” at USENIX Security, detailing an NFC relay attack that can reactivate expired Visa contactless cards for real-world purchases. The vulnerability stems from the fact that card expiration is enforced solely as a terminal-side policy check, reading a plaintext field. Crucially, Visa’s EMV Kernel 3 omits this expiry data from cryptographically signed records. In contrast, Mastercard, Amex, and Discover kernels include this data, allowing them to detect tampering and block such attacks.

Testing conducted across five major US banks in actual retail environments revealed inconsistent issuer-side protection. One bank, for instance, approved “zombie” transactions up to $500 because it only validated account and cryptogram data, not the specific card instance. Researchers disclosed their findings to Visa in May 2025. Visa’s red team is still working to reproduce the attack, and no confirmed fix has been deployed, leaving cardholders reliant on physically destroying expired cards to mitigate the risk.

MessiahGPT Fuels Ransomware and Phishing Attacks

Trellix researchers have identified MessiahGPT, an uncensored criminal AI service advertised on BreachForums. This service is marketed for generating ransomware, phishing kits, stealers, crypters, and rootkits, claiming to use a 128-expert Mixture-of-Experts architecture trained on unrestricted and dark-web data. The service, associated with messiahgpt[.]de and a Telegram community, offers free trial queries followed by crypto-only subscriptions starting around $8/month, effectively lowering the barrier for inexperienced attackers.

While Trellix could not independently verify the operators’ technical claims, the platform is confirmed to be active and promoted within criminal circles. The greater concern is the potential for scale: AI-generated phishing and malware variants can bypass static filters. Consequently, defenders are urged to prioritize behavioral detection—focusing on sender reputation, credential-access attempts, and encryption activity—rather than attempting to specifically fingerprint “AI-generated” content.

Shell Investigates Data Breach Following Cl0p Ransomware Claim

Energy giant Shell has initiated an incident response investigation after the Cl0p extortion group listed the company on a dark web leak site. Cl0p claims to have stolen approximately 89 GB of data, including engineering drawings, facility photographs, and testing reports. Shell confirmed it is investigating with third-party forensics firms but has not confirmed any operational disruption to its refineries or drilling operations.

Cl0p, also known as TA505 or FIN11, is notorious for pure extortion tactics, typically involving the mass exploitation of managed file transfer platforms such as MOVEit and Accellion FTA, rather than data encryption. This approach complicates detection, as compromised systems often continue to operate normally while data remains exfiltrated. Critical infrastructure organizations are urged to audit internet-facing management appliances and enforce multi-factor authentication across all administrative services.

Hackers Hijack Thousands of WordPress Sites for C2 Network

Check Point Research has uncovered “StopAndProtect,” a campaign that has co-opted nearly 2,000 hacked WordPress sites, transforming them into a resilient Command and Control (C2) network. Over 6,000 unique victim IP addresses have been identified, primarily concentrated in the US, Russia, and India. The infection process begins with deceptive CAPTCHA prompts that trick visitors into pasting malicious PowerShell commands into their terminals. This action launches a multi-stage .NET-loader chain that deploys various threats, including ransomware, credential stealers, screen lockers, and a USB-spreading worm.

Operational security lapses by the threat actors exposed internal logs and even a personal machine infection, revealing a custom VB6 tool used to manage the hijacked WordPress botnet. One compromised site had remained unpatched since 2021, containing nearly 40 vulnerabilities. This highlights how neglected Content Management System (CMS) installations are being weaponized as full C2 infrastructure rather than merely simple phishing redirectors.

What You Should Do

  • Patch Immediately: Apply all available security updates for Microsoft SCCM, Citrix NetScaler, and any affected WordPress installations.
  • Enforce Strong MFA: Implement phishing-resistant MFA methods like FIDO2 keys and passkeys across all accounts, especially for Microsoft 365 and Entra ID.
  • Invalidate Sessions: For Entra ID users, invalidate active sessions and enable Continuous Access Evaluation to mitigate stolen token risks.
  • Audit and Monitor: Regularly audit access to AI assistants like Copilot and monitor for suspicious activities such as impossible travel logins, mailbox rule changes, and unauthorized file access.
  • Network Segmentation: Implement robust network segmentation to limit lateral movement in case of a breach, particularly for critical infrastructure.
  • Educate Users: Provide ongoing training to employees on recognizing phishing attempts and the dangers of pasting commands from untrusted sources.
  • Destroy Expired Cards: Physically destroy expired Visa contactless cards to prevent “Zombie Card” exploitation until a formal fix is deployed.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

BreachCVEExploitHackerMalwarePatchphishingransomwareSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Iran-linked hackers force UK power plant offline in 4-day cyberattack

Next Post

Microsoft App Quietly Installs Bing as Default Search in Browsers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Claude Security Adds Mythos 5 for Enhanced Vulnerability Scanning
August 21, 2026
WhatsApp Groups Used for Stock Market Manipulation and Crypto Scams
August 21, 2026
Microsoft Doubles Mailbox Storage to 100 GB for Exchange Online Users
August 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us