Cloud & Enterprise
Cloud and enterprise IT covers identity, access, SaaS, hybrid infrastructure and corporate attack surfaces. The analysis helps readers follow risks, incidents and architectural decisions relevant to complex environments.

Cisco Confirms FMC Zero-Day: Static Credentials Under Attack, CISA Sets August 1 Deadline
Cisco confirms active exploitation of CVE-2026-20316 in Secure Firewall Management Center. CISA adds the flaw to its KEV catalog, mand…

F5 Races Against Its Own Stolen Code: 45 Vulnerabilities Disclosed in a Single Quarter
Nation-state actors compromised F5's internal systems, exfiltrating portions of BIG-IP proprietary source code and details on undisclo…

Broadcom Patches Five VMware Vulnerabilities: Three Critical Flaws Up to CVSS 9.8
Broadcom released patches on July 29, 2026 for five vulnerabilities in VMware vCenter, ESXi, Workstation, and Fusion. Three are critic…

Estée Lauder's 10-Month Oracle EBS Breach: The Suspected Patch Gap That Let Clop In
Estée Lauder disclosed a 10-month breach of its Oracle E-Business Suite HR system. The Clop ransomware group exploited CVE-2025-61882,…

TrendAI Vision One and the 'Historical' CVE-2025-71387: Patched in December
Trend Micro published bulletin KA-0023937 for CVE-2025-71387, a privilege escalation vulnerability in TrendAI Vision One that was alre…

Kemp LoadMaster: Hard-Coded Key in enablexroot Exposes Appliance to Root
Progress Software has patched CVE-2026-59689, a CVSS 8.0 privilege-escalation vulnerability in Kemp LoadMaster caused by a hard-coded…

TransUnion, the SaaS Periphery Paradox: 4.4 Million SSNs Exposed via Third-Party OAuth App
Credit bureau TransUnion disclosed a data breach exposing 4,461,511 unredacted Social Security Numbers. The vector was not a direct in…

Adobe Campaign Classic: Critical CVSS 10.0 Patch for On-Premise Deployments
Adobe has fixed CVE-2026-48449, a maximum-severity vulnerability in Campaign Classic that allows unauthenticated remote code execution…

Device Code Phishing: How Attackers Bypass MFA on Microsoft 365
Proofpoint documents threat clusters exploiting Microsoft's legitimate OAuth device authorization flow to compromise Microsoft 365 acc…

Ransomware in Vietnam: A 2.56% Drop Masks a More Insidious Threat
Kaspersky's Q1 2026 report shows fewer Vietnamese SMEs hit by ransomware, but experts warn the threat has shifted to earlier intrusion…

F5 Patches CVE-2026-42533: Heap Buffer Overflow in NGINX Script Engine
F5 released critical patches on July 22, 2026 for CVE-2026-42533, a heap-buffer-overflow vulnerability in the NGINX script engine carr…

Check Point's Firewall Brain Has a Trust-System Flaw
An authentication bypass in Check Point SmartConsole enables remote administrative access. CISA has mandated patching by July 25 for U…