Cloud & Enterprise
Cloud and enterprise IT covers identity, access, SaaS, hybrid infrastructure and corporate attack surfaces. The analysis helps readers follow risks, incidents and architectural decisions relevant to complex environments.

Microsoft Patch Tuesday: Legacy MSMQ Flaw Enables Local SYSTEM Escalation
The May 12, 2026, security update addresses CVE-2026-33838, an elevation-of-privilege vulnerability in Windows Message Queuing (MSMQ).…

GitHub Enterprise RCE: A Single 'git push' Puts Corporate Backends at Risk
CVE-2026-3854 allows Remote Code Execution on GitHub Enterprise Server via user-controlled push options. Reports indicate that 88% of…

Microsoft Exchange Zero-Day Exploited: Permanent Patch Restricted to ESU Customers
Microsoft has confirmed active in-the-wild exploitation of CVE-2026-42897 affecting Exchange on-premise servers. CISA has issued a hig…

Mistral AI Hit by Supply Chain Attack; 450 Repositories Put Up for Sale
Mistral AI has confirmed a supply chain compromise involving contaminated SDKs and abused SLSA provenance. The threat actor TeamPCP is…

Cisco SD-WAN Zero-Day: 'Ghost Peers' Infiltrated Controllers Since 2023
CVE-2026-20127 in Cisco Catalyst SD-WAN controllers allowed a sophisticated threat actor to impersonate trusted peers for over three y…

GitHub RCE: Crafted 'git push' Commands Compromised Backend Servers
CVE-2026-3854: An X-Stat header injection vulnerability in GitHub enabled remote code execution via a single push operation. Approxima…

Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents
Microsoft’s MDASH, an agentic multi-model system, discovered 16 vulnerabilities—including four critical RCEs—patched in the May 2026 u…

Exim 'Dead.Letter' Vulnerability: Critical RCE Risk for GnuTLS-Based Builds
CVE-2026-45185 is a use-after-free vulnerability in the Exim SMTP BDAT parser that allows unauthenticated RCE on GnuTLS-compiled serve…

Foxconn Confirms North American Cyberattack; Nitrogen Ransomware Group Claims 8TB Data Breach
Foxconn has confirmed a cyberattack affecting several of its North American facilities. The Nitrogen ransomware group claims to have e…

West Pharmaceutical Services Hit by Ransomware, Disrupting Global Operations
West Pharmaceutical Services has confirmed a ransomware attack involving data exfiltration and systemic encryption, causing significan…

Critical GitHub RCE: A Single Git Push Can Trigger Remote Code Execution
A critical RCE vulnerability (CVE-2026-3854) affecting GitHub.com and Enterprise Server allows arbitrary code execution via crafted gi…

Active OAuth Redirection Attacks Targeting Government Entities via Entra ID
Microsoft has identified a phishing campaign exploiting OAuth 2.0 flows to deliver multi-stage malware to public sector organizations,…