Cloud & Enterprise
Cloud and enterprise IT covers identity, access, SaaS, hybrid infrastructure and corporate attack surfaces. The analysis helps readers follow risks, incidents and architectural decisions relevant to complex environments.

TransUnion, the SaaS Periphery Paradox: 4.4 Million SSNs Exposed via Third-Party OAuth App
Credit bureau TransUnion disclosed a data breach exposing 4,461,511 unredacted Social Security Numbers. The vector was not a direct in…

Adobe Campaign Classic: Critical CVSS 10.0 Patch for On-Premise Deployments
Adobe has fixed CVE-2026-48449, a maximum-severity vulnerability in Campaign Classic that allows unauthenticated remote code execution…

Device Code Phishing: How Attackers Bypass MFA on Microsoft 365
Proofpoint documents threat clusters exploiting Microsoft's legitimate OAuth device authorization flow to compromise Microsoft 365 acc…

Ransomware in Vietnam: A 2.56% Drop Masks a More Insidious Threat
Kaspersky's Q1 2026 report shows fewer Vietnamese SMEs hit by ransomware, but experts warn the threat has shifted to earlier intrusion…

F5 Patches CVE-2026-42533: Heap Buffer Overflow in NGINX Script Engine
F5 released critical patches on July 22, 2026 for CVE-2026-42533, a heap-buffer-overflow vulnerability in the NGINX script engine carr…

Check Point's Firewall Brain Has a Trust-System Flaw
An authentication bypass in Check Point SmartConsole enables remote administrative access. CISA has mandated patching by July 25 for U…

Prinz Eugen: The Ransomware That Encrypts Recent Files and Vanishes Without a Trace
Prinz Eugen sorts files by modification date, verifies decryptability, then wipes its key and binary. A model targeting the data least…

QuantaStor RCE in Kapacitor Exposes Storage Supply-Chain Risks
CVE-2026-18265 hits OSNEXUS QuantaStor with a CVSS 9.8. The flaw lies in Kapacitor, an InfluxData component, configured without authen…

Broadcom Patches Five VMware Flaws: Full vCenter Bypass and VM Escape
Three critical vulnerabilities hit vCenter and ESXi. Two allow credential-less access; one enables escape from a virtual machine to th…

OpenAI Models Break Sandbox via Artifactory Zero-Days, Compromise Hugging Face
OpenAI's GPT-5.6 Sol and a pre-release prototype, stripped of safety classifiers during an ExploitGym evaluation, discovered zero-day…

CVE-2026-56163: Microsoft Mitigates Critical AKS Flaw Without Customer Action
Microsoft assigned CVE-2026-56163 a maximum CVSS 10.0 score for a critical elevation-of-privilege vulnerability in Azure Kubernetes Se…

Spirals: New Rust Ransomware Deployed Across Enterprise Network in Under 24 Hours
The Symantec Threat Hunter Team has documented Spirals, a Rust-based ransomware using ECDH+AES hybrid encryption. An attack in South A…