Cloud & Enterprise
Cloud and enterprise IT covers identity, access, SaaS, hybrid infrastructure and corporate attack surfaces. The analysis helps readers follow risks, incidents and architectural decisions relevant to complex environments.

Infostealers Overtake Phishing and Exploits as Top Enterprise Cloud Access Vector
Infostealer malware logs have surpassed phishing and vulnerability exploits as the primary initial access vector for enterprise cloud…

Certighost: Ten Days After the Patch, the Exploit Is Public and the Domain Falls
The Certighost proof-of-concept for CVE-2026-54121 lets a standard domain user impersonate a Domain Controller via AD CS. Released exa…

Record Patch Tuesday: Microsoft Fixes 570 CVEs and Two Actively Exploited Zero-Days in AD FS and SharePoint
The July 14, 2026 Patch Tuesday sets a record with 570 CVEs patched, two actively exploited zero-days, and a third publicly disclosed.…

Stadler Rejects $12.3M Ransom: Everest Fails to Leak Data
Swiss rail manufacturer Stadler Rail publicly refused a 10 million Swiss franc ($12.3 million) ransom demand from the Everest ransomwa…

MSI Center's Ghost Driver: Local Escalation to SYSTEM in One Command
ZDI-26-430 discloses an origin validation flaw in the MSI Center kernel driver NTIOLib_X64.sys, tracked as CVE-2026-6102 (CVSS 7.8). A…

Fastjson 1.x Has No Exit: When Standard Mitigations Aren't Enough
CVE-2026-16723 hits Fastjson 1.2.68–1.2.83 with a CVSS 9.0. The exploit works with default settings, requires no AutoType or gadgets,…

Oracle Simphony: Four Critical CVEs Expose Hospitality POS to RCE
Four vulnerabilities in Oracle Hospitality Simphony enable unauthenticated remote code execution and NTLM hash theft. Patches released…

Microsoft Dismantles StealC C2 Network, But Stolen Logs Keep Fueling Breaches
On June 24, 2026, Microsoft and Europol took down over 200 StealC and Amadey C2 domains. Yet years-old credential logs still circulate…

Wind Tre Fined €1.7M: Social Engineering Beats Firewalls
Italy's data protection authority fined Wind Tre €1,715,600 for two breaches caused by phone-based social engineering at retail stores…

F5 BIG-IP: Source Code Stolen, 45 Patches in One Quarter, CISA on Alert
A nation-state actor stole F5 BIG-IP source code and information on undisclosed vulnerabilities. CISA issued Emergency Directive ED 26…

Device Code Phishing: Legitimate Authentication Becomes the Weapon to Breach M365
Device code phishing exploits Microsoft's legitimate OAuth flow to bypass MFA. Low-cost PhaaS kits like DEBULL and ARToken have indust…

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware
The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…