Mirage2FA phishing-as-a-service is hijacking Microsoft 365 sessions at over 4,500 mostly US organizations, bypassing MFA with adversary-in-the-middle tactics.
CISA has given federal agencies three days to patch Oracle HTTP Server and WebLogic proxy plug-in flaw CVE-2026-21962 after evidence of active exploitation.
Android banking Trojan ToxicPanda 2.0 expands from consumer fraud to enterprise risk with 167 remote commands and targeting of 349 finance apps across 16 countries.[4][6][9]
Check Point Research shows Microsoft Defender's BTR.sys boot-time driver can be repurposed to wipe AV and EDR before startup, with no CVE or patch planned.
Microsoft warns that CVE-2026-69836, a CVSS 10.0 remote code execution flaw in Entra ID, has been exploited in the wild but says it is already fully mitigated.
Microsoft's August 2026 Patch Tuesday ships 400+ fixes, including an exploited WinSock zero-day and critical flaws across Windows, Azure and Microsoft 365.