● On the wire
Ubuntu 16.04 LTS Linux kernel Privilege Escalation Vulnern USN-8548-1//Ubuntu 16.04 Ruby Critical IMAP Injection Buffer Overflow USN-8556-1//Ubuntu 24.04 LTS Linux Kernel Important Security Advisory USN-8569-1//Cisco RoomOS Security Hardening Release: July 2026//Ubuntu 26.04 Tar Important Regression Extraction Issue USN-8477-2//Ubuntu 26.04 Linux Kernel Privilege Escalation Vulnerabilities USN-8568-1//Ubuntu 20.04 LTS Linux Kernel Important Security Fixes USN-8547-1//Ubuntu 26.04 FreeType Important Denial of Service CVE-2026-50811//Debian Chromium Critical Denial of Service Info Disclosure DSA-6390-1//Ubuntu 26.04 SQLite Critical DoS Buffer Overread USN-8565-1//Ubuntu 26.04 nginx Critical Denial of Service Vuln 8563-1//Ubuntu 26.04 LTS Python-idna Important DoS Issue 8549-1//Ubuntu 26.04 libslirp Important Info Exposure CVE-2026-9539 Advisory 8550-1//Ubuntu 24.04 LTS Linux Kernel Critical Security Update 8570-1//Debian tiff Critical Denial of Service or Code Exec Advisory DSA-6392-1//Ubuntu 16.04 LTS Linux kernel Privilege Escalation Vulnern USN-8548-1//Ubuntu 16.04 Ruby Critical IMAP Injection Buffer Overflow USN-8556-1//Ubuntu 24.04 LTS Linux Kernel Important Security Advisory USN-8569-1//Cisco RoomOS Security Hardening Release: July 2026//Ubuntu 26.04 Tar Important Regression Extraction Issue USN-8477-2//Ubuntu 26.04 Linux Kernel Privilege Escalation Vulnerabilities USN-8568-1//Ubuntu 20.04 LTS Linux Kernel Important Security Fixes USN-8547-1//Ubuntu 26.04 FreeType Important Denial of Service CVE-2026-50811//Debian Chromium Critical Denial of Service Info Disclosure DSA-6390-1//Ubuntu 26.04 SQLite Critical DoS Buffer Overread USN-8565-1//Ubuntu 26.04 nginx Critical Denial of Service Vuln 8563-1//Ubuntu 26.04 LTS Python-idna Important DoS Issue 8549-1//Ubuntu 26.04 libslirp Important Info Exposure CVE-2026-9539 Advisory 8550-1//Ubuntu 24.04 LTS Linux Kernel Critical Security Update 8570-1//Debian tiff Critical Denial of Service or Code Exec Advisory DSA-6392-1//
Microsoft 365, Entra ID, and OAuth abuse remain a top initial-access channel
Top story — News

Microsoft 365, Entra ID, and OAuth abuse remain a top initial-access channel

Identity abuse is one of the clearest operational threats in the feed, especially around Microsoft 365 and Entra ID. Attackers are using fake passkey enrollment, device-code flow abuse, OAuth client ID spoofing, malicious guest accounts, and consent tricks to evade detection and harvest credentials. These techniques matter because they often generate weak telemetry or no successful sign-in event, which makes…

Read the article →
From the newsroom