Aug 17–23: Entra ID CVSS 10 KEV, Citrix, RedC2
Entra ID CVSS 10 hits KEV. Citrix auth bypass, Zimbra RCE exploited, two supply-chain attacks. CareCloud 3.7M breach. Seven items require action.
- CVE-2026-69836 (Microsoft Entra ID, CVSS 10.0) added to CISA KEV Aug 21. Deserialization flaw enabling remote code execution. Active exploitation confirmed. Patch immediately.
- Citrix NetScaler critical auth bypass CVE-2026-19490 confirmed Aug 20. Exploitation expected imminently per Rapid7. Patch or mitigate now.
- Zimbra Collaboration Suite OS command injection CVE-2026-73570 actively exploited in the wild as of Aug 20. CISA KEV listed Aug 21.
- Two supply-chain attacks in four days: 14 trojanized npm packages delivering the RedC2 4.0 Linux backdoor (AI-assisted C2, Aug 21); Rust arrayref crate linked to North Korean actors delivering infostealer at build time (Aug 21).
- CareCloud data breach confirmed at 3.7 million patient records — SSNs, medical records, bank details. SickKids hit again via third-party app, employee and applicant data stolen.
- CISA and FBI: Medusa ransomware has claimed 500+ critical infrastructure victims. NSA and FBI warn of AI-powered attacks against Siemens PLCs.
- Microsoft Defender's btr.sys boot driver can be weaponized to terminate endpoint security software at boot — no CVE assigned, no patch, active research ongoing.
Seventeen items from Aug 17–23. Seven require immediate action.
Entra ID CVE-2026-69836 — CVSS 10, KEV, active exploitation
Patch now. Microsoft added CVE-2026-69836 to CISA’s Known Exploited Vulnerabilities catalog on August 21. CVSS: 10.0. Vulnerability class: deserialization of untrusted data enabling remote code execution. Exploitation confirmed active prior to KEV listing.
Confidence breakdown:
- Confirmed: CVE assigned, CVSS 10.0 confirmed by Microsoft MSRC advisory, KEV listing confirmed Aug 21.
- Confirmed: Active exploitation in the wild prior to KEV addition.
- Unknown: Full scale of exploitation campaign, targeting pattern, attacker attribution.
FCEB agencies: patch deadline applies. Everyone else: this is CVSS 10.0 on a widely deployed identity platform. There is no reason to delay. Full coverage: Entra ID CVE-2026-69836: CVSS 10, Exploited, KEV.
Citrix NetScaler — CVE-2026-19490, critical auth bypass
Patch now. Citrix patched a critical authentication bypass in NetScaler ADC and NetScaler Gateway on August 20. Rapid7 assessed exploitation as imminent at the time of patching given the flaw’s attack profile: unauthenticated access to protected admin functions. No public PoC confirmed at time of original reporting.
Confidence breakdown:
- Confirmed: Vulnerability and patch confirmed by Citrix and Rapid7 analysis.
- Unconfirmed: Active exploitation in the wild as of Aug 20 reporting. Treat as exploited — these devices are high-value targets and patch windows on Citrix vulnerabilities historically collapse fast.
If your NetScaler ADC or Gateway is internet-accessible, this is today’s first action. Full coverage: Citrix Patches Critical NetScaler Auth Bypass.
Zimbra CVE-2026-73570 — OS command injection, actively exploited, KEV
Exploited. CISA added CVE-2026-73570 — an OS command injection vulnerability in Zimbra Collaboration Suite — to the KEV catalog on August 21. Active exploitation in the wild confirmed by BleepingComputer on August 20. The flaw enables full takeover of Zimbra deployments.
Confidence:
- Confirmed: Exploitation active, KEV listed, patch available (Zimbra 10.1.20 per vendor blog).
- Confirmed: CISA KEV addition Aug 21.
Patch is available and has been since July. Running unpatched past this point is not an oversight, it’s a decision. Full coverage: Zimbra SNMP RCE Now Exploited in the Wild.
Supply-chain attacks — two in four days
RedC2 4.0 in npm (Aug 21)
Fourteen trojanized npm packages delivering the RedC2 4.0 Linux backdoor. Distinguishing feature: AI-assisted command-and-control infrastructure, reportedly using LLM-generated evasion logic. Affected packages had varying download counts; full dependency scope in enterprise pipelines requires audit against the disclosed package list.
Confidence: The Hacker News report confirmed; full attacker attribution and campaign scope ongoing. Full coverage: AI-Powered RedC2 Backdoor Hidden in 14 npm Packages.
Rust arrayref crate — North Korean nexus (Aug 21)
A compromised Rust crate delivered infostealer payloads at build time to projects consuming the tainted version. SecurityWeek reported North Korean actor attribution, confidence medium-high pending further disclosure. If your Rust build pipeline ingested the affected arrayref version in the disclosed window, treat the build environment and its secrets as compromised.
Confidence: Supply-chain compromise confirmed; North Korean attribution reported by SecurityWeek, not yet independently confirmed. Full coverage: Backdoored Rust Crates Delivered Infostealer at Build Time.
CareCloud — 3.7 million patient records
Confirmed. CareCloud disclosed that a breach of its electronic health records platform exposed data belonging to 3.7 million individuals. Data types confirmed: SSNs, medical records, bank details. Third-party app vector confirmed. No ransomware claim attached to this breach as of this writing.
Healthcare organizations relying on CareCloud for EHR should contact the vendor directly for scope clarification specific to their deployment. Confidence: Breach and victim count confirmed via BleepingComputer and The Record reporting from CareCloud notification filings. Full coverage: CareCloud Breach Hits 3.7M Healthcare Records.
SickKids — second breach in two years
The Hospital for Sick Children in Toronto confirmed a data breach affecting employee and job applicant information. Attacker accessed data via a third-party application. BleepingComputer and The Record confirmed the incident on August 21. Patient health records are stated as not involved in this incident. Confidence: Hospital-confirmed. Full coverage: SickKids Hit Again: Data Theft via Third-Party App.
Medusa ransomware — CISA/FBI: 500+ victims
CISA and the FBI released a joint advisory confirming Medusa ransomware has claimed over 500 critical infrastructure victims. Healthcare, education, and government sectors named. Double-extortion model: data encrypted and exfiltrated, with ransom demands for both decryption and non-publication. No new CVE tied to the advisory — Medusa operators use known-exploited vulnerabilities for initial access.
Confidence: CISA/FBI advisory confirmed. The count (500+) is the floor, not the ceiling. Full coverage: CISA, FBI: Medusa Ransomware Has 500+ Victims.
Microsoft Defender btr.sys — kill switch at boot, no patch
Unpatched. Researchers disclosed that Microsoft Defender’s own boot driver (btr.sys) can be weaponized by a local attacker to terminate endpoint security software during the boot sequence, before it can protect itself. No CVE assigned. Microsoft acknowledged the research; no ship date for a fix as of this writing.
No patch. No reliable workaround beyond monitoring for unauthorized boot-time process termination. This is an architectural issue, not a simple bug — the resolution timeline is uncertain. Confidence: Researcher and Microsoft acknowledgment confirmed; patch timeline unknown. Full coverage: Defender’s Own Boot Driver Can Kill Security Software.
Russian clusters — OAuth flows, WhatsApp hijacking
Russian-attributed clusters (UNC-tracked) exploiting OAuth device-code flows to hijack Microsoft 365 and WhatsApp accounts. Initial access via phishing pages replicating legitimate OAuth consent flows; victim grants access thinking they’re approving a legitimate app. Token-based persistence survives password resets.
Confidence: Campaign confirmed by security researchers; Russian attribution at medium-high confidence per source reporting. Full coverage: Russian Clusters Exploit OAuth Flows to Hijack Accounts.
NSA and FBI — AI-powered attacks on Siemens PLCs
NSA and FBI issued a joint advisory warning that threat actors are using AI-generated tools in attacks against Siemens Programmable Logic Controllers in US critical infrastructure sectors. This is the first major joint advisory explicitly naming AI-assisted tooling as a novel attack-enablement factor in OT targeting.
Confidence: Advisory confirmed. Specific CVEs or exploitation chains tied to the AI tooling not fully disclosed in the advisory. Full coverage: NSA, FBI Warn of AI-Powered Attacks on Siemens PLCs.
Also this week
- Forminator WordPress CVE-2026-15748 (Aug 17): Unauthenticated RCE via malicious PHP file upload in the Forminator plugin, installed on 600,000+ sites. Update to a patched version immediately. No active exploitation confirmed at time of disclosure but a public exploit path exists. Full coverage: Forminator WordPress Plugin RCE Flaw Hits 600K Sites.
- Windows Task Host — KEV, ransomware (Aug 18): CISA added the Windows Task Host vulnerability to KEV after ransomware gangs confirmed active exploitation. Full coverage: CISA: Ransomware Gangs Now Exploit Windows Task Host Flaw.
- MLflow SSRF + FUXA KEV (Aug 18–19): MLflow server-side request forgery CVE-2026-64849 added to KEV with active exploitation confirmed for cloud credential theft. FUXA industrial SCADA auth bypass also actively exploited. Full coverage: MLflow SSRF, FUXA Auth Flaws Actively Exploited.
- Apple patches — twice (Aug 17, Aug 19): Apple patched 108 flaws in iOS, iPadOS, and macOS on Aug 17, then issued a follow-on round addressing WebKit vulnerabilities and an actively exploited macOS screen-sharing flaw on Aug 19. Both rounds warrant immediate update. Full coverage: Apple Patches 108 Flaws in iOS, iPadOS and macOS 26 and Apple Patches 27 Flaws in iOS, iPadOS, and macOS Tahoe.
- GitLab CVE-2026-19478 (Aug 17, exploited Aug 21): Critical GraphQL flaw enabling unauthenticated deletion of public projects. Exploitation confirmed within days of disclosure. Full coverage: Critical GitLab Flaw Lets Attackers Delete Projects.
- TWINLOOT — SharePoint/Teams C2 (Aug 18): Threat actor operating C2 infrastructure entirely from Microsoft SharePoint and Teams. Legitimate cloud services as attack infrastructure; hard to block without disrupting business workflows. Full coverage: TWINLOOT Hides C2 Inside Microsoft SharePoint.
- Clop Windchill webshell (Aug 18): Clop-linked actors deployed a credential-harvesting webshell against PTC Windchill engineering data management systems. 40+ victims named. Full coverage: Clop’s Windchill Implant Decrypts Passwords, Steals Files.
- Ransomware affiliate posing as recovery firm (Aug 19): A rogue Medusa affiliate is operating a fake ransomware recovery service (“Ransom Busters”) — approaching victims and pocketing ransom payments. Confidence: BleepingComputer confirmed. Full coverage: Ransomware Affiliate Poses as Data Recovery Service.
- Android car head units — proxy botnet (Aug 22): Infotainment units in Android-based car systems compromised via supply-chain attack in built-in updaters. Units enrolled in a proxy botnet and ad-fraud scheme. Full coverage: Car Infotainment Units Hijacked via Supply-Chain Attack.
- Snowflake GitHub Actions injection (Aug 17): Workflow injection in Snowflake’s .NET repository — attacker-controlled GitHub issue content executing in CI context. Full coverage: GitHub Actions Injection Found in Snowflake .NET Repo.
What to watch
- Entra ID CVE-2026-69836 exploitation scope. This is CVSS 10 on a broadly deployed identity platform with confirmed active exploitation. The attack surface is wide. Watch for threat actor TTPs and victim sector disclosures.
- Citrix NetScaler CVE-2026-19490 exploitation confirmation. Rapid7 flagged imminent exploitation — the confirmation window is short. KEV listing likely if exploitation is observed.
- RedC2 npm campaign expansion. AI-assisted C2 infrastructure in a supply-chain attack is a novel combination. Attribution and full package list disclosure both pending. Audit your npm dependency tree.
- Rust supply chain — North Korea attribution. SecurityWeek reported North Korean nexus. Confirmation from a government advisory or second research team is the next signal. The threat actor pattern (supply-chain for build-time credential theft) is consistent with prior DPRK campaigns.
- Defender btr.sys patch timeline. No CVE, no ship date. Microsoft acknowledged the research. Watch MSRC for a security advisory — that is the earliest signal a patch is coming.
— airgap
- BleepingComputer — Microsoft warns of max severity Entra ID flaw exploited in attacks
- Rapid7 — CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
- BleepingComputer — Critical Zimbra RCE flaw now actively exploited in attacks
- The Hacker News — 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
- SecurityWeek — Rust Supply Chain Attack Linked to North Korean Hackers
- BleepingComputer — Healthtech firm CareCloud data breach impacts 3.7 million patients
- BleepingComputer — CISA: Medusa ransomware hit over 500 critical infrastructure orgs
- The Hacker News — Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot