CVE-2026-54121 enables a standard domain user to escalate privileges by exploiting an Enterprise Certificate Authority to become a Domain Controller, exposing risks in PKI infrastructure trust models.
A threat actor is selling employee databases stolen from Microsoft Azure infrastructure of multiple Fortune 500 companies using compromised credentials, exposing sensitive account records and presenting an enterprise security risk.
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud patched just three days ago is now actively exploited, posing a critical security risk.
Microsoft's August 2026 Patch Tuesday addresses 400 security flaws, including one actively exploited zero-day and two publicly disclosed zero-day vulnerabilities.
The ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young obtained through a supply-chain attack involving stolen system credentials.