top of page

The Security Brief


A CVSS 10.0 Flaw in Entra ID, and Nothing for Customers to Patch
Microsoft disclosed a remote code execution flaw in Entra ID on 20 August carrying a CVSS score of 10.0, the highest the scale allows. By the time the advisory went live, the fix was already deployed and there was nothing for customers to install. Maximum severity paired with zero customer action is an unusual combination, and it is worth sitting with rather than filing away. What Happened The vulnerability, tracked as CVE-2026-69836, is a deserialization of untrusted data is
3 days ago3 min read


AI-Generated Exploit Scripts Are Now Aimed at PLCs. Australian OT Owners Should Look Hard at Their Exposure
Five US federal agencies issued a joint advisory this week about an active threat to critical infrastructure operators. No new zero-day is involved. Attackers are using AI to write exploit scripts against Siemens S7 programmable logic controllers that have been sitting on the public internet for years, running software nobody has updated. What Happened The advisory, AA26-231A, was published on Wednesday by the NSA, CISA, the FBI, the Department of Energy and the Environmental
5 days ago3 min read


Five Days: How Fast Attackers Turned the vCenter Advisory Into a Campaign
Broadcom disclosed a critical flaw in VMware vCenter on 29 July. By 3 August, a suspected state-backed group was already using it to plant backdoors on internet-facing servers. Five days was the entire patching window, and hundreds of organisations across 47 countries did not make it. What Happened CVE-2026-59310 is a directory traversal vulnerability in the vCenter Syslog server, rated 9.8 on the CVSS scale. An attacker with network access to vCenter can manipulate file path
Aug 143 min read
bottom of page