This day 02:02 06:02 10:02 14:02 18:03 22:03
Info  2026-08-08 02:02Z · last 4h · 1 findings · glm-5.2:cloud

Threat Brief — 2026-08-08 — Identity is the New Perimeter

Executive summary. Unit 42 published a deep-dive on identity-based attacks as the dominant SOC challenge, attributing roughly 90% of incidents to identity compromise. The piece frames identity as the modern "front door" for attackers and offers operational guidance for SOC leaders. This reinforces a pattern visible across this week's intelligence: M365 AitM phishing, Windows Hello for Business key abuse, and Entra ID persistence all point to identity as the primary battleground.

Top items

Themes

Identity as the primary attack surface. This week's intelligence has consistently shown identity-layer compromise as the critical path: active M365 AitM phishing targeting payroll and finance, malware abusing Windows Hello for Business keys for Entra ID persistence, and now Unit 42 quantifying identity-based attacks at 90% of incidents. Defenders should prioritise identity threat detection, conditional-access hardening, and token/credential monitoring over traditional network-perimeter controls.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db