Salesforce gave every org the same free scanner. Attackers already know what it misses.
A defense every attacker can rehearse against isn't a defense. It's a false sense of security.
Microsoft disclosed a maximum-severity remote code execution vulnerability in Entra ID (CVE-2026-69836, CVSS 10.0) caused by unsafe deserialization, then reversed its advisory's "Exploited: Yes" designation to "No" without explanation a day later, leaving enterprises uncertain whether active attacks occurred. The company server-side patched the flaw affecting its cloud identity platform that underpins Microsoft 365, Azure, and thousands of federated applications, but declined to disclose detection methods, scope of exposure, or evidence supporting either exploitation claim. The reversal raises questions about transparency in vulnerability reporting, particularly for cloud services where only the provider holds forensic facts needed to assess materiality under emerging SEC and CISA disclosure frameworks.
Read full article at The Cyber Express ↗A defense every attacker can rehearse against isn't a defense. It's a false sense of security.
New research shows how attacks against some unprotected TSN protocols could allow attackers to disrupt or manipulate physical processes
Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
Microsoft has confirmed a maximum severity remote-code execution vulnerability in Entra ID that is being actively exploited in the wild. The company states the flaw has been fully mitigated and requires no further action from customers.