Tuesday, August 18, 2026
Daily digest
Today's flow is dominated by active-exploitation warnings on core infrastructure — CISA added two more KEV entries (Ray, Windows Task Host) while a threat actor is selling 3.6 million records allegedly pulled from Azure tenants via compromised credentials.
CISA Adds Actively Exploited Ray Framework Flaw to KEV Catalog
CISA added a critical vulnerability in the Ray distributed computing framework to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation that can trigger browser-based RCE. Ray is a popular open-source Python framework used to scale AI/ML workloads.
Why it matters: If Ray underpins any part of your self-hosted AI stack, this requires immediate patching per BOD 22-01 timelines under CMMC L2 vulnerability management requirements.
CISA Confirms Ransomware Gangs Exploiting Windows Task Host Flaw
CISA confirmed that ransomware operators are actively exploiting a high-severity Windows Task Host vulnerability that was first flagged as exploited back in April. The flaw affects Windows systems and has now been tied directly to ransomware deployment.
Why it matters: Directly affects Intune-managed Windows 11 endpoints — verify patch deployment status across the fleet and confirm this CVE is closed in your POA&M if not yet remediated.
Hacker Claims 3.6 Million Azure Account Records Stolen from Fortune 500 Companies
A threat actor is selling employee databases allegedly stolen from Microsoft Azure infrastructure belonging to multiple Fortune 500 companies, including McDonald's, Vodafone, TCS, and Kyndryl. Researchers say the access was gained using compromised credentials rather than an Azure platform vulnerability.
Why it matters: A credential-based Azure compromise campaign at this scale is a strong reminder to audit conditional access, MFA enforcement, and privileged account hygiene in your GCC High/Azure AD tenant.
Certighost Flaw Lets Standard Domain User Escalate to Domain Controller via AD CS
CVE-2026-54121 allows a standard domain user to turn an Enterprise Certificate Authority into a Domain Controller through Active Directory Certificate Services. A patch is available, but researchers note the underlying issue is standing privilege and implicit trust in PKI infrastructure.
Why it matters: If you run an on-prem or hybrid AD CS deployment tied to your Nutanix AHV or Windows environment, this is a Tier 0 identity risk — patch immediately and review CA permissions as part of NIST 800-171 access control controls.
Critical GitLab GraphQL Flaw Allows Unauthenticated Deletion of Public Projects
GitLab patched a critical vulnerability (CVE-2026-19478, CVSS 9.4) in Community and Enterprise Edition that could let unauthenticated attackers remotely modify or delete public projects and user data via GraphQL. GitLab has released security updates addressing the flaw.
Why it matters: If GitLab is part of your Ansible/CI pipeline for infrastructure automation, patch immediately — an unauthenticated wipe of pipeline or IaC repos would be a serious availability and integrity incident under CMMC L2.
Snowflake GitHub Actions Workflow Vulnerable to Command Injection via Crafted Issues
Wiz researchers disclosed a GitHub Actions workflow injection vulnerability in Snowflake's snowflake-connector-net repository that could be exploited through a crafted GitHub issue to execute commands and access internal Jira credentials. The flaw existed in a workflow file that ran automatically on issue creation.
Why it matters: A useful reminder to audit your own GitHub Actions/Ansible CI workflows for untrusted-input triggers if you maintain open or semi-public repos as part of automation pipelines.
Apple Patches 108 Vulnerabilities in iOS 26/18 and macOS 26
Apple released updates for iOS/iPadOS (26 and 18) and macOS 26 fixing 108 vulnerabilities, roughly two weeks after a smaller macOS update addressing a screen-sharing flaw. The new update does not affect iOS/iPadOS with the previously patched screen-sharing issue.
Why it matters: Push these updates through Intune's Apple device management policies promptly given the scale of the patch — 108 CVEs is a large attack-surface reduction for any managed iOS/macOS devices in scope.
Windows Server 2022 Reaches End of Mainstream Support in 60 Days
Microsoft reminded IT administrators that Windows Server 2022 will reach its mainstream end-of-support date in October 2026, after which it moves to extended support. Extended support typically limits free updates to security fixes only.
Why it matters: Inventory any Windows Server 2022 instances (including Nutanix AHV VMs) now and plan upgrade paths — CMMC L2 requires documented lifecycle management for unsupported/soon-to-be-limited-support systems.
Xen Project Pursues Formal Safety Certification for Embedded Use
The Xen Project is working toward compliance with formal safety standards, with AMD and Renesas leading the effort and Boeing joining as a contributor. The push targets safety-critical partitioning use cases such as embedded and robotics systems.
CMMC Works, Now Let's Sharpen It — Commentary Calls for Holding the Standard Firm
A NextGov commentary argues that CMMC's current framework is functioning as intended and that the DFARS requirements behind it should not be loosened, despite calls from some in industry to relax standards. The piece frames this as a critical moment for the program's credibility.
Why it matters: Signals continued regulatory pressure to maintain strict CMMC L2 compliance rather than expect relaxed requirements — plan assessments and POA&Ms accordingly rather than anticipating leniency.
Microsoft Begins Removing WMIC Tool from Windows 11
Microsoft has removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from this week's beta builds. WMIC has long been abused as a living-off-the-land binary by attackers for reconnaissance and lateral movement.
Why it matters: Review any Ansible playbooks, scripts, or legacy tooling in your Intune-managed fleet that still depend on WMIC — those will break once this rolls to production builds.
GE and Philips Investigating Clop Ransomware Data Theft Claims
General Electric and Philips confirmed they are investigating claims by the Clop ransomware gang that it breached their systems and stole data. Both companies have not yet confirmed the scope or validity of the stolen data claims.