~/greenteam/nerd

Thursday, August 20, 2026

Daily digest

Today is dominated by active-exploitation warnings — CISA KEV additions (macOS/SharePoint/vCenter/Microsoft IKE), MLflow, Citrix NetScaler, and Zimbra all have confirmed in-the-wild attacks. Prioritize patching cycles this week.

cybersec The Hacker News

CISA Adds Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws to KEV Catalog

CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation, including CVE-2026-65400 (CVSS 9.8) in Apple macOS involving improper authentication, along with flaws in SharePoint, vCenter, and Microsoft's IKE implementation.

Why it matters: Federal agencies and CMMC-scoped contractors must remediate KEV entries on CISA's mandated timeline; the IKE and SharePoint flaws directly touch common M365/GCC High and Windows networking infrastructure.

cybersec BleepingComputer

CISA Warns of Active Exploitation of Critical MLflow Vulnerability

CISA alerted federal agencies that threat actors are actively exploiting a critical vulnerability in MLflow, the open-source machine learning lifecycle platform. The agency added the flaw to its Known Exploited Vulnerabilities catalog.

Why it matters: If MLflow is used anywhere in your self-hosted AI/ML pipeline, this needs immediate patching or isolation — it's now confirmed under active attack, not just theoretical risk.

cybersec BleepingComputer

Citrix Urges Immediate Patching of New NetScaler Vulnerabilities

Citrix issued an urgent advisory for two new vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances, urging customers to patch immediately.

Why it matters: NetScaler devices are a common remote-access edge point in CMMC L2 environments; unpatched instances are a frequent initial-access vector for ransomware crews and a likely audit finding.

cybersec BleepingComputer

Critical Zimbra RCE Flaw Now Actively Exploited

CERT Polska warned that attackers have begun exploiting a critical remote code execution vulnerability in Zimbra Collaboration Suite (ZCS) in live attacks.

cybersec Cisco Talos

UAT-10147 Deploys SPECTRE Implant with Linux Rootkit and BYOVD Capabilities

Cisco Talos identified a new cross-platform implant called SPECTRE tied to threat actor UAT-10147, featuring cross-platform C2, process injection, credential theft, anti-analysis protections, and kernel-level EDR bypass via BYOVD techniques.

Why it matters: BYOVD-based EDR bypass on Linux is relevant to hardened server fleets and Nutanix AHV host security; ensure driver allow-listing and kernel integrity controls are current.

cybersec The Record

NSA, FBI Warn of AI-Generated Tools Used to Attack Critical Infrastructure PLCs

The NSA, FBI, and other federal agencies issued a joint advisory warning that a hacking campaign targeting Siemens S7 Series PLCs is using AI-assisted development alongside known vulnerability exploitation, calling it 'not a theoretical risk.'

cmmc Federal News Network

CMMC Review: DoD's Inconsistent CUI Marking Continues to Plague Program

A review of the CMMC program found that the Defense Department's inconsistent identification and marking of Controlled Unclassified Information (CUI) remains a persistent problem cited by most organizations involved.

Why it matters: Ambiguous CUI marking from DoD contracting offices directly complicates your scoping and boundary decisions for CMMC L2 assessments — document your interpretation and rationale for any ambiguous data flows.

cmmc DefenseScoop

Army Cyber Chief Reveals AI Task Force Building Agents to Hunt on DOD Networks

Lt. Gen. Christopher Eubank disclosed that Army Cyber Command has stood up a task force developing AI agents for network defense hunting operations, with humans currently retaining all risk-acceptance decisions rather than delegating to agents.

infrastructure The Register

Microsoft Ends One of the Last Ways to Buy VMware Without Big Bundles

Microsoft is discontinuing a licensing path that allowed Azure customers to purchase VMware software outside Broadcom's larger VMware Cloud Foundation (VCF) bundles, aligning with Broadcom's VCF-or-nothing licensing push.

Why it matters: If any workloads still run on VMware alongside your Nutanix AHV environment, licensing costs and options are narrowing further — worth revisiting migration timelines off VMware.

infrastructure AWS Security Blog

AWS Publishes Guidance on Propagating User Authorization Context in Bedrock AgentCore

AWS Security Blog detailed a method for propagating user authorization context into AI agents built on Amazon Bedrock AgentCore, addressing the risk that agents pulling from DynamoDB, document repos, and internal knowledge bases may return data a user isn't authorized to see.

Why it matters: Relevant guidance if building agentic AI workflows in AWS GovCloud — enforcing per-user authorization context in agent pipelines is a practical control for NIST 800-171 access-control requirements.

infrastructure SANS ISC

Using Microsoft Graph and PowerShell to Find Stale Accounts and Licenses

A SANS ISC diary walked through using Microsoft Graph API (v2.3.9) with PowerShell to audit Microsoft 365 tenants for stale accounts and unused license assignments, noting that many admins and commercial tools still haven't adopted Graph over older APIs.

Why it matters: Practical technique for M365 GCC High tenant hygiene — stale accounts are a common CMMC assessment finding under access-control requirements (AC.L2-3.1.1/3.1.2).

cybersec The Record

CareCloud Data Breach Impacts 3.7 Million Patients

Electronic health record vendor CareCloud disclosed to HHS that 3,756,469 individuals had information exposed after a hacker spent eight hours inside one of the company's EHR environments.