~/greenteam/nerd

Tuesday, August 25, 2026

Daily digest

CISA added a maximum-severity, actively-exploited Oracle WebLogic/HTTP Server flaw to its KEV catalog — patch immediately if any Oracle middleware sits in your environment.

cybersec The Hacker News

CISA Adds Maximum-Severity Oracle WebLogic Flaw to KEV Catalog Amid Active Exploitation

CISA added CVE-2026-21962 (CVSS 10.0), a flaw in Oracle HTTP Server and Oracle WebLogic Server, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The bug allows an unauthenticated attacker with network access via HTTP to access critical data without credentials.

Why it matters: Under CMMC L2/NIST 800-171, KEV-listed vulnerabilities carry remediation timelines for federal contractors — inventory any Oracle middleware in your environment and patch or isolate it now.

cybersec The Hacker News

Critical Keycloak Password Reset Flaw Allows Unauthenticated Account Takeover

Red Hat and the Keycloak project patched CVE-2026-18963 (CVSS 9.1), a critical flaw in the open-source IAM server that let an unauthenticated remote attacker take over any user account by forcing a password reset. Patches are now available for affected Keycloak deployments.

Why it matters: If Keycloak underpins any SSO/federation into your M365 GCC High or AWS GovCloud environment, this is a full account-takeover risk that requires immediate patching.

cybersec The Hacker News

Mirage2FA Phishing Kit Hits 4,500 Companies, Bypassing Microsoft 365 MFA

The Mirage2FA phishing-as-a-service toolkit has run from 2024 through 2026, targeting Microsoft 365 accounts by abusing legitimate login flows to bypass two-factor authentication. ANY.RUN research found 48% of targeted email addresses were potentially compromised, with most affected organizations based in the US.

Why it matters: This directly targets M365 login flows — verify Conditional Access policies and phishing-resistant MFA (FIDO2/passkeys) are enforced tenant-wide in GCC High to blunt AiTM-style bypasses.

cybersec BleepingComputer

Over 270 Zimbra Servers Compromised in Ongoing RCE Attacks

Threat actors have compromised more than 270 Zimbra Collaboration Suite instances by exploiting a high-severity remote code execution vulnerability. The attacks are ongoing and actively tracked by researchers.

cybersec BleepingComputer

Microsoft Teams Adds Admin Control to Block External Bots from Meetings

Microsoft is rolling out a new Teams meeting protection policy that lets administrators automatically block all identified external bots from joining meetings. The feature is being deployed as part of ongoing Teams meeting security controls.

Why it matters: Worth enabling in GCC High Teams admin center to reduce risk from AI notetaker/bot-based data exfiltration during sensitive meetings.

infrastructure BleepingComputer

August .NET Framework Updates Break Printing and PDF Export in WPF Apps

Microsoft confirmed that .NET Framework updates shipped in the August 2026 Patch Tuesday are breaking printing and PDF export functionality in WPF applications. Microsoft has not yet issued a fix.

Why it matters: If line-of-business WPF apps are deployed to your Intune-managed Windows 11 fleet, hold or test this month's cumulative update before broad ring deployment.

infrastructure Red Hat Blog

Red Hat Hardened Images Now Supported in AWS InspectorScan API and ECR Basic Scanning

Red Hat Hardened container images are now supported for vulnerability scanning through AWS InspectorScan API and Amazon ECR Basic scanning. The integration aims to reduce CVE noise from unnecessary packages bundled into traditional base images.

Why it matters: Relevant for reducing container CVE remediation overhead if you're running hardened images in AWS GovCloud ECR pipelines feeding CMMC-scoped workloads.

cmmc Federal News Network

GSA and Treasury Launch Post-Quantum Cryptography Initiatives

GSA is updating its Federal Identity, Credential and Access Management (FICAM) architecture and expanding physical security testing to support a government-wide migration to post-quantum cryptography. Treasury separately launched a task force focused on moving the financial sector to quantum-resistant technology.

Why it matters: Federal PQC migration timelines will eventually cascade into CMMC/NIST 800-171 crypto requirements — start tracking vendor PQC roadmaps for M365 GCC High and AWS GovCloud now.

cmmc Federal News Network

Lawmakers Demand Investigation into CISA Workforce Cuts Amid Rising Threats

Members of Congress are calling for an investigation into staffing reductions at CISA, citing concerns that the cuts come as cyber threats to critical infrastructure and federal systems increase. CISA has also seen significant leadership turnover under the current administration.

Why it matters: Reduced CISA capacity may slow advisory publication and KEV catalog updates that CMMC-scoped contractors rely on for vulnerability remediation timelines.

cybersec The Record

US Sanctions Iranian Cyber Actors as UK Discloses Power Plant Intrusion

The US Treasury sanctioned several Iranian nationals for cyberattacks on critical infrastructure, coming days after reports surfaced of a cyber intrusion at a small power plant in the United Kingdom. The disclosures highlight continued state-sponsored targeting of critical infrastructure operators.

cybersec The Record

Large DDoS Attack Takes Norwegian Public Services Offline

The Norwegian Digitalisation Agency confirmed a distributed denial-of-service attack disrupted government services, with staff working alongside an IT partner to gradually restore systems. Some services remain affected as recovery continues.