Wednesday , August 19 2026

International

Azure CLI Password Spray Impacts 78 Microsoft Accounts in 81M+ Attempts

CLI

Cybersecurity researchers have warned of a “massive, ongoing, automated password spray attack” aimed at Microsoft’s Azure command-line interface (CLI), compromising dozens of accounts in the process. According to Huntress, the activity comes from an IPv6 address range (2a0a:d683::/32) managed by the internet provider LSHIY LLC (AS32167). “Between June 12 and …

Read More »

Linux Unveils New Open Source Security Project “Akrites” For (OSS) Ecosystem

linux

The Linux Foundation said on Thursday that they are starting a new project to fix flaws in open source software (OSS) more effectively. Akrites sets up a shared Security Incident Response Team (SIRT) to work together on finding, fixing, and sharing OSS security problems. If it sounds familiar, it should. Less …

Read More »

Hackers Target Cloudflare-Hosted AWS Domains to Steal Console Logins

Cloudflare

A complex phishing attack targets AWS console users by misusing Cloudflare-hosted websites to steal login details. Each domain had a nearly identical copy of the AWS login page. It used a server-driven process that switched to email, SMS, or authenticator-app MFA challenges, allowing for real-time collection of second factors. The phishing …

Read More »

CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

FortiGate

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) asked Fortinet users with FortiGate devices on Thursday to act to protect against harmful attacks on many internet-connected devices. The large campaign, thought to be done by Russian-speaking hackers, is called FortiBleed. There are 86,644 targeted devices as of June 19, 2026. …

Read More »

Critical Splunk Enterprise Pre-Auth RCE Chain Exposes Databases With Zero Authentication

Splunk Enterprise

A serious pre-authentication remote code execution (RCE) flaw in Splunk Enterprise has been revealed, earning a very high CVSS score of 9.8. Tracked as CVE-2026-20253, Splunk shared the flaw on June 10, 2026. It impacts the PostgreSQL Sidecar Service that came with Splunk version 10. The root cause of CVE-2026-20253 lies …

Read More »