Microsoft disclosed on Thursday that a maximum-severity remote code execution vulnerability in Entra ID, the identity service underpinning Microsoft 365, Azure and Dynamics 365, was exploited in the wild before the company mitigated it on its own infrastructure. The flaw, tracked as CVE-2026-69836 and rated CVSS 10.0, required no authentication and no user interaction. Entra ID, formerly Azure…
This weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. The latest developments also show that…
Every enterprise wants the upside of AI — faster workflows, sharper decisions, leaner teams. Far fewer have asked the harder question: what happens when the same systems delivering that upside are also quietly rewriting who, or what, has access to the crown jewels? Autonomous agents are now reading contracts, touching customer data, writing production code, and triggering workflows once reserved…
Oz Hair and Beauty has confirmed that customers’ personal information was accessed during a data breach after an unauthorized third party briefly gained access to the company’s online purchase and order platform. The company described the Oz Hair and Beauty data breach as a cybersecurity incident and said its investigation found that limited personal information connected to purchases made before…
UT San Antonio cyber incident response efforts have prompted the university to delay the start of fall classes by three days, with the semester now scheduled to begin Monday, August 24. The university said the decision will give its teams additional time to restore technology systems and services following attempted unauthorized activity against its academic campus. The activity was detected over…
GitLab has patched two security flaws, including CVE-2026-19478, a critical code injection vulnerability that could allow unauthenticated attackers to remotely modify or delete public projects and user data. The disclosure adds to the growing list of GitLab vulnerabilities requiring prompt attention from organizations running self-managed instances. GitLab has released versions 19.2.4, 19.1.6,…
A suspected ARMA cyberattack has targeted Ukraine's Asset Recovery and Management Agency as it prepares to select a manager for assets linked to IDS Ukraine. ARMA said its servers experienced unauthorized interference ahead of the August 22 deadline for applications, prompting an investigation into whether the incident was part of a broader effort to disrupt its operations. The Asset Recovery and…
A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging to France's Directorate General of Public Finances. The French Public Finances Directorate said investigations found that data linked to 678,000 individuals and professionals had been consulted and extracted during intrusions in June and July 2026.…
Recent AI security incidents involving model evaluations have raised questions about how securely frontier AI models are tested before deployment. Cybersecurity-focused AI company Irregular said an investigation into a publicly reported incident found that models in a small number of evaluation runs gained unintended internet access and carried out offensive security actions against real-world…
This weekly roundup highlights the expanding range of threats facing businesses, technology platforms, and individuals. From social engineering attacks against corporate systems and vulnerabilities uncovered by AI agents to large-scale software patches and cyberattacks disrupting logistics operations, recent incidents demonstrate how quickly the threat landscape is evolving. The latest…
As enterprises race to bolt AI onto every business process, security leaders are being forced to answer a harder question than "should we adopt it" — it's "who's accountable when it goes wrong." To unpack this, The Cyber Express sat down with Harsha Reddy , Head of Information Security at Veterinary Emergency Group ( VEG ). With nearly two decades in security leadership — including senior roles at…
A CEVA Logistics cyberattack disrupted parts of the company's European operations on July 29, halting shipments at eight affected warehouses and exposing customer data tied to several major clients. CEVA Logistics, which operates in more than 170 countries, is part of the CMA CGM Group, one of the world's largest shipping and logistics conglomerates. On August 1, CEVA notified affected customers…