DJBSEC's CyberNews 2026-08-21

Today’s daily news covers the following categories: Vulnerability Authentication Policy & Legislation Phishing Threat Intelligence Data Breach Ransomware


Windows Defender Update Causes Virus Scans to Crash

Vulnerability

A recent Microsoft Defender security intelligence update caused Quick, Full, and Offline malware scans to fail on some Windows systems, with the antimalware process crashing inside the mpengine.dll component. The timing raised speculation that the problem could be connected to changes made in response to the recently disclosed ShieldBreak Defender zero-day, although Microsoft has not confirmed any connection. Reports indicate the issue affected both clean Windows installations and managed enterprise endpoints, while some manual file scans continued to work normally. Updated Security Intelligence packages, including versions 1.457.236.0 and newer, restored scanning functionality for many affected systems. Administrators should ensure Defender is fully updated and verify that scans actually complete successfully rather than relying solely on the installed version number.

Read More

Password Spraying Attacks Surge 155-Fold as Hackers Exploit MFA Gaps

Authentication

Huntress reports a 155-fold increase in password-spraying attacks during the first half of 2026, including a massive campaign targeting Microsoft’s Azure CLI authentication flow. In just two weeks during June, researchers observed more than 81 million login attempts and 78 successful account compromises associated with the campaign. Attackers abused the legacy Resource Owner Password Credentials, or ROPC, OAuth flow, which does not support modern MFA challenges and allowed valid username-and-password combinations to generate authenticated sessions. Many compromised organizations technically had MFA enabled, but their Conditional Access policies failed to cover the specific applications, users, or authentication methods attackers were abusing. Defenders are being urged to disable ROPC where possible, restrict Azure CLI access, eliminate Conditional Access exclusions, and require strong authentication across all users, applications, and client types.

Read More

Microsoft Ending Support for Windows 11 24H2 Home and Pro

Policy & Legislation

Microsoft is warning customers that Windows 11 version 24H2 Home and Pro editions will reach end of support on October 13, 2026. After that date, Home, Pro, Pro Education, and Pro for Workstations systems running 24H2 will stop receiving monthly security and quality updates, leaving them increasingly vulnerable to newly discovered threats. Microsoft recommends upgrading eligible devices to Windows 11 version 25H2, which remains supported for those editions until October 2027. Enterprise and Education editions of Windows 11 24H2 are not affected by the October deadline and will continue receiving updates for another year. IT teams should inventory affected systems now and test critical applications, drivers, EDR agents, VPN clients, and encryption tools before deploying the feature upgrade.

Read More

Critical Citrix NetScaler Flaw Allows Authentication Bypass

Vulnerability

Cloud Software Group disclosed two serious vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including a critical authentication-bypass flaw tracked as CVE-2026-19490. The vulnerability carries a CVSS score of 9.3 and can allow remote attackers to bypass authentication on vulnerable SSL VPN, ICA Proxy, CVPN, RDP Proxy, and AAA configurations without possessing valid credentials. A second vulnerability, CVE-2026-19489, involves a memory overflow that can trigger denial-of-service conditions when specific SIP ALG and Large Scale NAT configurations are enabled. Multiple NetScaler 13.1 and 14.1 releases are affected, while Cloud Software Group’s cloud-managed services have already been patched. Because these appliances frequently sit directly on the internet and protect enterprise remote access, administrators are being urged to install the updated NetScaler builds immediately.

Read More

Mirage2FA Lets Microsoft 365 Users Complete MFA Before Stealing Their Sessions

Phishing

A phishing-as-a-service platform called Mirage2FA is helping attackers hijack Microsoft 365 accounts without directly defeating multi-factor authentication. The adversary-in-the-middle toolkit proxies a victim’s credentials and MFA response to the legitimate Microsoft authentication service, then intercepts the authenticated session cookies returned after a successful login. Attackers can reuse those cookies to access Outlook mailboxes, SharePoint, OneDrive, and connected SSO applications without triggering another MFA challenge. Researchers identified 9,426 targeted accounts across 94 countries, with more than 4,500 addresses showing indicators of potential compromise and U.S. organizations accounting for nearly two-thirds of identified victims. The campaign demonstrates why traditional MFA alone is increasingly insufficient against sophisticated session-token theft and real-time phishing proxies.

Read More

Trusted Vendors Are Increasingly Becoming Enterprise Attack Paths

Threat Intelligence

Third-party suppliers are becoming increasingly attractive attack paths because compromised vendor accounts, legitimate domains, and familiar business workflows can make malicious activity appear trustworthy. Large U.S. and European enterprises may depend on hundreds of suppliers, dramatically expanding the number of accounts, files, links, and external relationships security teams must monitor. Modern supply-chain attacks can also use redirects, dynamically generated credential pages, and other techniques that may not reveal malicious behavior until after a user interacts with the content. The report argues that traditional static scanning and reputation-based trust are insufficient when an attacker is operating through a legitimate supplier’s infrastructure. Organizations should combine stronger vendor controls with behavioral analysis, threat intelligence, rapid investigation capabilities, and continuous reassessment of third-party access.

Read More

CareCloud Data Breach Impacts More Than 3.7 Million Patients

Data Breach

U.S. healthcare technology company CareCloud says a March cyberattack affected 3,756,469 individuals, making the incident one of the larger healthcare data breaches disclosed this year. An unauthorized third party accessed one of the company’s AWS environments between March 10 and March 16 and claimed to have exfiltrated information from databases stored there. The attack caused an approximately eight-hour disruption to CareCloud’s network and affected infrastructure containing patient information, although the company’s public notification does not fully detail the types of information exposed beyond names. CareCloud began notifying affected individuals in July and is offering identity-protection services to those impacted. No ransomware or data-extortion group had publicly claimed responsibility for the attack at the time of reporting.

Read More

Sakura Internet Hack Potentially Exposes 1.36 Million Accounts

Data Breach

Japanese cloud and data-center provider Sakura Internet disclosed that attackers gained access to a sales management system containing information associated with as many as 1,360,563 customer accounts. The intrusion was uncovered while the company was investigating a separate breach involving unauthorized access to 583 Sakura Rental Server accounts, where attackers also installed malware. Sakura says it has not confirmed that data from the larger sales system was actually exfiltrated, and stored passwords were hashed while credit-card information was not present in the compromised system. The company invalidated abused credentials, removed the malware, notified authorities, and began contacting potentially affected customers. Sakura has also confirmed that the incident was not ransomware-related and that no ransom demand was received.

Read More

Rogue Ransomware Affiliate Poses as Data Recovery Company to Steal Payments

Ransomware

Security researchers believe a ransomware affiliate calling itself Ransom Busters is posing as a data-recovery company and contacting victims of attacks that have not yet been publicly disclosed. The group claims it can obtain decryption keys and delete stolen information from ransomware servers belonging to operations such as DragonForce, Settra, and Anubis, charging victims between $20,000 and $60,000. GuidePoint Security found matching tools, backdoor credentials, hostnames, and tactics between Ransom Busters and the attackers responsible for multiple ransomware incidents, suggesting the supposed recovery service may actually be the affiliate that conducted the attacks. Researchers believe the affiliate may be attempting to bypass its ransomware-as-a-service partners and keep additional payments for itself. The scheme highlights growing distrust inside the ransomware ecosystem and creates another risk for victims, who may no longer know how many different criminal parties possess copies of their stolen data.

Read More




Enjoy Reading This Article?

Here are some more articles you might like to read next:

  • DJBSEC's CyberNews 2026-08-28
  • DJBSEC's CyberNews 2026-08-27
  • DJBSEC's CyberNews 2026-08-26
  • DJBSEC's CyberNews 2026-08-25
  • DJBSEC's CyberNews 2026-08-24