UnifiedThreatHunting is a practical framework for building structured threat hunts instead of just running random SIEM queries.
It covers hypothesis driven hunting, telemetry validation, feasibility checks, MITRE ATT&CK mapping, hunt execution, detection handoff, documentation, and automation/AI.
Github:- https://t.co/rLAqigpA0c
⚠️ A CVSS 10.0 Entra ID flaw was exploited in the wild.
CVE-2026-69836 allows an unauthorized attacker to remotely execute code through unsafe deserialization.
Microsoft says the flaw is fully mitigated and no customer action is required. How attackers exploited it remains undisclosed.
Read more: https://t.co/31qY0Piy6u
A simple guided setup for emergency access accounts 😎
Recommend dev/test for now - includes setup of emergency access accounts, automated exclusion from CA policies, optional RMAU and alerting
azd init -t nathanmcnulty/azd-emergency-access && azd up
https://t.co/Ik485fs4J5
Microsoft is now bundling Intune Remote Help with M365 E3/E5, no more separate add-on needed for many orgs. Our step-by-step guide covers licensing, RBAC setup, app deployment & troubleshooting:
https://t.co/7b4Iiw9Lcg
#MSintune#RemoteHelp#Microsoft365
🚨 ثغرة حرجة في نواة WordPress تسمح بتنفيذ أوامر عن بُعد دون مصادقة, واستغلال نشط مؤكد خلال 24 ساعة من الإفصاح
سلسلة أُطلق عليها "wp2shell"، اكتشفتها شركة Searchlight Cyber عبر وحدة Assetnote، وأُفصح عنها في 17 يوليو 2026 عبر برنامج HackerOne الخاص بـ WordPress. التقييم CVSS 10.0.
🔹 التفاصيل التقنية:
• CVE-2026-63030, خلل route confusion في نقطة نهاية REST API المخصصة للطلبات المجمّعة (/wp-json/batch/v1). خلل في التحليل يُخرج مصفوفتين داخليتين عن التزامن، فيُنفَّذ طلب فرعي تحت معالج طلب آخر. أُدخل هذا الخلل في الإصدار 6.9
• CVE-2026-60137, حقن SQL في معامل author__not_in داخل الصنف WP_Query، وهو الصنف الذي تمر عبره غالبية استعلامات WordPress. موجود منذ الإصدار 6.8
• منفردةً، كل ثغرة محدودة الأثر. مسلسلةً، تنتهي بتنفيذ أوامر عن بُعد على تثبيت افتراضي دون حساب ودون إضافات ودون تفاعل من المستخدم
• بحسب تحليل Cloudflare، مسار الوصول إلى RCE متاح حين لا يكون persistent object cache مفعّلاً, وهو الوضع الافتراضي في أغلب التثبيتات.
🔹 الوضع الحالي:
• PoC عام متاح على GitHub منذ أيام
• Wiz Research رصدت استغلالاً فعلياً in the wild مع زرع webshells دائمة على خوادم مصابة
• WordPress.[org فعّلت التحديث التلقائي القسري نظراً لخطورة الثغرة
🔹 ما يجب فعله:
• التحقق من الإصدار فعلياً لا افتراض نجاح التحديث التلقائي، عبر wp core version أو من لوحة التحكم
• حصر كل تثبيتات WordPress في البيئة، بما فيها بيئات الاختبار والتطوير والمواقع المنسية
• لمن لا يستطيع الإصلاح فوراً: عليه حجب /wp-json/batch/v1 ومعامل rest_route=/batch/v1 على مستوى WAF كإجراء مؤقت لا كبديل
• مراجعة السجلات بحثاً عن طلبات POST إلى المسارين أعلاه، وفحص الخوادم بحثاً عن ملفات webshell مزروعة، من كان مكشوفاً بين 17 و20 يوليو يُفترض أنه استُهدف حتى يثبت العكس
🔎 هذه حالة تستحق الدراسة في تقييم المخاطر: ثغرتان تُصنَّفان منفردتين بخطورة متوسطة، تنتجان مسلسلتين أخطر نتيجة ممكنة في تطبيقات الويب. النظرة أحادية الثغرة كانت ستمرّ على كلتيهما دون إنذار.
🔎 نقطة تستحق الانتباه: Searchlight Cyber اكتشفت هذه السلسلة باستخدام نموذج لغوي (GPT-5.6 Sol). بعد أسبوع من حادثة استخدام نماذج في اختراق بنية Hugging Face، هذه هي الوجهة المقابلة للقدرة نفسها، والفارق ليس في النموذج بل في من يشغّله ولأي غرض.
🔎 بالنسبة لبيئات OT تحديداً: WordPress يعمل على عدد كبير من المواقع المؤسسية والبوابات التعريفية، وكثير منها مستضاف على شرائح شبكية قريبة من بيئات التشغيل أو متصلة بها. تثبيت منسي على خادم في DMZ هو مسار وصول أولي كلاسيكي.
🛡️ GitLab Vulnerabilities Allow Attackers to Execute Remote Code on Default GitLab Installations
Source: https://t.co/wj5kb075Zw
A newly disclosed exploit chain in GitLab shows how two long-buried memory-safety flaws in a Ruby JSON parsing library, Oj, could be combined to achieve remote code execution on default GitLab installations, exposing source code, Rails secrets, and internal services.
18 prioritized vulnerabilities were uncovered, seven of which were memory-safety bugs, two of which had silently persisted in Oj for nearly five years before being weaponized into a working exploit chain.
#cybersecuritynews
#CyberAlertes | Plusieurs avis de sécurité : Drupal, Check Point, JetBrains, MS Edge, Google Chrome, Moxa, Ericsson, MongoDB, HPE
Nous encourageons les utilisateurs et les administrateurs à appliquer les mises à jour nécessaires.
Pour en savoir plus : https://t.co/7qNWv5rLKw
‼️A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC
Source: https://t.co/BZ52NkzRXY
A new phishing operation, tracked as Operation BlueDash, is tricking users into installing a fake Microsoft Teams update that silently hands attackers not one but two independent ways to remotely control infected computers.
The infection starts with an email claiming a document was "too large" to send directly and was instead shared securely through Microsoft Teams.
When victims click the embedded link, they are routed through compromised websites to a convincing fake Microsoft Store page, complete with Teams branding, screenshots, and a spoofed Windows taskbar, all designed to look like a legitimate software update prompt.
#cybersecuritynews
Such an exciting Saturday night...
Timelining an Azure intrusion that led to on-premise compromise via Intune software deployment.
This feels like something @IAMERICAbooted would be doing.
🚨 Attackers are exploiting Palo Alto Networks PAN-OS flaw CVE-2026-0257 to deploy Qilin ransomware.
Some intrusions ended in rapid encryption. Others escalated to credential theft, data exfiltration, and double extortion.
How the attacks unfolded: https://t.co/NWiGvzeFer
IMPORTANT: Block Soft and Hard Match in Microsoft Entra ID!
When on-premises users are synced to existing Entra accounts, things can go really wrong. If the system matches the wrong users, it can mix up account data or give someone access to data they should not have.
Microsoft recommends that all customers disable hard matching and soft matching in Microsoft Entra ID unless they need it to take over cloud-only accounts.
By default, both settings are not blocked in the Microsoft tenant, so it's important to set it yourself!
Learn more:
https://t.co/hmX5bs7v7o
#Microsoft365 #EntraID #Cybersecurity