A curated dispatch from GajShield

The GajShield Gazette

Lead story
Also today
In brief

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

The disclosure of CVE-2026-69836 in Microsoft Entra ID is particularly significant because it affects one of the most important trust layer…

Aug 21, 2026

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA’s August 20, 2026 addition of CVE-2026-72529 and CVE-2026-72530 to the Known Exploited Vulnerabilities catalog deserves particular att…

Aug 21, 2026

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

The newly disclosed flaw in `isolated-vm` is particularly significant because it attacks the fundamental security promise of the library: t…

Aug 21, 2026

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

The critical Elementor Pro vulnerability identified as CVE-2026-32475 is a particularly serious WordPress security issue because it can all…

Aug 21, 2026

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

The Rust supply-chain attack involving `arrayref`, `internment` and `append-only-vec` is particularly concerning because it demonstrates ho…

Aug 21, 2026

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

The newly disclosed NetScaler vulnerabilities deserve immediate attention because they affect exactly the systems organisations rely on to …

Aug 20, 2026

Critical Zimbra RCE flaw now actively exploited in attacks

The active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite deserves immediate attention because this is not merely another web…

Aug 20, 2026

CISA Adds One Known Exploited Vulnerability to Catalog

CISA’s latest addition to the Known Exploited Vulnerabilities catalog concerns CVE-2025-62593, a critical remote code execution vulnerabili…

Aug 20, 2026

Hackers compromise 14,500 Dahua web cameras in 35-day campaign

The CameraSwarm campaign targeting Dahua IP cameras is a strong reminder that Internet-connected surveillance devices are not passive appli…

Aug 20, 2026

Healthtech firm CareCloud data breach impacts 3.7 million patients

The CareCloud breach is a stark reminder of why healthcare data remains one of the most valuable targets in cybercrime. CareCloud has now c…

Aug 20, 2026

Sakura Internet hack exposes data of up to 1.36 million accounts

The Sakura Internet breach is significant not simply because of the potential number of affected accounts, but because of where the attacke…

Aug 20, 2026