August 2026
5artifacts
IAM & Security Weekly Briefing
Two alleged TeamPCP members were charged in Australia over a long-running open-source supply chain attack spree, including the March 2026 compromises of Trivy, Checkmarx KICS, and LiteLLM.
IAM & Security Weekly Briefing
Microsoft patched a CVSS 10.0 Entra ID flaw plus critical Azure Arc and Exchange Online issues; the "exploited" flag was later corrected to "No."
IAM & Security Weekly Briefing
Microsoft's August Patch Tuesday closed 398 flaws, including a Windows kernel driver zero-day (CVE-2026-68820) already exploited for SYSTEM compromise.
IAM & Security Weekly Briefing
Snowflake extortionist Connor Riley Moucka pleaded guilty, closing a landmark identity-enabled breach affecting 165+ organizations and 100M+ people.
IAM & Security Weekly Briefing
Attackers are shifting from password theft to session/token theft — Russian actors kept mailbox access after credential rotation, and device-code phishing is now an industrial-scale OAuth token…