CISA Advisories

Microsoft's "Perfect 10" Bug 🚨 and 9,300 Live AWS Keys 🔑

Two stories from today's security news deserve your attention: a Microsoft flaw that scored a perfect 10 out of 10 on the severity scale, and a four-year study showing thousands of company cloud keys sitting in the open right now. Both come down to the same uncomfortable question — who else already has the keys to your front door?

Microsoft Quietly Patched a Bug That Scored a Perfect 10

Microsoft has fixed CVE-2026-69836, a critical flaw in Entra ID — the identity service that decides who gets into Microsoft 365, Teams, Outlook, and most corporate apps at companies around the world. The bug earned a rare 10.0 severity rating because an attacker needed no password, no phishing email, and no help from an employee to run their own code on the system. In practice, that means someone could have walked straight past the login screen of a huge number of organizations.

The good news: Microsoft says it found no evidence anyone actually exploited it, and it published the details voluntarily rather than burying them. The lesson for everyone else is less about this one bug and more about the pattern — your identity provider is the single most valuable target in your environment, and patching it fast is not optional.

Read more →

9,300 Live AWS Keys Are Sitting Out in Public

Truffle Security spent four years scanning public code for leaked Amazon Web Services access keys, and the results are rough: 9,300 of the keys they found are still active today. Of those, 817 belong to real companies, and 526 are root keys — the digital equivalent of the master key to the whole building, with no limits on what they can do.

These leaks usually happen by accident. A developer pastes a credential into code, pushes it to a public repository, and forgets. But an attacker with a live root key does not need to hack anything — they simply log in and help themselves to your customer data, your backups, and your bill. If your business runs on cloud infrastructure, this is a good week to rotate old keys, turn on automated secret scanning, and stop using root credentials for day-to-day work.

Read more →

Stay ahead of threats with GOCO Security at gocosecurity.com.

Comments

Popular Posts