
Max-Severity Entra ID Flaw Exploited: What Pittsburgh SMBs Should Do
Microsoft patched a max-severity Entra ID flaw exploited in attacks. Here is what Pittsburgh SMBs on Microsoft 365 should check this week, step by step.
Blog

Microsoft patched a max-severity Entra ID flaw exploited in attacks. Here is what Pittsburgh SMBs on Microsoft 365 should check this week, step by step.

Password spraying attacks jumped 155x by exploiting MFA gaps in Microsoft 365. Here is what Pittsburgh SMBs should check in their tenant this week.

CISA added actively exploited macOS, SharePoint, vCenter, and Windows IKE flaws to its KEV catalog. Here is what Pittsburgh SMBs should patch and verify this week.

CISA confirms ransomware gangs are exploiting a Windows Task Host flaw. Here is what Pittsburgh SMBs should verify, patch, and hunt for this week.

Microsoft is patching a Defender zero-day (CVE-2026-69414, "ShieldBreak"). Here is what Pittsburgh SMBs should verify and harden this week.

A critical VMware vCenter RCE (CVE-2026-59310) is under active exploitation. What Pittsburgh SMBs running VMware should verify, patch, and hunt for this week.

Attackers are exploiting a critical Microsoft SharePoint flaw in the wild. Here is what Pittsburgh SMBs should verify, patch, and monitor this week.

CISA confirms ransomware crews are exploiting a SharePoint RCE flaw. Here is what Pittsburgh SMBs should patch, verify, and monitor this week.

A critical WordPress pre-auth XSS (CVE-2026-64638) affects every version and can chain to PHP code execution. Here is what Pittsburgh SMBs should do this week.

UNC6671 is vishing financial and professional services employees on personal phones to steal SaaS data. Here is what Pittsburgh SMBs should do this week.

An active Microsoft 365 AitM phishing campaign is hijacking finance and payroll mailboxes at SMBs. Here is what Pittsburgh businesses should do this week.

Kali365 hijacks Microsoft 365 accounts via device-code phishing. What Pittsburgh SMBs should check in Entra ID this week, plus a 7-step action list.