SolarWinds Database Mapper and Task Factory enable data professionals to accelerate cloud migrations
NIST and CISA finalize playbook to stop token theft and forgery
NIST and CISA finalized NIST IR 8587, a playbook helping federal agencies and cloud providers defend identity tokens against theft and forgery.
The finalized NIST IR 8587 guidance covers protecting token signing keys, verifying tokens, lifetimes, revocation, session management, and dividing security responsibilities between cloud providers and customers. It cites an incident in which foreign actors forged tokens with a stolen commercial signing key to steal more than 60,000 emails from one government agency. It also recommends extending token protections to AI agents and preparing identity systems for a future post-quantum cryptography transition.
Microsoft security advisory – August 2026 monthly rollup (AV26-804) – Update 2
Canada's Cyber Centre updated advisory AV26-804 relaying Microsoft's August 2026 monthly rollup of vulnerabilities across .NET and Azure products.
The Canadian Centre for Cyber Security advisory AV26-804, updated August 27, 2026, relays Microsoft's August 2026 monthly security rollup originally issued August 11. Affected products include .NET 8.0, 9.0, and 10.0 on Linux, macOS, and Windows, plus many Azure services. Listed Azure components include Azure Kubernetes Service, Azure SQL Database, Azure Service Bus, Azure Active Directory, Azure Logic Apps, and Azure Monitor Agent.
CISA Vulnerability Review
CISA's Vulnerability Review finds most compromises exploit exposed, well-known flaws due to basic security failures, based on FY2024-2025 data.
The CISA Vulnerability Review analyzes CISA and open-source data from fiscal years 2024 and 2025. It concludes most compromises do not rely on advanced techniques; threat actors scan the internet for exposed, well-known software vulnerabilities. CISA urges organizations to address underlying weaknesses and prioritize vulnerabilities for remediation based on the risk they pose.