Three things came across the wire this weekend that I would not ignore. One is in the identity plane I write about. One is in the physical world. One is in the build pipeline. All three are the same story: the attack surface moved, and the patch calendar did not.
A 10.0 in Entra ID, already exploited, fixed server-side
Microsoft disclosed CVE-2026-69836 on Thursday. CVSS 10.0. Unauthenticated remote code execution in Entra ID itself, from unsafe deserialization of untrusted data over the network. No user interaction required. Microsoft said it was already exploited in the wild.[1][2]
Because Entra ID is a Microsoft-operated service, they fixed it on their side. No customer action. That is the good news. The bad news is we do not know who exploited it, how long they were in, or what they reached. Microsoft has not said.[3]
This is the identity service. The thing that vouches for every user in the tenant. A 10.0 RCE in that plane is not a patch-it-and-move-on moment. It is a go-check-your-sign-in-logs moment.
I would look for: unexpected service principal creations, new app registrations, modifications to Conditional Access policies, and authentication events from IP ranges that do not match your user baselines. If you have Entra ID P2, pull Identity Protection sign-in risk events for the last 30 days. If you do not, your Entra audit log is still your friend.[2]
Two weeks ago I wrote about passkeys and the frontline. The premise was that password spray is still the boring hole.[8] A 10.0 in the identity service itself is a different kind of hole. It is not the user’s fault. It is not the factor’s fault. It is the plane.
AI-generated exploit scripts targeting Siemens S7 PLCs
CISA, NSA, and FBI published a joint advisory on August 19 warning of an active campaign targeting Siemens S7 series PLCs across energy, water, critical manufacturing, and agriculture. The attackers are using AI-generated exploitation scripts disguised as legitimate monitoring software.[4][5]
The advisory covers S7-200, S7-300, S7-400, S7-1200, and S7-1500 variants. The AI piece is the part that caught my eye. They are using AI to generate code for initial access, credential theft, and denial-of-service. That is not a research paper. That is a field campaign.[5]
I do not work OT every day. But I know enough to say this: if you have S7 PLCs on a network that can be reached from the internet, this is your weekend. CISA’s advisory has the mitigations. The short version is segment, restrict, and log. If the PLC is reachable from a engineering workstation that is reachable from a corporate VLAN that is reachable from a guest Wi-Fi, you have a problem CISA cannot fix for you.
Rust supply chain: build-time malware in 245 million downloads
The Rust Security Response Team confirmed a supply chain attack on the arrayref crate, version 0.3.10, plus append-only-vec and internment. The compromised crates pulled in a malicious proc-macro1 package that downloaded and executed a remote payload at build time. The combined download count was 245 million.[6][7]
The Rust team’s advisory includes a find command to check your local cargo cache for the affected crate versions. If you build Rust, run it.
What makes this one interesting is the vector. This is not a typo-squat or a name confusion. The maintainer’s account or publish pipeline was compromised, and a legitimate crate shipped a new version with a malicious build script. The trust model that makes package registries fast is the same trust model that makes them fragile. That is not a Rust problem. It is the same story as npm, PyPI, and every other registry that lets a build step run arbitrary code.
What I am actually doing Monday morning
- Check Entra sign-in logs and audit for the last 30 days. Look for new service principals and CA policy changes, not just failed sign-ins.[2]
- Ask the OT team if we have S7 PLCs. If yes, where. If they are segmented, confirm it is still true.[4]
- Run the Rust
findcommand from the Rust blog post against any cargo caches on build machines.[6] - Do not treat any of these as closed because the vendor patched. The Entra ID exploit was in the wild. The PLC campaign is active. The Rust crate was live for days before someone noticed.
Three weekends ago the wrap was 415 patches and a NetScaler we have seen before.[9] This weekend it is a 10.0 in the identity service, AI hunting PLCs, and a build-time payload in one of the most downloaded Rust crates. The surface is not getting smaller. The calendar is the same.
Sources
[1] https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html — THN Entra ID CVSS 10 [2] https://www.securityweek.com/microsoft-rolls-out-22-fresh-security-patches — SecurityWeek 22 patches Entra ID exploited [3] https://www.theregister.com/cyber-crime/2026/08/21/microsoft-sounds-alarm-as-perfect-10-entra-id-flaw-comes-under-attack/5290925 — Register Entra ID perfect 10 [4] https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a — CISA Siemens S7 advisory [5] https://thehackernews.com/2026/08/ai-generated-exploit-scripts-target.html — THN AI Siemens S7 [6] https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref — Rust blog arrayref supply chain [7] https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html — THN Rust supply chain 245M [8] https://blog.darkpixeltech.com/posts/passkeys-meet-the-frontline — DPT passkeys frontline [9] https://blog.darkpixeltech.com/posts/weekend-wrap-415-patches-and-another-netscaler — DPT weekend wrap patches