CISA Issues Fresh SBOM Guidance. Did They Get It Right?

2026-08-03T02:51:34Zea15632ed8cdd0e74cfe420edc6c975243b153d7940387d201db381540c8accd
Active DirectoryICS/OTMicrosoft AzureSBOMactive-exploitationbanking-trojancertificate-securitycloud-securitycritical-infrastructurecybersecuritydata-breach‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌​‌identity-securityinfostealermalwaremobile-RATnon-human-identitiespasskeysphishingransomwaresession-token-theftsoftware-supply-chainthreat-intelligencevulnerabilitywater-utilitieszero-day

What happened

Dark Reading security news covering software supply-chain and SBOM guidance, certificate and non-human identity risks, critical-infrastructure attacks, malware campaigns, cloud and Active Directory privilege escalation, ransomware, data exposure, authentication bypasses, and emerging threats involving agentic AI, sandbox escapes, and AI toolchains. Several reports describe high-impact vulnerabilities and active exploitation, including attacks against Zimbra, Azure Automation, Microsoft AD certificates, exposed data-center controllers, and water utilities.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
ea15632ed8cdd0e74cfe420edc6c975243b153d7940387d201db381540c8accd
Enrichment time
2026-08-03T02:51:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.