The four stories our desk logged this week look unrelated on the surface: an identity provider tightening its defenses, a router operating system with a critical flaw, an SD-WAN product under active exploitation, and a Russian state actor rolling out a new malware installation technique. The thread running through all of them is that attackers are no longer primarily probing the hardened core of enterprise security. They are working the margins: the authentication layer, the edge appliances, the update pathways, and the managed networks that connect everything else. Each of these is a place where the enterprise assumes it is covered, and each is where the current pressure is concentrated.
Identity Is Being Hardened, Which Tells You Where Attackers Went
Microsoft's reminder that Entra ID will begin blocking external script injection attacks from October, as BleepingComputer reported, is not a story about a breach. It is a story about a class of attack that had become common enough to warrant a platform-level response. External script injection into an authentication system is the kind of thing that succeeds when an attacker already has a foothold or when a misconfiguration leaves a window open. Microsoft is closing the window. The timing matters because it confirms that identity providers are treating the browser-facing edges of their systems as contested ground. For US enterprises, this is a reminder that identity security is not a static product they buy; it is a platform surface that changes under them, sometimes on a schedule they did not set. Companies that have built their access architecture around Entra ID need to understand what changes in October and whether their own integrations depend on behavior that is about to disappear.
The Edge Is Where the Unpatched Live
CISA's warning about a critical pre-authentication remote code execution flaw in MikroTik RouterOS, as BleepingComputer reported, is the clearest example of the pattern. Pre-auth RCE in a router operating system means an attacker does not need credentials, does not need a session, and does not need to be on the network in any privileged way. They only need reachability. RouterOS is widely deployed in small and mid-sized business networks, in branch offices, and in environments where the security team is thin. The flaw can also cause a denial-of-service condition, which means even unsuccessful exploitation can take a site offline.
The lesson is not that MikroTik is uniquely vulnerable. The lesson is that edge appliances are where the enterprise's security assumptions are weakest. They are often deployed once and forgotten, updated rarely, and monitored less than endpoints or servers. CISA issuing a warning is a signal that the exposure is broad enough to warrant public attention. US companies with distributed sites should treat this as a prompt to inventory what is actually running at the edge, not just what they think is running.
Active Exploitation Changes the Urgency Calculation
Cisco's disclosure of a critical zero-day in Catalyst SD-WAN Manager, tracked as CVE-2026-76504, with attackers already exploiting it to escalate to admin privileges, as BleepingComputer reported, is a different category of problem. This is not a theoretical vulnerability. It is being used. The product is a management plane for SD-WAN, which means compromise does not just affect one device. It affects the control layer for a network that may span many sites.
For US enterprises, the practical implication is that patch cycles measured in weeks are not adequate for management-plane vulnerabilities that are under active exploitation. The exploit path here leads to admin privileges, which means an attacker who succeeds can change routing, alter policies, and potentially persist in the network infrastructure itself. This is the kind of compromise that is hard to detect because it looks like normal administrative activity. Companies running Catalyst SD-WAN need to treat the update as urgent, not routine.

