This Week in Cybersecurity
Each week at Applied Tech we recap the biggest cybersecurity news headlines from the week to keep you informed and ready to face the latest threats. Here’s your breakdown for the week of August 12th-21st!
Senator Demands Federal Audit of Government Hacking Tools
United States Senator Ron Wyden sent a letter asking the GAO to review how the FBI, DEA, ICE’s HSI, and the Secret Service use hacking tools and spyware against Americans. His complaint: unlike wiretaps, which get annual public reporting, federal hacking operations have run for two-plus decades with almost no disclosure of scope or safeguards, and DOJ/FBI have repeatedly stonewalled past transparency requests. He wants GAO to check for misuse, review how agencies acquire and secure these tools against leaks, and assess how courts are informed when warrants authorize them.
He cites the Peter Williams case (the ex-L3Harris exec who sold hacking tools to a Russian broker, later used against Ukraine and by Chinese crypto-targeting hackers) as proof unaccounted-for exploit stockpiles are a real proliferation risk.
Source: TechCrunch
Read More
Deserialization Strikes Again: Entra ID's Perfect Score Vulnerability
Microsoft disclosed CVE-2026-69836, a maximum-severity (CVSS 10.0) remote code execution flaw in Entra ID, and confirmed it’s already been exploited in the wild. It’s a deserialization-of-untrusted-data bug, letting an unauthorized attacker execute code over the network against the identity backbone underpinning huge swaths of enterprise cloud environments.
Microsoft says it’s fully mitigated the flaw server-side with no customer action required, but hasn’t disclosed how it was exploited, when activity started, whether it’s ongoing, or how it was found. The bug was reported by Microsoft’s own Principal Security Engineer, Robert Fitzaptrick.
Source: The Hacker News
Read More
Someone's Watching: 14,000+ Russian and Ukrainian Cameras Backdoored in a 35-Day Blitz
Threat intel firm Hunt.io uncovered Operation CameraSwarm, a 35-day campaign (June 17–July 22) that compromised over 14,500 Dahua IP cameras, concentrated on Russian and CIS telecom networks. Researchers accessed the attacker’s own exposed infrastructure and found them chaining three known Dahua vulnerabilities to bypass authentication and plant a persistent backdoor account (p2pwn/p2password) on nearly 1,900 cameras—one that survives password changes and even factory resets.
Attackers also abused Dahua’s cloud relay to reach NAT-hidden cameras using just serial numbers. Hunt.io assesses with “moderate confidence” the toolkit was built to hand access to a third party, though it stops short of calling this a confirmed access-broker operation.
Source: SecurityWeek
Read More
Researchers Demonstrate NFC Relay Attack That Revives Expired Visa Cards
UMass Amherst researchers built “Zombie Card,” an NFC relay attack that rewrites the expiration date a terminal reads during a contactless Visa transaction, without touching the card’s cryptography. It exploits a split in Visa’s Kernel 3: the terminal checks an unsigned expiry field, while the issuer checks a separate, untouched field, so both still validate despite the terminal being lied to.
Using two Android phones as the relay, researchers completed real transactions, that included purchases at retail and grocery merchants, against one of five tested US banks; others caught the tampering but handled it inconsistently. Mastercard, Amex, and Discover all detected and declined it, making this Visa-specific. Disclosed in May 2025; Visa still hasn’t issued public guidance.
Source:The Hacker News
Read More

About Applied Tech, An HBS Brand
Applied Tech is a leading IT and cybersecurity services provider dedicated to helping organizations protect their digital assets and scale their IT capabilities. Our proactive services span cloud management, security, productivity, and IT growth strategy—delivered by an experienced team with solutions built around your goals.
As part of Heartland Business Systems, we now bring greater resources, broader capabilities, and deeper technical expertise to every client relationship.
Get in Touch with Us


