
Increased Cyber Threats Targeting AI Credentials, Enterprise Routers, and Microsoft Entra ID
The July 14, 2026, SANS Internet Storm Center Stormcast episode highlights a rise in scans targeting AI-related credentials and Model Control Protocol (MCP) connections on web servers, with attackers probing for /mcp URLs and sending full MCP-compliant payloads to exploit AI tokens. CISA, the FBI, and other agencies issued guidance on securing enterprise-grade routers against Russian threat actors, emphasizing the disabling of insecure protocols like SNMPv1/v2, enforcing strong passwords, and deactivating Cisco Smart Install, which remains enabled by default and lacks authentication. The advisory also recommends blocking internet-exposed ports for SNMP, TFTP, and SMI. Proofpoint documented a brute-force technique abusing Microsoft Entra ID’s resource owner flow, where attackers use fake client IDs to bypass logging of application names, allowing them to enumerate valid usernames and passwords without triggering alerts for failed logins. A newly disclosed remote code execution vulnerability in a backup company (BH) requires only domain user credentials, though details on exploitation were not specified. The episode precedes Patch Tuesday and concludes with a mention of a SANS Fire talk.