
Cybersecurity Updates: PowerShell Script for Entra ID Audits, Ubiquiti Vulnerabilities, New Log4j Flaw, and Sleepwalker Malware Analysis
On August 27, 2026, Johannes Ullrich of the SANS Institute Stormcast highlighted a PowerShell script developed by Rob to audit Entra ID administrator roles, identifying users with elevated privileges across various roles beyond just global administrators. Ubiquiti released Security Advisory Bulletin #67 addressing 22 vulnerabilities in UniFi products, including high-severity flaws (CVSS scores of 10, 9.9, and 9.1) requiring control plane access for exploitation, with patches already released. A new Log4j vulnerability was disclosed, involving a deserialization flaw in the FilteredObjectInputStream feature, though exploitation is limited as most software does not directly accept Log4j-serialized objects, unlike the 2021 Log4j incident. Palo Alto Networks analyzed Sleepwalker malware, which uses an unusual passive command-and-control mechanism by listening for network packets with specific checksums and side-loads into ESET antivirus, executing decrypted bytecode instructions. The Log4j flaw lacks a CVE or patch, while the Ubiquiti vulnerabilities were found partly via AI tools, and the PowerShell script aids in detecting unauthorized or legacy admin accounts.