On August 21, Citrix disclosed that the appliance many organizations use to front their remote access — NetScaler Gateway — could be talked past its login checks entirely by an unauthenticated attacker taking an alternate path through the request flow. The same day, Microsoft published a maximum-severity remote code execution flaw in Entra ID, the service that issues identity tokens for a substantial share of the corporate world. Neither story is about stolen credentials.