Webex A.I CyberSecurity Scoring
Webex
Company Information
Website:http://www.webex.com/
Employees number:1,310
Number of followers:155,438
NAICS:517
Industry Type:Telecommunications
Homepage:webex.com
Webex Risk Score (AI oriented)
Between 650 and 699
WebexTelecommunications
Updated:
17/07/2026
17/07/2026
696/1000
Weak
B
Webex Global Score (TPRM)
xxxx
WebexTelecommunications
Score locked

WebexWeak
Current Score
696B (WEAK)
01000
2 incidents
-38.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
696
JUNE 2026
694
MAY 2026
722
Cyber Attack
18 May 2026 • Webex
AnyDesk, Putty, Microsoft and Webex: Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs
Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation
692
CRITICAL-30
PUTWEBANYMIC1779215753
Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation
Microsoft has dismantled Fox Tempest, a sophisticated malware-signing-as-a-service (MSaaS) operation that enabled cybercriminals to bypass security defenses by making malicious software appear legitimate. The takedown, revealed in a U.S. District Court filing on Tuesday, targeted a service active since May 2025 that weaponized Microsoft’s Artifact Signing system designed to verify software authenticity to distribute malware and ransomware.
Cybercriminals, including affiliates of Rhysida, INC, Qilin, and Akira, used Fox Tempest to obtain fraudulent code-signing certificates, allowing malware to evade detection. The service provided short-lived certificates that mimicked trusted software like AnyDesk, Teams, Putty, and Webex, tricking users and security tools into executing malicious payloads. Microsoft’s investigation found that the group created over 1,000 certificates and established hundreds of Azure tenants to support its operations.
The disruption included seizing Fox Tempest’s website, taking down virtual machines, and revoking compromised certificates. Evidence showed cybercriminals complaining about the takedown, with some ransomware affiliates losing access to critical attack tools. Microsoft’s Digital Crimes Unit linked the service to the distribution of malware families such as Oyster, Lumma Stealer, and Vidar, delivered via malicious ads and fake download sites.
Fox Tempest operated as a well-resourced criminal enterprise, with dedicated teams for infrastructure, customer support, and financial transactions. Cryptocurrency analysis revealed the group earned millions of dollars from ransomware affiliates, with attacks targeting organizations in the U.S., China, France, and India. Unlike lower-cost cybercrime services, Fox Tempest charged thousands per operation, reflecting the growing sophistication of the cybercriminal ecosystem.
The takedown highlights how code-signing abuse undermines trust in digital security, allowing attackers to bypass defenses by masquerading as legitimate software. Microsoft’s actions aim to increase the cost of cybercrime by disrupting critical infrastructure used in large-scale attacks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
APRIL 2026
721
MARCH 2026
720
FEBRUARY 2026
718
JANUARY 2026
763
Cyber Attack
01 Jan 2026 • Webex
ConnectWise, LogMeIn, Kaseya, O&O Software, WebEx, Arctic Wolf, Oracle and Google: ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
Cybersecurity Roundup: Major Threats and Disruptions in Early 2026
716
HIGH-47
ARCCONO&OLOGKASORAWEBGOO1784262481
Cybersecurity Roundup: Major Threats and Disruptions in Early 2026
A series of high-profile cyber threats and law enforcement actions have marked the first half of 2026, targeting individuals, businesses, and critical infrastructure across multiple regions.
### Phishing Campaigns Exploit RMM Tools and AI-Generated Lures
A sustained phishing operation, SeasonalInvite, has been active since January 2026, abusing commercial Remote Monitoring and Management (RMM) tools like ConnectWise ScreenConnect, LogMeIn Resolve, Kaseya, and O&O Syspectr to compromise Windows and macOS users. The campaign leverages seasonal themes, distributing malicious links via phishing emails and poisoned search results. Researchers identified 959 eCard-themed domains and a traffic distribution system (TDS) using 2,658 gate pages to evade security scanners. The phishing pages appear to be AI-generated, suggesting threat actors used large language models (LLMs) to rapidly adapt their tactics.
### Chrome Sync Feature Abused for Surveillance
A legitimate Chrome feature designed for cross-device synchronization has been weaponized by stalkers and cybercriminals. By briefly accessing a victim’s device, attackers can add a controlled Google account and enable sync, allowing them to monitor browsing history, bookmarks, and saved passwords in real time. The method requires no malware, making detection difficult.
### Spanish Police Dismantle €140M Cybercrime Network
Authorities in Spain, in collaboration with international partners, disrupted a €140 million cybercrime operation involving fake investment platforms, CEO fraud, and adversary-in-the-middle (AitM) attacks. Four suspects were arrested two in Portugal, one in Spain, and one in Panama. The group used 800+ bank accounts and a network of "money mules" to launder funds, funneling stolen cryptocurrency through third-country accounts.
### UAT-11795 Deploys Starland RAT and WLDR Implant in U.S. and Europe
A Russian-speaking threat actor, UAT-11795, has been targeting users in the U.S. and Europe since June 2025 with a Python-based remote access trojan (RAT) called Starland and a PowerShell-based C2 implant (WLDR agent). The campaign uses trojanized installers for popular software like MobaXterm, WebEx, Zoom, and DBeaver, delivering payloads via ClickFix lures. The WLDR agent features encrypted beaconing, task queuing, and a Runspace execution engine, enabling stealthy data exfiltration and further payload deployment.
### Ransomware Attack Encrypts Network in Under 24 Hours
An unnamed ransomware group compromised an internet-facing IIS web server in June 2026, deploying a Rust-based ransomware strain dubbed Spirals within 24 hours. The attackers used an ASP.NET web shell for initial access, disabled endpoint security, dumped the Security Account Manager (SAM) hive, and spread laterally using PsExec. The ransom note threatened to publish stolen data after six days if demands were not met.
### Vidar Stealer and XMRig Miner Campaign Targets Global Victims
A financially motivated campaign detected in April 2026 delivers Vidar stealer (targeting browser credentials, cookies, and crypto wallets) and XMRig cryptocurrency miner via malvertising. The malware, distributed through cracked software lures, uses the Factory-v3 malware-as-a-service (MaaS) framework. Operators monetize stolen data on criminal markets while generating passive income from hijacked CPU cycles.
### Fake GitHub Repositories Spread Windows Infostealer
A Russian-speaking threat actor created 290+ fake GitHub repositories impersonating trusted vendors like Arctic Wolf to distribute a Windows infostealer with the same codebase as BoryptGrab-Lineage. The malware targets 41 cryptocurrency wallet paths and 19+ browsers, exfiltrating stolen data to a Russian-hosted C2 server. The campaign highlights the risks of brandjacking and supply chain attacks.
### Dutch Authorities Arrest Alleged Mastermind Behind 700-Person Scam Network
A 46-year-old man with Israeli and Polish citizenship was arrested in the Netherlands for allegedly running a global investment fraud network employing 700+ scammers across 20 call centers. Victims were manipulated into depositing funds often in cryptocurrency into fake platforms, with scammers maintaining contact for months to build trust. The operation is linked to €140 million in losses.
### New Phishing Toolkits and MFA Bypass Techniques Emerge
- Jalisco: An AI-powered device code phishing toolkit that provisions fresh OAuth codes in real time, bypassing time-based MFA defenses.
- OmegaLord: A JavaScript-based credential harvester that impersonates a PDF reader and collects phone numbers alongside passwords to intercept MFA codes.
### U.S. and Allies Sanction Russian Cybercrime Groups
The U.S., U.K., and Australia imposed sanctions in November 2025 on Media Land LLC, ML.Cloud LLC, and three Russian nationals Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova for cybercrimes causing $62+ million in losses. The Rewards for Justice (RFJ) program offers up to $10 million for information on their activities.
### Critical Vulnerabilities Added to CISA’s KEV Catalog
CISA added two high-severity flaws to its Known Exploited Vulnerabilities (KEV) catalog:
- CVE-2026-46817: An improper privilege management vulnerability in Oracle E-Business Suite.
- KNX Protocol Connection Authorization Option 1: An overly restrictive account lockout mechanism with unknown exploitation details.
### Eastern European C2 Infrastructure Mapped
A Hunt.io analysis uncovered 3,900+ threat-activity-enabling servers across 302 Eastern European providers, with Russia’s Media Land leading (1,277 IPs), followed by Tactical RMM (232) and Acunetix (173). The findings underscore the region’s role in hosting cybercriminal infrastructure.
### Malicious NuGet Packages Drop Surveillance Payloads
Eleven malicious NuGet packages, masquerading as game utilities and productivity tools, were found delivering a Python-based infostealer ("pepesoft.exe") from GitHub and Hugging Face. The payload uses AWS-style key material for remote configuration, binds activations to hardware, and includes a BitTorrent fallback mechanism.
### Windows Bind Links Exploited to Bypass EDR
Bitdefender researchers demonstrated three techniques File-Binding, Process-Binding, and Silo-Binding that abuse Windows’ bind links to evade EDR detection. While Microsoft rated the findings as low severity (requiring admin access), the methods highlight potential gaps in endpoint security.
### Key Takeaways
- Phishing and RMM abuse remain dominant attack vectors, with AI-generated lures increasing in sophistication.
- MFA bypass techniques (e.g., device code phishing, OAuth abuse) are evolving, reducing the effectiveness of traditional defenses.
- Ransomware and infostealers continue to target businesses and individuals, with 24-hour encryption timelines becoming more common.
- Law enforcement actions have disrupted major cybercrime networks, but threat actors rapidly adapt.
- Supply chain risks persist, with fake repositories and trojanized software posing significant threats.
The first half of 2026 has seen a surge in financially motivated cybercrime, state-linked activity, and novel evasion techniques, underscoring the need for robust detection and response strategies.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
763
NOVEMBER 2025
763
OCTOBER 2025
763
SEPTEMBER 2025
763
AUGUST 2025
763
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Webex ??
What was Webex's A.I Rankiteo Cyber Score in June 2026 ??
What was Webex's A.I Rankiteo Cyber Score in May 2026 ??
What was Webex's A.I Rankiteo Cyber Score in April 2026 ??
What was Webex's A.I Rankiteo Cyber Score in March 2026 ??
What was Webex's A.I Rankiteo Cyber Score in February 2026 ??
What was Webex's A.I Rankiteo Cyber Score in January 2026 ??
What was Webex's A.I Rankiteo Cyber Score in December 2025 ??
What was Webex's A.I Rankiteo Cyber Score in November 2025 ??
What was Webex's A.I Rankiteo Cyber Score in October 2025 ??
What was Webex's A.I Rankiteo Cyber Score in September 2025 ??
What was Webex's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on Webex's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Webex ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Webex's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?