Search
Find merged stories by title or summary.
CVE-2026-70125 - Microsoft Outlook Remote Code Execution Vulnerability
Information published. This CVE was addressed by updates that were released in September 2026, but the CVE was inadvertently omitted from the September 2026 Security Updates. This is an informational change only. Customers who have already installed the September 2026 updates do not need to take any further action.
The hunters go after the bureau.
ShinyHunters claims to have breached FBI systems. CLOSEDQUORUM malware delegates command-and-control decisions to commercial LLMs. An IT error erases 11 years of hospital maternity data. F5 patches a critical BIG-IP APM zero-day. Ransomware activity remains high. Microsoft disrupts the EvilTokens cybercrime platform. Researchers turn Claude Code’s normal workflow against itself. Pundits propose an AI Assurance Compact. A Ryuk ransomware gang member gets two years prison time. Our guest is Jen Sovada, General Manager of Public Sector at Claroty, on Project Watershed 250 and the challenges facing U. S. water utilities. Meta’s Muse mettles with messages. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
Reimagining the SOC for the agentic era in Microsoft Defender
The physics of cybersecurity are changing. So must the security operations center (SOC). Cyberattackers are using agents to automate execution at unprecedented scale. What once required entire teams now requires a single operator and an agent framework. That shift has exposed a hard truth: security cannot operate at AI speed when protection and operations are built as separate systems. Every handoff, integration, and boundary slows defenders down. Agents inherit that complexity. For agentic security to work, the industry needs a different model. It needs a modern cyber stack with the breadth to see across the environment and the depth to investigate and act. Security operations and native protection must function as one system. This is the integrated security operations center (ISOC).
Microsoft Copilot browser faces user backlash - Cybernews
Microsoft Copilot browser faces user backlash Cybernews
Microsoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes - Hackread
Microsoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes Hackread
OAuth Token Theft Through Microsoft's Front Door | Huntress
A sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. No phishing domain, no spoofed UI, no browser. Here's how to detect it.
Fake Claude Max giveaway hides a Google account phishing trap
Phishing follows whatever people want at the moment, and right now that includes AI subscriptions they don’t have to pay for. We recently uncovered a new variation on this theme: A fake Claude Max giveaway that uses a convincing Google sign-in window to steal login information. Claude’s paid plans start at $20 a month and cost considerably more for higher usage limits, while free accounts have stricter limits. That makes the promise of a free upgrade an attractive lure. Microsoft reported in June that it had seen a growing number of phishing, malicious advertising, and search-based campaigns impersonating services such as ChatGPT, Claude, DeepSeek and Copilot. Some claim that a payment has failed and send you to a fake checkout. Others offer an app download that installs malware. The campaign we found takes a different approach.
AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets. The post AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft appeared first on SecurityWeek .
Microsoft: September Windows updates break Always On VPN connections
Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. [... ]
Lapsus$ Explained | The Hacking Group Behind Okta, Uber, Nvidia and Its Return
Lapsus$ is a hacking and extortion group first known for breaching Okta, Microsoft, Nvidia, Samsung, and Uber in 2021 and 2022 using social engineering rather than malware, and it has since reemerged as part of a larger collective called Scattered Lapsus$ Hunters. Unlike ransomware gangs that rely on encryption, Lapsus$ built its reputation on stealing source code and internal data, then threatening to leak it publicly unless the victim paid or complied with its demands. This tactic made it one of the most disruptive threat actors of the past few years despite reportedly being run largely by teenagers. That threat hasn’t gone away; it’s evolved.
EvilTokens made phishing-as-a-service look easy. Then it got taken down
Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 organizations. Microsoft says the EvilTokens platform, operated by Storm-2992, is a phishing-as-a-service kit sold to cybercriminals through Telegram. The service costs $1,500 upfront and $500 per month, with additional tools available for extra fees. Its control panel lets customers build and manage phishing campaigns, customize landing pages, configure domains, track victims, and manage stolen authentication tokens. The platform includes 44 themes and uses AI to create targeted phishing emails based on a victim’s role.
The Phishing Kit That Turned Microsoft’s Login Flow Into an AI-Powered Fraud Machine
EvilTokens turns a Microsoft sign-in into a route to corporate email fraud. The phishing kit, first seen in February 2026, tricks people into approving an attacker’s login through a real device code process without handing over a password. The lure usually arrives as an urgent email about an invoice, shared file, document signature or expiring password. A link or attachment takes the recipient to a page that presents a code and urges them to continue with the sign-in. The request looks routine. Microsoft researchers tied EvilTokens to a group they track as Storm-2992 and said the toolkit helped scale business email compromise. Microsoft said in a report shared with Cyber Security News (CSN) that campaigns using the kit compromised more than 12,000 inboxes at over 10,000 organizations worldwide. Affected sectors include finance, construction, healthcare and education.
ChatGPT Computer History Creates New Attack Surface for macOS Infostealers
OpenAI’s new ChatGPT Computer History feature for macOS is designed to make AI assistance more context-aware, but its local “diary” of user activity may also create a high-value target for macOS infostealers . Released for the ChatGPT macOS desktop app, Computer History is disabled by default and currently applies to ChatGPT Pro, Business, and Enterprise users. The opt-in capability converts selected activity across apps and websites into searchable memories that ChatGPT and Codex can use in later conversations. ChatGPT Computer History Creates New Attack Surface The feature requires ChatGPT Memories to be enabled, while Business and Enterprise users need workspace-level administrative approval to activate it individually. Unlike Microsoft Recall’s original screenshot-centric model, Computer History relies on macOS Accessibility APIs to record interaction events.
Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes
The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft. With authorization from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs to seize 50 websites used to operate the service and disable more than 150 domains tied to … More → The post Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes appeared first on Help Net Security .
Claude Opus 5.5 cuts costs and adds safeguards for autonomous AI
Claude Opus 5. 5 is available across Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure. Developers can access it through the Claude Platform using the model name claude-opus-5-5. It includes watermarking measures designed to comply with the EU AI Act. Built for long and complex tasks Opus 5. 5 is designed for codebase migrations, software audits, financial analysis, data collection and workflows involving several applications. Early testers used the model for engineering tasks that ran … More → The post Claude Opus 5.5 cuts costs and adds safeguards for autonomous AI appeared first on Help Net Security .
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break
Fake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools
Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download a fake authenticator, and ended up killing 145 different antivirus and EDR products using a driver that Microsoft itself had signed. That last part is the one worth sitting with. LastPass’s Threat Intelligence, Mitigation, and Escalation team spotted the fake GitHub organization on August 13, 2026. It appeared high in search results for “LastPass Authenticator download” and used real LastPass logos and branding to look legitimate. The download page also displayed fake trust badges, including “VirusTotal Approved.” The badges were meaningless and were simply there to make users feel safe enough to download the file.
Top 10 Best Decentralized Identity Solutions in 2026 [Ranked & Scored]
EU digital identity and GDPR compliance mandates, deepfake-driven fraud in authentication and verification , and credential-reuse fatigue pushed decentralized identity from conference-talk to contract. We scored ten players on standards depth, production evidence, and enterprise readiness and flagged the market’s churn honestly, because this category retires vendors faster than most. Microsoft Entra Verified ID ranks #1 on deployable reach; Dock Labs and Ping Identity complete the podium. Key Takeaways • #1 overall: Entra Verified ID verifiable credentials bundled into the identity platform enterprises already run. • Podium: Microsoft (reach), Dock Labs (fastest issuance API), Ping (IAM-integrated credentials). • Churn warning: this market consolidates fast we flag status risks ([VERIFY]) rather than rank ghosts blindly.
Microsoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime
Microsoft has hailed its success in disrupting EvilTokens , an AI-powered a phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000 organizations worldwide. Since February 2026, EvilTokens has offered a subscription platform combining account compromise, mailbox analysis, target selection, and fraud preparation. Its dashboard and chatbot centralized access to those capabilities, with a $1,500 initial sign-up fee and $500 monthly subscription, marketed through Telegram channels. “EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service,” Microsoft explains in a post about the takedown . “Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface.”
Microsoft Disrupts EvilTokens Device Code Phishing Service
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Volexity researchers spotted another state-aligned Chinese threat group exploiting a triple-link chain of zero-day vulnerabilities across multiple campaigns, the company said in a blog post Monday. The threat group it tracks as UTA0565 exploited the vulnerabilities in Chrome and Microsoft between Sept. 3 and 4 before the defects were disclosed or patched, researchers said. The timing of the malicious activity mirrors other spikes threat hunters observed and attributed to multiple Chinese espionage threat groups. Yet, Volexity noted UTA0565’s campaigns differed from those attacks by using multiple fake websites to deceive victims. Volexity shared phishing emails UTA0565 sent to Asian government entities urging them to publicly support imprisoned Hong Kong activist Chow Hang-tung.
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U. S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver
Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud.
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
Microsoft, along with a group of industry partners, disrupted EvilTokens, a short-lived but highly consequential cybercrime platform that investigators linked to more than 12,000 compromised Microsoft customer email inboxes across more than 10,000 organizations globally, the company said Tuesday. Acting on federal court order Sept. 15, Microsoft and partners seized 50 websites the phishing-as-a-service used for operations and disabled more than 175 domains linked to EvilTokens’ supporting infrastructure. EvilTokens, launched in February 2026, was “a powerful cybercrime platform that used AI at every step of the attack chain — from compromising email accounts to designing intricate roadmaps for financial fraud and scams,” Steven Masada, associate general counsel and general manager of Microsoft’s Digital Crimes Unit, wrote in a blog post .
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU). [... ]
Unmasking EvilTokens: Getting to the root of device code phishing
In this article • What is device code phishing? • EvilTokens platform and operations • EvilTokens phishing emails • Mitigation and protection guidance • Microsoft Defender XDR detections • Hunting queries Following its emergence in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, providing cybercriminals with AI capabilities for tailoring phishing lures and analyzing compromised inboxes to identify high-value targets. This AI-powered cybercrime platform facilitated sophisticated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes in over 10,000 organizations worldwide. EvilTokens enabled threat actors to abuse the device code authentication flow, steal tokens, and compromise organizational accounts at scale using an AI-driven infrastructure and automating multiple parts of the attack chain.
Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day
The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse , also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit BigDiskBuster, it triggers a Denial of Service Vulnerability in Windows Defender Update. The security researcher claims to have developed BigDiskBuster, a proof-of-concept that can block Microsoft Defender from receiving platform and signature updates. “This proof of concept is similar to UnDefend , it prevents windows defender from performing platform/signature updates.” wrote the expert. “Seems to work on all supported windows versions but PoC is a bit buggy and needs some rewritting but you get the idea.”
Microsoft SharePoint Flaw Lets Attackers Execute Code Remotely With Low Privileges
Microsoft has confirmed a high-severity remote code execution vulnerability in on-premises SharePoint Server that lets an authenticated, low-privileged attacker run arbitrary code over a network without user interaction. Tracked as CVE-2026-65660, the code-injection flaw carries a CVSS score of 8.8 and affects SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Because SharePoint servers hold sensitive documents and operate with powerful service identities, successful exploitation could provide attackers with a foothold for credential theft, lateral movement, data exfiltration, and persistent access across environments. The vulnerability was discovered by Viettel Cyber Security researcher Dinh Ho Anh Khoa, who described it as another bypass of SharePoint’s SafeControls protection .
Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
Abdelhamid Naceri, a former Microsoft Germany employee, is the exploit leaker Nightmare Eclipse, aka Chaotic Eclipse. The post Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity appeared first on SecurityWeek .
Veeam Agent Flaw Actively Exploited to Gain SYSTEM Privileges on Windows
A critical local privilege escalation flaw in Veeam Agent for Microsoft Windows is drawing attention after public proof-of-concept exploit code became available. The vulnerability, tracked as CVE-2026-32996 , could let a low-privileged local user run commands with NT AUTHORITY\SYSTEM permissions on affected Windows devices. Technical details and exploit code were publicly released on September 14, 2026, increasing the risk that threat actors may incorporate the issue into post-compromise attack chains. The flaw affects Veeam Agent for Microsoft Windows version 13. 0. 1. 2067 and earlier 13 builds. The issue exists in the Veeam Endpoint Backup service, which handles privileged client activity through a local gRPC named pipe located at \\.\pipe\Veeam\VAW\ServiceConnectionPipe.
Hackers Exploit Veeam Agent Flaw to Gain SYSTEM Privileges on Windows
A newly disclosed active exploitation of a critical local privilege escalation flaw in Veeam Agent for Microsoft Windows that enables attackers to elevate low-privileged access to NT AUTHORITY\SYSTEM on vulnerable endpoints. Tracked as CVE-2026-32996 , the vulnerability affects Veeam Agent for Microsoft Windows version 13. 0. 1. 2067 and earlier Version 13 builds. Public technical analysis and proof-of-concept exploit code became available on September 14, significantly increasing the risk that threat actors and post-exploitation operators will adopt the flaw in real-world intrusion chains. Hackers Exploit Veeam Agent Flaw The vulnerability exists in the Veeam Endpoint Backup service, which manages elevated client sessions over the local gRPC named pipe \\.\pipe\Veeam\VAW\ServiceConnectionPipe .
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been
CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access
ANY. RUN researchers investigated CSuite , a phishing and remote-access operation that combines credential theft, Microsoft 365 session hijacking, and the abuse of legitimate management tools. The campaign showed a strong US focus, with 60% of identified victim organizations based in the United States . By blending trusted business services with legitimate remote-access software, CSuite can give attackers both account and endpoint access while making malicious activity harder to distinguish from normal workflows. Discover how the operation works, which tools and techniques it relies on, and what SOC teams should watch to detect related activity earlier. TL;DR • CSuite is a multi-stage phishing and remote-access operation targeting organizations across the US and Europe.
Public PoC Exposes Critical Veeam Agent Privilege Escalation
A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you’re running Veeam Agent on a Windows endpoint with more than one local user, now’s the time to check the version, not tomorrow. On September 14, 2026, public technical details and a proof-of-concept exploit dropped for CVE-2026-32996. From that point on, the odds of active exploitation went up considerably, because once working code sits on GitHub, anyone can copy it and adapt it in an afternoon. Arctic Wolf already flagged this in a bulletin. “On September 14, 2026, public technical details and proof-of-concept (PoC) exploit code were released for CVE-2026-32996, increasing the likelihood of exploitation attempts against affected Veeam Agent for Microsoft Windows deployments.” warns Arctic Wolf.
PAYLOAD ransomware hijacks Windows Group Policy in encryption-less attacks
A PAYLOAD ransomware incident weaponized Microsoft Active Directory Group Policy to disrupt an organization’s Windows computers without deploying ransomware or encrypting files. Instead, the attackers used the company’s own administration infrastructure to display ransom notes, change wallpapers, deactivate local administrator accounts, and turn off Windows Firewall across the network. Kaspersky’s Global Emergency Response Team (GERT) … The post PAYLOAD ransomware hijacks Windows Group Policy in encryption-less attacks appeared first on CyberInsider .
New Windows Defender zero-day blocks Microsoft antivirus updates
Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. [... ]
8 Leading Authentication-as-a-Service (AaaS) Providers to Consider in 2026
Quick Answer: AaaS buying is stage-driven. Prototypes and Firebase-stack apps use Firebase Auth (free at startling scale); React/Next. js products ship fastest with Clerk’s components; fraud-exposed consumer apps choose Stytch; the enterprise-proof default remains Auth0 (Okta’s developer line); sovereignty and cost control at scale favor open-source Ory; Microsoft-committed teams use Entra External ID; web3-flavored logins use Magic; orchestrated enterprise journeys go to Ping. Passkeys are now the baseline expectation in every lane. Who This Guide Is For Founders deciding whether to build or buy login, engineering leads graduating from a framework’s built-in auth, and architects sizing per-MAU economics at scale.
Microsoft to retire Microsoft 365 Companion apps in December
Microsoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices. [... ]
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers
Microsoft fixes broken Excel copy and paste for all Office users
Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. [... ]
