Ticker feed
A sophisticated phishing campaign has been hijacking Microsoft 365 accounts since May 2026 — and it can defeat MFA protections entirely. Attackers pose as IT support via phone or text, claiming a passkey or sign-on setting needs attention, then direct victims to fake Microsoft login pages. From there, they capture credentials and session tokens, or trick users into approving device-code sign-ins that hand over cloud access.
Once inside, attackers quietly map the organization using Microsoft Graph, then download files from SharePoint, OneDrive, and Exchange — often staying below 1 000 items per hour to avoid detection. A password reset alone won't remove them if rogue authentication methods remain active. Microsoft recommends revoking sessions, removing unauthorized MFA methods, and requiring phishing-resistant authentication going forward.
Source: Cyber Security News
A sophisticated phishing campaign has been hijacking Microsoft 365 accounts since May 2026 — and it can defeat MFA protections entirely. Attackers pose as IT support via phone or text, claiming a passkey or sign-on setting needs attention, then direct victims to fake Microsoft login pages. From there, they capture credentials and session tokens, or trick users into approving device-code sign-ins that hand over cloud access.
Once inside, attackers quietly map the organization using Microsoft Graph, then download files from SharePoint, OneDrive, and Exchange — often staying below 1 000 items per hour to avoid detection. A password reset alone won't remove them if rogue authentication methods remain active. Microsoft recommends revoking sessions, removing unauthorized MFA methods, and requiring phishing-resistant authentication going forward.
Source: Cyber Security News
A new exploit kit called BlueMoon is letting espionage groups chain Chrome and Windows flaws to plant backdoors on government, defense, and commercial targets. Proofpoint counted four clusters using it since late August 2026, most suspected of a China nexus, though some use is unattributed and the kit may not be exclusive to Chinese actors.
The chain runs a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491), and a Windows kernel privilege escalation (CVE-2026-85880). Both Chrome flaws were patch-gap zero-days, fixed in public Chromium source but missing from stable releases. That gap has since closed, with the V8 fix reaching stable Chromium on September 3.
Exposure is narrower than it sounds. The privilege escalation only fires on older Windows builds, which Proofpoint says substantially cuts the pool of viable targets, and successful exploitation ends in a plain curl command that leaves endpoint tools plenty to catch. Circumstantial signs point to AI-assisted development, including verbose debugging comments and a markdown handover file of the kind coding agents leave behind.
TA412, also known as APT31, posed as students seeking internships and conference organizers to reach US NGOs, mining firms, and commodity traders, then installed a surveillance extension disguised as Google Gemini across Chrome, Edge, Brave, and Vivaldi. How four groups obtained the same kit is unknown. Proofpoint expects the technique to reach financially motivated actors too.
Source: Cybersecurity News
A new exploit kit called BlueMoon is letting espionage groups chain Chrome and Windows flaws to plant backdoors on government, defense, and commercial targets. Proofpoint counted four clusters using it since late August 2026, most suspected of a China nexus, though some use is unattributed and the kit may not be exclusive to Chinese actors.
The chain runs a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491), and a Windows kernel privilege escalation (CVE-2026-85880). Both Chrome flaws were patch-gap zero-days, fixed in public Chromium source but missing from stable releases. That gap has since closed, with the V8 fix reaching stable Chromium on September 3.
Exposure is narrower than it sounds. The privilege escalation only fires on older Windows builds, which Proofpoint says substantially cuts the pool of viable targets, and successful exploitation ends in a plain curl command that leaves endpoint tools plenty to catch. Circumstantial signs point to AI-assisted development, including verbose debugging comments and a markdown handover file of the kind coding agents leave behind.
TA412, also known as APT31, posed as students seeking internships and conference organizers to reach US NGOs, mining firms, and commodity traders, then installed a surveillance extension disguised as Google Gemini across Chrome, Edge, Brave, and Vivaldi. How four groups obtained the same kit is unknown. Proofpoint expects the technique to reach financially motivated actors too.
Source: Cybersecurity News
KnowBe4 published research on September 4 into a phishing campaign still running in the wild, and the trick sits in the link. Rather than hide a malicious URL and hope the gateway misses it, the operators built a three-hop redirect chain from Google's own services, so every hop an inspector checks resolves to a domain it already trusts.
The services named include Google Meet, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics. What waits at the end varies: some victims get a fake corporate login page, others a fake identity verification prompt that quietly installs ScreenConnect for remote access.
The login page is the more inventive half. JavaScript builds it on the fly from the victim's email address alone, sets a live screenshot of their real corporate website behind it, and localizes the interface to their location. Credentials reach the operator's Telegram channel within seconds, along with the victim's IP, geolocation, browser string, and their organization's verified MX records.
KnowBe4 wants the IOCs blocked at DNS filter, proxy, and SIEM level now, Telegram bot API traffic hunted, unauthorized ScreenConnect installs checked, and credential resets forced for anyone who may have received a lure. An email address after the # in a URL signals a pre-targeted link, though it is base64-encoded, so nobody will spot one by eye.
Source: Dark Reading
KnowBe4 published research on September 4 into a phishing campaign still running in the wild, and the trick sits in the link. Rather than hide a malicious URL and hope the gateway misses it, the operators built a three-hop redirect chain from Google's own services, so every hop an inspector checks resolves to a domain it already trusts.
The services named include Google Meet, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics. What waits at the end varies: some victims get a fake corporate login page, others a fake identity verification prompt that quietly installs ScreenConnect for remote access.
The login page is the more inventive half. JavaScript builds it on the fly from the victim's email address alone, sets a live screenshot of their real corporate website behind it, and localizes the interface to their location. Credentials reach the operator's Telegram channel within seconds, along with the victim's IP, geolocation, browser string, and their organization's verified MX records.
KnowBe4 wants the IOCs blocked at DNS filter, proxy, and SIEM level now, Telegram bot API traffic hunted, unauthorized ScreenConnect installs checked, and credential resets forced for anyone who may have received a lure. An email address after the # in a URL signals a pre-targeted link, though it is base64-encoded, so nobody will spot one by eye.
Source: Dark Reading
Everett City Hall has been closed to the public since Tuesday, September 8, after the city discovered a cybersecurity incident on its internal network on Sunday night. Officials still haven't said what kind of incident it was or how far it reached, and the doors stay shut through Thursday, September 10.
Business has moved rather than stopped. Nine departments, from the Treasurer to Inspectional Services, are operating out of the Connolly Center from 9 to 5 on both closure days, with 311 taking questions. Police, fire, public works, schools, and libraries are unaffected.
Online bill payments also still work, though only because they run on third-party systems rather than the city's own network. What Everett hosts internally is what went down, and Mayor Robert J. Van Campen says IT staff and investigators are working around the clock to restore it.
Everett is at least the second Massachusetts case this week, after Springfield Public Schools canceled classes Tuesday. Cynthia Kaiser, formerly of the FBI's Cyber Division, says local government makes an easy mark because agencies each run thin IT teams, and that patching a known flaw is an emergency, not maintenance
Source: CBS News Boston
Everett City Hall has been closed to the public since Tuesday, September 8, after the city discovered a cybersecurity incident on its internal network on Sunday night. Officials still haven't said what kind of incident it was or how far it reached, and the doors stay shut through Thursday, September 10.
Business has moved rather than stopped. Nine departments, from the Treasurer to Inspectional Services, are operating out of the Connolly Center from 9 to 5 on both closure days, with 311 taking questions. Police, fire, public works, schools, and libraries are unaffected.
Online bill payments also still work, though only because they run on third-party systems rather than the city's own network. What Everett hosts internally is what went down, and Mayor Robert J. Van Campen says IT staff and investigators are working around the clock to restore it.
Everett is at least the second Massachusetts case this week, after Springfield Public Schools canceled classes Tuesday. Cynthia Kaiser, formerly of the FBI's Cyber Division, says local government makes an easy mark because agencies each run thin IT teams, and that patching a known flaw is an emergency, not maintenance
Source: CBS News Boston
North Korea's Kimsuky group turned to opencode, an open-source AI coding agent, to mass-produce the decoy documents behind its latest phishing run. Speed came at the cost of care. Genians counted placeholder text for payment dates, grace periods, and interest rates surviving into the files that shipped, nine times over, which is what gave the tool away.
What reaches the inbox is handled far more carefully. Genians examined 13 shortcut files sent in ZIP archives between August 11 and 19, 2026, aimed at Korean financial and corporate staff, each wearing a Chrome icon over a forged "Hangul Document" property. Open one and PowerShell runs behind 5,800 to 9,500 characters of arguments, held out of sight by roughly 300 leading spaces.
From there the loader reaches GitHub Raw with a hardcoded access token, then registers a hidden scheduled task misspelled to pass for BitLocker, MATLAB, or .NET before deleting itself. Three samples never fetch a decoy and open a 16-byte error file instead, which looks like a failed attack. Persistence and payload retrieval run anyway.
That is why document quality settles nothing. Genians points defenders at the shortcut itself: a chrome.exe icon over a PowerShell target, randomly named scripts written into AppData and executed on the spot, and scheduled tasks carrying slight misspellings or long strings of digits.
Source: Cyber Security News
North Korea's Kimsuky group turned to opencode, an open-source AI coding agent, to mass-produce the decoy documents behind its latest phishing run. Speed came at the cost of care. Genians counted placeholder text for payment dates, grace periods, and interest rates surviving into the files that shipped, nine times over, which is what gave the tool away.
What reaches the inbox is handled far more carefully. Genians examined 13 shortcut files sent in ZIP archives between August 11 and 19, 2026, aimed at Korean financial and corporate staff, each wearing a Chrome icon over a forged "Hangul Document" property. Open one and PowerShell runs behind 5,800 to 9,500 characters of arguments, held out of sight by roughly 300 leading spaces.
From there the loader reaches GitHub Raw with a hardcoded access token, then registers a hidden scheduled task misspelled to pass for BitLocker, MATLAB, or .NET before deleting itself. Three samples never fetch a decoy and open a 16-byte error file instead, which looks like a failed attack. Persistence and payload retrieval run anyway.
That is why document quality settles nothing. Genians points defenders at the shortcut itself: a chrome.exe icon over a PowerShell target, randomly named scripts written into AppData and executed on the spot, and scheduled tasks carrying slight misspellings or long strings of digits.
Source: Cyber Security News
A dark web identity theft service called Nexus began selling digital scans of more than 153 million US and Canadian driver's licenses in the week of August 31, 2026, most of them American. The FBI's New Orleans field office opened an investigation on September 1, and the site went dark hours later.
Investigative journalist Brian Krebs found his own license listed, then asked more than a dozen friends and family for permission to search. All nine he found confirmed traveling on or near the timestamps attached to their images. The common thread was Hertz car rentals, plus a Las Vegas dispensary in one case.
Both point to IDScan.net, a Louisiana identity verification firm that lists Hertz as a client and holds an exclusive agreement with that dispensary chain. IDScan scans IDs with infrared and ultraviolet light, and the Nexus records include infrared and ultraviolet versions of each license.
IDScan.net says it is investigating and has issued no statement. Nexus operators claim a year of continuous exfiltration, and the license count grew by nearly 400,000 in a single day. Licenses for Defense Secretary Pete Hegseth and the FBI's assistant director were among those listed.
NCC Group's Tim Rawlins says organizations should design identity systems assuming that identity evidence will eventually be compromised, and should hold identity vendors to contract terms covering retention, incident notification, and independent assurance.
Source: SecurityWeek
A dark web identity theft service called Nexus began selling digital scans of more than 153 million US and Canadian driver's licenses in the week of August 31, 2026, most of them American. The FBI's New Orleans field office opened an investigation on September 1, and the site went dark hours later.
Investigative journalist Brian Krebs found his own license listed, then asked more than a dozen friends and family for permission to search. All nine he found confirmed traveling on or near the timestamps attached to their images. The common thread was Hertz car rentals, plus a Las Vegas dispensary in one case.
Both point to IDScan.net, a Louisiana identity verification firm that lists Hertz as a client and holds an exclusive agreement with that dispensary chain. IDScan scans IDs with infrared and ultraviolet light, and the Nexus records include infrared and ultraviolet versions of each license.
IDScan.net says it is investigating and has issued no statement. Nexus operators claim a year of continuous exfiltration, and the license count grew by nearly 400,000 in a single day. Licenses for Defense Secretary Pete Hegseth and the FBI's assistant director were among those listed.
NCC Group's Tim Rawlins says organizations should design identity systems assuming that identity evidence will eventually be compromised, and should hold identity vendors to contract terms covering retention, incident notification, and independent assurance.
Source: SecurityWeek
A critical zero-day called StyleSmuggler is being actively exploited against Magento Open Source stores, giving unauthenticated attackers remote code execution. Dutch security firm Sansec, which disclosed the flaw on September 5, 2026, says every current version of Magento and Adobe Commerce is affected. It published early because stores were already being compromised.
Sansec reproduced the attack chain on clean 2.4.7, 2.4.8, and 2.4.9 installations, and the first identified victim ran 2.4.6-p15 with July and August 2026 patches applied. The exploit abuses Magento's own template and email systems, dropping a Rust implant disguised as a Linux kernel thread.
Adobe has issued no advisory, CVE, or fix. Its next scheduled security release is September 8, though Sansec says there is no confirmation it covers this bug. Until then, store owners are on stopgaps.
Disrex, ProxiBlue, and Graycore have each published unofficial patches guarding specific Magento classes. Disrex says its own patch is verified against 2.4.6 through 2.4.9. Sansec recommends temporarily disabling GraphQL, which classic and Hyvä themes generally don't need, unlike headless and progressive web app storefronts.
The layer that doesn't depend on knowing the exploit is server-level. Disable PHP's exec functions, proc_open included, since a list blocking five of the six stops nothing, and mount temporary directories with noexec. Check both var/report and var/log/system.log too, since Sansec's published check looks only at the first
Source: Cybersecurity News
A critical zero-day called StyleSmuggler is being actively exploited against Magento Open Source stores, giving unauthenticated attackers remote code execution. Dutch security firm Sansec, which disclosed the flaw on September 5, 2026, says every current version of Magento and Adobe Commerce is affected. It published early because stores were already being compromised.
Sansec reproduced the attack chain on clean 2.4.7, 2.4.8, and 2.4.9 installations, and the first identified victim ran 2.4.6-p15 with July and August 2026 patches applied. The exploit abuses Magento's own template and email systems, dropping a Rust implant disguised as a Linux kernel thread.
Adobe has issued no advisory, CVE, or fix. Its next scheduled security release is September 8, though Sansec says there is no confirmation it covers this bug. Until then, store owners are on stopgaps.
Disrex, ProxiBlue, and Graycore have each published unofficial patches guarding specific Magento classes. Disrex says its own patch is verified against 2.4.6 through 2.4.9. Sansec recommends temporarily disabling GraphQL, which classic and Hyvä themes generally don't need, unlike headless and progressive web app storefronts.
The layer that doesn't depend on knowing the exploit is server-level. Disable PHP's exec functions, proc_open included, since a list blocking five of the six stops nothing, and mount temporary directories with noexec. Check both var/report and var/log/system.log too, since Sansec's published check looks only at the first
Source: Cybersecurity News
McKesson, one of North America's largest pharmaceutical distributors with $403.4 billion in annual revenue, disclosed a cyberattack on August 28, 2026, three days after discovering it. Unauthorized access to certain third-party applications led to data theft affecting a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units, the company says.
ShinyHunters claimed responsibility, though McKesson has not named the group. It says it used voice phishing to compromise employees' Okta single sign-on accounts, then reached the Salesforce and Snowflake environments and exfiltrated data between August 21 and August 25, claiming roughly 284 million records and demanding over $55 million.
That figure counts database rows rather than patients, and the group has not fully analyzed the data. None of its claims are independently verified. A September 1 deadline to open negotiations passed without a response from the company, which has declined to comment on the demand.
Its distribution centers remain operational, McKesson says, though it warned customers to expect intermittent service degradation. Health-ISAC had warned the healthcare sector about ShinyHunters just weeks before the breach.
Source: CyberScoop
McKesson, one of North America's largest pharmaceutical distributors with $403.4 billion in annual revenue, disclosed a cyberattack on August 28, 2026, three days after discovering it. Unauthorized access to certain third-party applications led to data theft affecting a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units, the company says.
ShinyHunters claimed responsibility, though McKesson has not named the group. It says it used voice phishing to compromise employees' Okta single sign-on accounts, then reached the Salesforce and Snowflake environments and exfiltrated data between August 21 and August 25, claiming roughly 284 million records and demanding over $55 million.
That figure counts database rows rather than patients, and the group has not fully analyzed the data. None of its claims are independently verified. A September 1 deadline to open negotiations passed without a response from the company, which has declined to comment on the demand.
Its distribution centers remain operational, McKesson says, though it warned customers to expect intermittent service degradation. Health-ISAC had warned the healthcare sector about ShinyHunters just weeks before the breach.
Source: CyberScoop
SonicWall confirmed on Tuesday, September 1, that attackers are actively exploiting two zero-days in its SMA 1000 remote-access appliances. CVE-2026-83548 (SSRF, CVSS 10.0) hits the user-facing Workplace portal; CVE-2026-83549 (OS command injection, CVSS 7.8) sits behind the admin console. Chained, the first supplies the authentication the second needs — unauthenticated remote code execution.
Models 6210, 7210, and 8200v are affected on 12.4.3-03453 or 12.5.0-02835 and older. Upgrade to 12.4.3-03526 or 12.5.0-02952. Patching isn't the end of it: SonicWall says compromised appliances need re-imaging or redeployment, every user and admin password changed, and TOTP tokens reset.
There is little to check against, though: Rapid7 found no public proof-of-concept, no published indicators of compromise, and no attribution — so a verdict runs through SonicWall's support team rather than a threat feed.
This is the second such pair on the SMA 1000 in two months. July's CVE-2026-15409 was the same shape — pre-auth SSRF plus post-auth command injection — and CISA later flagged it as used in ransomware campaigns. NHS England rates further exploitation as almost certain.
Source: Dark Reading
SonicWall confirmed on Tuesday, September 1, that attackers are actively exploiting two zero-days in its SMA 1000 remote-access appliances. CVE-2026-83548 (SSRF, CVSS 10.0) hits the user-facing Workplace portal; CVE-2026-83549 (OS command injection, CVSS 7.8) sits behind the admin console. Chained, the first supplies the authentication the second needs — unauthenticated remote code execution.
Models 6210, 7210, and 8200v are affected on 12.4.3-03453 or 12.5.0-02835 and older. Upgrade to 12.4.3-03526 or 12.5.0-02952. Patching isn't the end of it: SonicWall says compromised appliances need re-imaging or redeployment, every user and admin password changed, and TOTP tokens reset.
There is little to check against, though: Rapid7 found no public proof-of-concept, no published indicators of compromise, and no attribution — so a verdict runs through SonicWall's support team rather than a threat feed.
This is the second such pair on the SMA 1000 in two months. July's CVE-2026-15409 was the same shape — pre-auth SSRF plus post-auth command injection — and CISA later flagged it as used in ransomware campaigns. NHS England rates further exploitation as almost certain.
Source: Dark Reading
The Minnesota Supreme Court, Court of Appeals, Tax Court, and Court of Administrative Hearings all had user data compromised in a breach at their vendor, Thomson Reuters Court Management Solutions. Attackers were inside the C-Track case management platform from March 1 until June 29, and Thomson Reuters only discovered the intrusion on June 30.
The exposed backup data may include names alongside Social Security numbers, driver's license numbers, dates of birth, medical information and health insurance details. Case documents such as orders and briefs were not affected, and Minnesota courts are operating normally. Chief Justice Natalie Hudson called the compromise deeply troubling.
Minnesota's judicial branch has cut Thomson Reuters' access to court information. Every Minnesota C-Track user has to reset their password — old credentials will lock the account — and affected individuals are being offered 12 months of credit monitoring.
This reaches well past Minnesota. Courts in at least eleven other states, the U.S. Virgin Islands and Ontario, Canada were caught in the same intrusion, which Thomson Reuters says happened inside its own environment rather than the courts' systems. Investigators are still working out what was taken.
Source: CBS News Minnesota
The Minnesota Supreme Court, Court of Appeals, Tax Court, and Court of Administrative Hearings all had user data compromised in a breach at their vendor, Thomson Reuters Court Management Solutions. Attackers were inside the C-Track case management platform from March 1 until June 29, and Thomson Reuters only discovered the intrusion on June 30.
The exposed backup data may include names alongside Social Security numbers, driver's license numbers, dates of birth, medical information and health insurance details. Case documents such as orders and briefs were not affected, and Minnesota courts are operating normally. Chief Justice Natalie Hudson called the compromise deeply troubling.
Minnesota's judicial branch has cut Thomson Reuters' access to court information. Every Minnesota C-Track user has to reset their password — old credentials will lock the account — and affected individuals are being offered 12 months of credit monitoring.
This reaches well past Minnesota. Courts in at least eleven other states, the U.S. Virgin Islands and Ontario, Canada were caught in the same intrusion, which Thomson Reuters says happened inside its own environment rather than the courts' systems. Investigators are still working out what was taken.
Source: CBS News Minnesota