Microsoft has detailed a Microsoft 365 passkey phishing campaign active since May 2026, in which threat actors impersonate corporate IT help desks to trick employees into handing over session tokens and credentials, with ShinyHunters, Helix, and related extortion groups identified as participants.The attacks begin well before any phone call or message is sent. According to Microsoft, the actors invest heavily in pre-attack research, gathering information about employees and organisational structure from public sources such as social networking and professional profiling platforms. Once they have enough to sound plausible, they contact targets directly (by phone or message) claiming that a passkey,…
Author: Gary Behan
A string of AI platform malware attacks is turning the features users rely on every day (shareable conversations, public mini-apps, sponsored search results) into delivery mechanisms for infostealers and remote-access trojans. The Huntress Security Operations Center has tracked incidents over the past nine months in which attackers weaponised Claude Artifacts, shareable chatgpt.com and grok.com URLs, and SEO poisoning to reach victims who had every reason to trust what they were looking at.None of these campaigns cracked the AI platforms themselves. The whole point is that they did not need to.How AI Platform Malware Attacks Are ConstructedThree distinct techniques have emerged.…
GitLab has urged all self-managed server operators to apply patches immediately after disclosing a maximum-severity GitLab path traversal flaw tracked as CVE-2026-85706, a vulnerability that allows unauthenticated attackers to read arbitrary files from vulnerable servers under certain conditions. The flaw was reported through GitLab’s HackerOne bug bounty programme by a security researcher using the handle ‘s3ntago’, and stems from improper path confinement combined with missing authentication enforcement in the repository commits API.According to GitLab Official Documentation, the vulnerability affects all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. That is a broad swath of the self-managed…
The Trezor Brevo phishing attack that unfolded on 9 September 2026 reached 347,000 email addresses, with 2,500 users clicking a malicious link before Trezor pulled the domain down, the company has confirmed. What made the campaign particularly nasty is that the emails did not need to spoof anything: as BetaNews reports, the messages passed through Brevo’s own systems under Trezor’s account, so they sailed straight through the email authentication checks that normally flag a dodgy sender.How the Trezor Brevo phishing attack was carried outTrezor uses Brevo as its third-party marketing platform for newsletter campaigns. According to SecurityWeek, Brevo has confirmed…
Mantax Otax Android malware is a newly identified strain that combines ransomware, spyware, remote control, and outright harassment into a single package, a combination that makes it considerably nastier than your average mobile threat. Indonesian operators are distributing it through malicious APKs hosted outside Google Play, using phishing and social engineering messages to reach victims.Once installed, the malware requests Accessibility service permissions, which hand it sweeping control over a compromised device. From there, it retrieves its command-and-control (C2) domain from GitHub and phones home with victim details: location, carrier, Android version, and device ID. The C2 can then push commands…
A PaperCut AI exploitation campaign linked to a likely Russian-speaking threat actor has compromised at least 440 PaperCut NG/MF instances across 395 distinct organisations in 48 countries, according to attack and threat intelligence company GreyNoise. The operation used hundreds of AI agents to build, test, and refine exploits, and managed to compromise at least 11 organisations in 26 seconds once it reached full operational tempo.The two vulnerabilities at the heart of the attack, CVE-2026-81578 and CVE-2026-82078, both affect PaperCut Software and had been flagged as actively exploited earlier in September 2026. According to Arctic Wolf, multiple security firms detected initial…
Microsoft has confirmed that the Windows 11 mouse settings reset triggered by the KB5120998 August 2026 preview update is now resolved, with the fix delivered via the KB5124008 cumulative update released on 8 September 2026. The original problem surfaced after users installed KB5120998 on 27 August 2026, an optional preview update carrying Start menu, taskbar, and Windows Search improvements for devices running Windows 11 versions 24H2 and 25H2. Almost immediately, reports came in that cursor and cursor-animation settings selected under Mouse Properties were reverting without warning, and refusing to stick even after manual attempts to restore them. What caused the…
Ransomware gangs are now confirmed to be exploiting a critical vulnerability in WatchGuard Firebox firewalls, with WatchGuard Firebox ransomware attacks formally acknowledged in the latest update to the US Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalogue. The flaw in question, tracked as CVE-2025-14733, has been circulating in the wild since at least December, but Thursday’s catalogue update makes the ransomware connection official.CVE-2025-14733 stems from an out-of-bounds write in WatchGuard’s Fireware operating system. Unauthenticated attackers can use it to execute malicious code remotely, and the attack complexity is rated low, the kind of combination that tends to…
Cisco has confirmed that CVE-2026-20079 is actively exploited in the wild, a maximum-severity authentication bypass flaw in its Secure Firewall Management Center (FMC) software carrying a CVSS score of 10.0. The admission, quiet as it was, matters: Cisco first disclosed the vulnerability in March and said at the time it had no evidence of exploitation.The flaw allows unauthenticated, remote attackers to bypass authentication entirely and execute scripts and commands as root on vulnerable devices. It is caused by an improper system process created at boot time, and can be triggered by sending crafted HTTP requests to the web interface of…
A joint advisory from US agencies has formally accused six Chinese AI firms of conducting Chinese AI distillation attacks on American frontier models at industrial scale, extracting billions of tokens through millions of API requests from models belonging to Anthropic, OpenAI, Google, and xAI. The advisory, numbered CISA AA26-251A and co-signed by the NSA and FBI, identifies the offending firms as DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.The agencies assess that the scale and sophistication of the operations indicate Chinese government awareness, and describe this approach as likely a core development strategy for the firms involved. The operations are…
