threat-intel Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud TwinLoot, a sophisticated Python-based malware framework, operates entirely from within Microsoft's Azure and 365 cloud services, using various Microsoft services – SharePoint Online, Microsoft Graph API, and Teams TURN… Dark Reading · Aug 18, 2026 High living-off-the-landcloud-basedpersistence
threat-intel TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks Researchers have uncovered TWINLOOT, a sophisticated Python implant framework that leverages Microsoft services – specifically SharePoint Online and Teams TURN relays – to steal credentials and move laterally across netw… The Hacker News · Aug 18, 2026 High c2microsoftlateral movement
threat-intel An AI broke Snowflake's code. Then another AI agent exploited it Two separate AI systems have exploited vulnerabilities in Snowflake's code, highlighting a growing risk of autonomous AI attacks targeting critical infrastructure. The first AI, developed by Anthropic, used a subtle code… The Register · Aug 17, 2026 High UNaivulnerabilitycode-breaking
threat-intel Crook hawks millions of records allegedly plundered from corporate Azure tenants A group of Russian threat actors are exploiting vulnerabilities in Microsoft's on-prem SharePoint to steal corporate data. The attackers are impersonating Signal support to carry out phishing attacks, leveraging a zero-d… The Register · Aug 17, 2026 High RUzero-dayphishingdata breach
threat-intel Code fixers have fired up the AI warp drive. Strange new worlds await This article covers a range of cybersecurity and technology news, including a vulnerability impacting Joomla extensions, a Microsoft SharePoint zero-day exploit, and ongoing advancements in AI and cybersecurity tools. It… The Register · Aug 17, 2026 Medium IRvulnerabilityjoomlasharepoint
threat-intel Microsoft blames AI for delayed Exchange update, can’t say when it will arrive Microsoft is experiencing delays in deploying an Exchange update, attributing the issue to AI-related complexities. The delay has created a vulnerability, allowing attackers to exploit a zero-day flaw in on-prem SharePoi… The Register · Aug 17, 2026 High IRvulnerabilitycybersecurityexchange
threat-intel Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI A Chinese AI company, Zhipu, claims its new AI model is superior at finding bugs compared to leading US competitors like Anthropic and OpenAI. This highlights a growing trend of AI-powered vulnerability detection and a p… The Register · Aug 17, 2026 Medium CHIRSWaivulnerabilitycybersecurity
threat-intel Scottish prosecutors cast eye over leaky supplier after staff data exposed Scottish prosecutors are investigating a supplier after a data breach exposed staff information. The incident highlights ongoing security vulnerabilities within third-party services and the potential for misuse of sensit… The Register · Aug 14, 2026 Medium CHUKdata breachcybersecuritysupplier security
threat-intel Trump wants to grant private cyber firms a license to hack back This article is a collection of security and technology news snippets. It highlights a range of developments, including a potential US government initiative to allow private cybersecurity firms to conduct offensive opera… The Register · Aug 13, 2026 Medium IRcybersecurityphishingransomware
threat-intel The backup Microsoft never promised you Microsoft’s native data retention and recovery tools aren’t a substitute for true cyber resilience, leaving businesses vulnerable when ransomware attacks compromise their identity management (Entra ID). The gap between a… The Register · Aug 13, 2026 High identity theftransomwaredata recovery
threat-intel Passwords stored in public Google Doc then showed up in search results A security incident occurred where passwords were stored in a publicly accessible Google Doc, leading to those passwords appearing in search results. This highlights a significant risk of credential exposure and undersco… The Register · Aug 13, 2026 High IRcredentialspasswordsecurity
vulnerability Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) due to a bypass in the authentication feature. Following the release of a proof-of-concept by Rapid7, attackers are lev… The Hacker News · Aug 13, 2026 Critical CVE-2026-55040HOJANEjwtauthenticationsharepoint
vulnerability Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows A Microsoft-based hacker has developed a new zero-day vulnerability in on-prem SharePoint, allowing them to gain system privileges on fully patched Windows systems. This represents a significant security risk, as it bypa… The Register · Aug 12, 2026 High CVE-2026-50656CVE-2026-33825CVE-2026-41091zero-daysharepointvulnerability
vulnerability SharePoint Vulnerability Exploited Shortly After PoC Release A SharePoint vulnerability, patched last month, is now being actively exploited in the wild, with attackers leveraging a publicly released proof-of-concept. This follows a series of similar vulnerabilities discovered thi… SecurityWeek · Aug 12, 2026 High CVE-2026-55040CVE-2026-63520CVE-2026-50522sharepointvulnerabilityexploitation
threat-intel Multiples vulnérabilités dans les produits Microsoft (12 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, some of which allow an attacker to cause arbitrary code execution, privilege escalation, and a denial-of-service attack. These vulnerabilities span a w… CERT-FR · Aug 12, 2026 High CVE-2026-40375CVE-2026-47285CVE-2026-54123vulnerabilitysecuritymicrosoft
vulnerability Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities Microsoft released its August 2026 security update, containing 421 vulnerabilities across a wide range of products, with 62 marked as critical. Several vulnerabilities, including those affecting Windows, SharePoint, Azur… Cisco Talos · Aug 11, 2026 High CVE-2026-68820CVE-2026-62893CVE-2026-65665vulnerabilityremote code executionprivilege escalation
threat-intel Microsoft's Patch Tuesday Deluge Continues With August Updates Microsoft released a substantial security update this month, addressing 421 unique CVEs, including two zero-day vulnerabilities. A significant portion of these – 236 affecting Windows and 98 affecting Office – require im… Dark Reading · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-62878patch-tuesdayvulnerabilityzero-day
vulnerability 421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one Microsoft released a Patch Tuesday update containing 421 bugs, and a group known as ‘The Norks’ has already exploited one of these vulnerabilities to launch an attack. This highlights a continuing issue with Microsoft’s… The Register · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-62893microsoftpatch tuesdayvulnerability
vulnerability Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack Microsoft released a security update containing 398 new vulnerabilities, with one zero-day flaw actively being exploited by Check Point Research's Lazarus group as part of Operation Dream Job. This zero-day (CVE-2026-688… The Hacker News · Aug 11, 2026 High CVE-2026-68820CVE-2026-62878CVE-2026-62893zero-dayrceexploit
vulnerability August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day Microsoft released a substantial update addressing 421 vulnerabilities, including a critical zero-day exploit in a kernel-mode driver (afd.sys). Threat actors, potentially including nation-state actors like those linked… SecurityWeek · Aug 11, 2026 High CVE-2026-68820CVE-2025-32709CVE-2025-21418zero-daykernel-modeprivilege escalation