threat-intel Omarchy distro gains serious backing This article is a collection of security and technology news snippets from The Register. It covers a range of topics including a debate within the Debian Linux community regarding AI code, a Russian phishing campaign mimicking Signal support, Microsoft's ongoing SharePoint vulnerabilities, and acquisitions within the c… The Register · 3d ago Medium RUdebianransomwarephishing
threat-intel A Tale of Two SOCs: Insights From Two Red Team Assessments Two separate red team assessments at a Government Services and Facilities Sector organization (Organization A) and a Water and Wastewater Systems Sector organization (Organization B) revealed significant vulnerabilities… CISA Advisories · 5d ago High credential abuseactive directorymicrosoft
threat-intel Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows The Mirage2FA campaign, a commercial phishing-as-a-service toolkit, has impacted approximately 4,532 organizations, primarily in the US, by exploiting legitimate Microsoft 365 login flows and bypassing two-factor authent… The Hacker News · 5d ago High USINSGphishingmicrosoftmfa
threat-intel Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot Check Point Research has discovered a method to weaponize Microsoft Defender's own built-in boot-time remediation driver (BTR.sys) to delete security software and manipulate Windows systems. This technique, dubbed ‘BTR R… The Hacker News · Aug 21, 2026 High CVE-2021-24092driverbootremediation
threat-intel Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st) This script identifies users within an organization who have not yet been enrolled in multi-factor authentication (MFA) using the Microsoft Graph API. It leverages a beta command to efficiently list un-registered users,… SANS Internet Storm Center · Aug 21, 2026 Info mfamicrosoftgraph
vulnerability Vulnérabilité dans Microsoft Entra ID (21 août 2026) A critical vulnerability (CVE-2026-69836) has been identified in Microsoft Entra ID, allowing for remote code execution. While initially reported as actively exploited, Microsoft has clarified that it is currently not be… CERT-FR · Aug 21, 2026 Critical CVE-2026-69836entria idremote code executioncve
vulnerability Multiples vulnérabilités dans les produits Microsoft (21 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, allowing attackers to bypass security policies and cause denial-of-service conditions. Microsoft has released security bulletins detailing the issues a… CERT-FR · Aug 21, 2026 Medium CVE-2026-55013CVE-2026-55015microsoftvulnerabilitysecurity
vulnerability Vulnérabilité dans Microsoft Office (21 août 2026) A vulnerability has been discovered in Microsoft Office that could allow an attacker to compromise data confidentiality. Affected versions of Office, including Office 365 and Office 2019, require immediate patching to pr… CERT-FR · Aug 21, 2026 Medium CVE-2026-70105vulnerabilitymicrosoftpatch
vulnerability Multiples vulnérabilités dans Microsoft Edge (21 août 2026) Microsoft Edge is experiencing multiple vulnerabilities, as detailed in security advisories released by CERT-FR. These vulnerabilities could allow an attacker to trigger an unspecified security issue. Users of Microsoft… CERT-FR · Aug 21, 2026 Medium CVE-2026-76033CVE-2026-76034CVE-2026-76035vulnerabilitymicrosoftedge
threat-intel TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks Researchers have uncovered TWINLOOT, a sophisticated Python implant framework that leverages Microsoft services – specifically SharePoint Online and Teams TURN relays – to steal credentials and move laterally across netw… The Hacker News · Aug 18, 2026 High c2microsoftlateral movement
threat-intel Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic The Cavern C2 framework, used by Iranian nation-state hackers linked to the Ministry of Intelligence and Security (MOIS) and associated with groups like MuddyWater and OilRig (Lyceum), is undergoing continuous evolution.… The Hacker News · Aug 17, 2026 High IRc2dnsgoogle
vulnerability Multiples vulnérabilités dans les produits Microsoft (17 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, allowing attackers to execute arbitrary code remotely and elevate privileges. These issues primarily affect PowerShell versions, requiring immediate pa… CERT-FR · Aug 17, 2026 High CVE-2026-50523CVE-2026-69414microsoftpowershellvulnerability
vulnerability Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows A Microsoft-based hacker has developed a new zero-day vulnerability in on-prem SharePoint, allowing them to gain system privileges on fully patched Windows systems. This represents a significant security risk, as it bypa… The Register · Aug 12, 2026 High CVE-2026-50656CVE-2026-33825CVE-2026-41091zero-daysharepointvulnerability
vulnerability SharePoint Vulnerability Exploited Shortly After PoC Release A SharePoint vulnerability, patched last month, is now being actively exploited in the wild, with attackers leveraging a publicly released proof-of-concept. This follows a series of similar vulnerabilities discovered thi… SecurityWeek · Aug 12, 2026 High CVE-2026-55040CVE-2026-63520CVE-2026-50522sharepointvulnerabilityexploitation
vulnerability Multiples vulnérabilités dans Microsoft Edge (12 août 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, allowing an attacker to trigger arbitrary code execution and a security issue not specified by the vendor. These vulnerabilities are part of a larger set o… CERT-FR · Aug 12, 2026 High CVE-2026-19137CVE-2026-19138CVE-2026-19139vulnerabilitysecuritymicrosoft
vulnerability Multiples vulnérabilités dans Microsoft .Net (12 août 2026) Multiple vulnerabilities have been discovered in Microsoft .NET, allowing for remote code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect various versions of .NET Framework an… CERT-FR · Aug 12, 2026 High CVE-2026-58641CVE-2026-62871CVE-2026-62872vulnerabilityremote code executionprivilege escalation
vulnerability Multiples vulnérabilités dans Microsoft Azure (12 août 2026) Multiple vulnerabilities have been discovered within Microsoft Azure, potentially allowing an attacker to elevate privileges, compromise data confidentiality, and bypass security policies. These vulnerabilities affect va… CERT-FR · Aug 12, 2026 High CVE-2026-47299CVE-2026-57104CVE-2026-65806azurevulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Microsoft Office (12 août 2026) Multiple vulnerabilities have been discovered in Microsoft Office, some of which allow an attacker to trigger arbitrary code execution, privilege escalation, and data confidentiality breaches. These vulnerabilities are p… CERT-FR · Aug 12, 2026 High CVE-2026-58651CVE-2026-62842CVE-2026-62882vulnerabilitysecuritymicrosoft
threat-intel Multiples vulnérabilités dans les produits Microsoft (12 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, some of which allow an attacker to cause arbitrary code execution, privilege escalation, and a denial-of-service attack. These vulnerabilities span a w… CERT-FR · Aug 12, 2026 High CVE-2026-40375CVE-2026-47285CVE-2026-54123vulnerabilitysecuritymicrosoft
threat-intel Microsoft's Patch Tuesday Deluge Continues With August Updates Microsoft released a substantial security update this month, addressing 421 unique CVEs, including two zero-day vulnerabilities. A significant portion of these – 236 affecting Windows and 98 affecting Office – require im… Dark Reading · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-62878patch-tuesdayvulnerabilityzero-day