Mirage2FA Phishing Campaign Compromises 4,500 Microsoft 365 Accounts
August 25, 2026 The Mirage2FA phishing campaign has compromised an estimated 4,500 organizations across the United States and European Union by abusing legitimate Microsoft 365 login flows and bypassing traditional two-factor authentication.…
Check Point Researchers Weaponize Microsoft Defender Remediation Driver for Kernel-Level Attacks
August 23, 2026 Check Point Research has disclosed a technique that weaponizes Microsoft Defender’s own signed boot-time remediation driver, BTR.sys, to execute arbitrary kernel-level file and registry operations on fully patched Windows systems.…
Lazarus Exploits Windows AFD.sys Zero-Day in Defense Sector Attacks
August 21, 2026 North Korean Lazarus hackers exploited CVE-2026-68820, a zero-day vulnerability in the Windows Ancillary Function Driver (AFD.sys), to deploy their FudModule rootkit and gain SYSTEM privileges on defense-sector targets. Microsoft patched…
Rust Supply Chain Attack on arrayref Crate
August 21, 2026 The Rust Security Response Team has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency. That dependency executed a…
ShieldBreak CVE Microsoft Defender Zero-Day
August 18, 2026 Microsoft confirmed it is actively working on a security patch for CVE-2026-69414, a zero-day vulnerability in Microsoft Defender publicly known as ShieldBreak. The flaw allows local attackers with limited permissions to escalate to…
Lazarus Exploits Windows Zero-Day to Deploy Troy Backdoor
August 17, 2026 The North Korean Lazarus Group has been caught exploiting a newly patched Windows zero-day vulnerability as part of its long-running Operation Dream Job campaign. The flaw, tracked as CVE-2026-68820, targets the Windows Ancillary Function…
Threema DDoS Attack Disrupts Secure Messaging Service
August 16, 2026 Large-scale distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service on August 12, 2026. Consequently, users experienced severe communication disruptions for several hours. Threema is a Swiss end-to-end…
Sable Squirrel Spends Million on Expired Domains for Malware
August 16, 2026 A threat actor tracked as Sable Squirrel has spent nearly $7 million acquiring expired domains to build a sprawling criminal enterprise. Consequently, the group operates illegal sports streaming platforms, online gambling promotions, and…
Head Mare Hacktivists Trojanize TrueConf Installers to Deploy PhantomCore and PhantomGraph Backdoors
August 10, 2026 The Head Mare hacktivist group has been exploiting unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions that deliver backdoors. Researchers at Kaspersky discovered the campaign in…
North Carolina Ports Cyberattack Disrupts Three Major Maritime Facilities
August 8, 2026 The North Carolina Ports Authority confirmed a cyberattack that forced a systems-wide outage across three major port facilities. The incident disrupted operations at the Port of Wilmington, the Port of Morehead City, and the Charlotte…