Microsoft disrupted EvilTokens after it was linked to more than 12,000 compromised inboxes across over 10,000 organizations.
AI agents can chain credentials and tools to reach beyond direct permissions, as a Hugging Face evaluation showed.
Bifrost CVE-2026-90898 enables unauthenticated command execution with management auth disabled; transports/v2.1.0 fixes the flaw.
BigDiskBuster can block Microsoft Defender updates by filling disk space, leaving detection content stale; no patch or advisory exists.
Attackers are exploiting CVE-2026-93952 in certificate-authenticated VeloCloud Orchestrators, with some release trains still awaiting fixes.
SharePoint CVE-2026-65660 enables authenticated RCE; Microsoft patched it on August 11, and no in-the-wild exploitation is reported.
A Linux KVM flaw on ARM64 can expose host kernel memory to guests and enable guest-to-host escape when nested virtualization is enabled.
A Mac Muse flaw lets malware running as the logged-in user reroute dictation, inject instructions, and steal the assistant's session token.
CISA added Zyxel CVE-2026-7273 to KEV after active exploitation, while Arctic Wolf reported attacks on a Veeam Windows flaw.
SideCopy targets Indian academic institutions with spear-phishing that abuses mshta.exe to deploy ReverseRAT for collection and remote access.
WordPress fixed a comment flaw that could lead to server code execution if a logged-in administrator opened the page.
DORA’s second year shifts focus to proving ICT controls work, with network evidence supporting monitoring, detection, and incident response.