Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
24 / 195 results
highperson_alertThreat ActorChaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsers
Chaos is a ransomware group that operates through spam floods, vishing campaigns, Quick Assist abuse, and RMM tools for initial access and persistence. The group deploys custom tooling including the msaRAT Rust-based implant as a pre-ransomware stage…
highperson_alertThreat ActorChaos ransomware gang deploys msaRAT backdoor via browser hijacking
Chaos is a ransomware gang that emerged in early 2025, distinct from the earlier same-named ransomware family active since 2021. The group has been linked to Iranian state-backed threat actor MuddyWater, who reportedly leveraged Chaos ransomware to d…
criticalbug_reportVulnerabilityMicrosoft July 2026 Patch Tuesday: 569 vulnerabilities, 56 critical
Microsoft product portfolio (specific products and versions not disclosed in available data). 569 total vulnerabilities patched, including 56 rated critical severity.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE flaws actively exploited; immediate patching required
Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Five critical vulnerabilities: CVE-2026-50522 (CVSS 9.8, deserialization RCE), CVE-2026-58644 (CVSS 9.8, unauthenticated RCE), CVE-2026-5…
highperson_alertThreat ActorKratos Phishing Kit Dismantled After Stealing Microsoft 365 Sessions
The Kratos operator is an Indonesian individual arrested by local authorities for allegedly developing and operating the Kratos phishing-as-a-service (PhaaS) platform.
highbug_reportVulnerabilityAzure DevOps MCP server flaw lets hidden PR comments hijack AI agents
Microsoft Azure DevOps MCP server versions up to and including v2.8.0 (released June 24, 2026). The flaw affects the repo_get_pull_request_by_id tool, which returns pull request descriptions without prompt-injection guardrails.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE CVE-2026-50522 actively exploited for persistence
Microsoft SharePoint Server (specific versions not provided). Vulnerability enables remote code execution with machine key theft capability, allowing persistent access beyond patch deployment.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE (CVE-2026-50522) actively exploited after PoC
Microsoft SharePoint Server (all versions prior to July 2026 patches). Vulnerability involves deserialization of untrusted data leading to unauthenticated remote code execution. CVSS 9.8 (Critical).
highbug_reportVulnerabilityWindows LegacyHive zero-day enables privilege escalation, unofficial patches available
Microsoft Windows systems (all current versions). Specific affected versions not disclosed. Impacts up-to-date Windows installations. No CVE assigned yet.
highbug_reportVulnerabilityHollowGraph malware abuses Microsoft 365 calendar for C2 and exfiltration
Microsoft 365 environments with compromised mailboxes. Threat actors leverage Microsoft Graph API and calendar features to establish covert command-and-control channels.
highbug_reportVulnerabilityAI-assisted phishing toolkit targets Windows users in Mexico via fake gov site
Windows users in Mexico targeted via fake government ID-lookup website. Delivery mechanism uses WebDAV to distribute infostealer malware. Toolkit contains 1,048 files including phishing templates, droppers, and builder documentation.
highperson_alertThreat ActorHollowGraph Malware Uses Microsoft 365 Calendars for Covert C2
HollowGraph is a newly discovered espionage implant that leverages Microsoft 365 calendar infrastructure for command and control operations. The malware was identified and analyzed by Group-IB.
highbug_reportVulnerabilityACR Stealer campaign targets Microsoft enterprise customers
Microsoft enterprise customers; targets browser-stored credentials, authentication tokens, and sensitive documents across enterprise environments
criticalbug_reportVulnerabilityWindows zero-day LegacyHive enables privilege escalation on patched systems
All up-to-date Windows systems. Specific affected versions not disclosed. Exploit enables local privilege escalation from standard user to administrator level. No CVE assigned yet.
highbug_reportVulnerabilityACR Stealer campaign uses ClickFix social engineering to steal M365 data
Microsoft 365 enterprise users and organizations. ACR Stealer targets browser credentials, session tokens, and M365 documents. Active since 2024 with two documented delivery chains using ClickFix social engineering lures.
criticalbug_reportVulnerabilityCISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploited
Microsoft SharePoint Server (specific versions not disclosed). CVSS 9.8 critical remote code execution vulnerability.
highperson_alertThreat ActorVishing Campaign Targets Microsoft 365 Users with Entra Passkey Scam
The threat actor behind this campaign remains unattributed. The operation demonstrates sophistication in social engineering tactics, specifically targeting Microsoft 365 environments through voice-based phishing (vishing).
highperson_alertThreat ActorEvilTokens Ghost Phishing Campaign Targets US and European Businesses
EvilTokens is a campaign leveraging "ghost phishing" techniques to target business entities across the United States and Europe. The campaign's primary motivation appears to be credential theft and unauthorized access to Microsoft 365 environments, w…
highperson_alertThreat ActorDEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishing
DEBULL is a phishing campaign active from late June through early July 2026, targeting Microsoft 365 accounts through abuse of Microsoft's legitimate device-code flow authentication mechanism.
highbug_reportVulnerabilityAttackers impersonate IT support on Teams calls to deploy EtherRAT
Organizations using Microsoft Teams for internal communications. All industries are potential targets. The campaign exploits user trust in voice-based IT support interactions rather than a technical vulnerability in Teams itself.
highperson_alertThreat ActorEvilTokens Affiliate ARToken Exposes M365 Phishing-as-a-Service Platform
EvilTokens is a threat actor operating a phishing-as-a-service (PhaaS) ecosystem targeting Microsoft 365 credentials. The group utilizes an affiliate model, with ARToken identified as one operational affiliate platform.
highbug_reportVulnerabilityConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token theft
Microsoft 365 accounts across all organizations using OAuth authentication. Campaigns target users through social engineering to approve malicious OAuth consent prompts, bypassing MFA protections by stealing valid authentication tokens.
highbug_reportVulnerabilityCISA: Active exploitation of RCE flaw in Microsoft SharePoint
Microsoft SharePoint servers vulnerable prior to May 2024 security updates. Affects on-premises SharePoint deployments; unauthenticated remote code execution possible on unpatched systems.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)
Microsoft SharePoint Server, all versions vulnerable to deserialization attacks. Specific affected versions not yet disclosed.