Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

16 / 16 results
Active filter:tag: #enterprise✕ clear
Attackers abuse Microsoft Teams external chat to impersonate IT supporthighbug_reportVulnerability
bug_reportVulnerability

Attackers abuse Microsoft Teams external chat to impersonate IT support

Microsoft Teams users in enterprise environments with external collaboration enabled. All organizations using Teams for business communication are at risk if users accept external contact requests and grant remote access via RMM tools or Quick Assist…

Microsoft2 Sep · 20:51 UTC
Spring Ring Campaign Weaponizes Microsoft Teams for Vishing Attackshighperson_alertThreat Actor
person_alertThreat Actor

Spring Ring Campaign Weaponizes Microsoft Teams for Vishing Attacks

Spring Ring is a coordinated social engineering campaign identified between January and April 2026 that leverages external Microsoft Teams accounts to impersonate IT help desk personnel.

Microsoft31 Aug · 08:00 UTC
Microsoft SharePoint RCE chain (CVE-2026-55040 + CVE-2026-63520) exploitedhighbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE chain (CVE-2026-55040 + CVE-2026-63520) exploited

Microsoft SharePoint Server (on-premises). CVE-2026-55040: JWT authentication bypass. CVE-2026-63520: Business Connectivity Services RCE. Over 8,700 SharePoint servers exposed online. Specific vulnerable versions not disclosed in article.

Microsoft26 Aug · 12:47 UTC
Cisco Secure Firewall DoS flaw under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Firewall DoS flaw under active exploitation

Cisco Secure Firewall products (specific versions not disclosed in available data). Organizations using Cisco ASA, FTD, or Firepower appliances should assume exposure until vendor advisory is reviewed.

Cisco13 Aug · 06:31 UTC
Kali365 Campaign Weaponizes Microsoft Device Code Flow Against US Firmshighperson_alertThreat Actor
person_alertThreat Actor

Kali365 Campaign Weaponizes Microsoft Device Code Flow Against US Firms

Kali365 is a device code phishing campaign targeting US organizations through abuse of legitimate Microsoft authentication mechanisms. The campaign leverages a phishing kit designed to trick victims into approving attacker-controlled device codes on…

Microsoft5 Aug · 09:43 UTC
Greatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentralhighperson_alertThreat Actor
person_alertThreat Actor

Greatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentral

Greatness is a phishing-as-a-service (PhaaS) platform active since at least mid-2022, operated by cybercriminals who sell access for $289/month via a Telegram channel with thousands of subscribers.

Microsoft4 Aug · 19:45 UTC
ACR Stealer campaign uses ClickFix social engineering to steal M365 datahighbug_reportVulnerability
bug_reportVulnerability

ACR Stealer campaign uses ClickFix social engineering to steal M365 data

Microsoft 365 enterprise users and organizations. ACR Stealer targets browser credentials, session tokens, and M365 documents. Active since 2024 with two documented delivery chains using ClickFix social engineering lures.

Microsoft17 Jul · 06:56 UTC
DEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishinghighperson_alertThreat Actor
person_alertThreat Actor

DEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishing

DEBULL is a phishing campaign active from late June through early July 2026, targeting Microsoft 365 accounts through abuse of Microsoft's legitimate device-code flow authentication mechanism.

Microsoft7 Jul · 13:14 UTC
ConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token thefthighbug_reportVulnerability
bug_reportVulnerability

ConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token theft

Microsoft 365 accounts across all organizations using OAuth authentication. Campaigns target users through social engineering to approve malicious OAuth consent prompts, bypassing MFA protections by stealing valid authentication tokens.

Microsoft2 Jul · 12:00 UTC
Oracle PeopleSoft RCE actively exploited, immediate patching requiredcriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft RCE actively exploited, immediate patching required

Oracle PeopleSoft (specific versions not disclosed in alert). Remote code execution vulnerability affecting internet-facing PeopleSoft instances.

Oracle12 Jun · 12:39 UTC
Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunterscriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters

Oracle PeopleSoft (all versions prior to June 10 patch). Confirmed exploitation targeting enterprise systems and universities. Vulnerability was unpatched during active exploitation window (May 27 - June 9).

CVE-2026-3527311 Jun · 18:29 UTC
Windows Server domain controllers under active RCE attackcriticalbug_reportVulnerability
bug_reportVulnerability

Windows Server domain controllers under active RCE attack

Windows Server domain controllers (all supported versions). Specific version details not yet published by Microsoft. Unauthenticated remote code execution vulnerability.

Microsoft10 Jun · 06:47 UTC
Microsoft SharePoint RCE vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE vulnerability requires immediate patching

Microsoft SharePoint Server (specific versions not disclosed in advisory). Organizations running on-premises SharePoint deployments are affected. SharePoint Online managed by Microsoft likely already patched.

Microsoft27 May · 14:23 UTC
F5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movementhighperson_alertThreat Actor
person_alertThreat Actor

F5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movement

The threat actor behind this campaign remains unattributed. Motivation appears to be credential theft and network persistence within enterprise environments.

F522 May · 14:53 UTC
Microsoft Exchange Server XSS flaw actively exploited for session hijackingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Exchange Server XSS flaw actively exploited for session hijacking

Microsoft Exchange Server (specific versions not disclosed). Cross-Site Scripting vulnerability enabling spoofing and session hijacking. No CVE assigned yet.

Microsoft18 May · 13:25 UTC
Cisco Catalyst SD-WAN auth bypass grants admin access to attackerscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN auth bypass grants admin access to attackers

Cisco Catalyst SD-WAN platform. Specific affected versions not disclosed. Vulnerability allows authentication bypass leading to administrative access on SD-WAN infrastructure components.

Cisco18 May · 12:16 UTC