This is a newsletter I create and share with my internal security team. Feel free to grab and do the same.
ClickFix Turns Users Into Their Own Attackers
Researchers warn that ClickFix has become one of the most effective social engineering techniques in use today because it removes the need for attackers to bypass security controls directly. Instead, victims are tricked into doing the work themselves by copying and pasting malicious commands from fake CAPTCHA pages, browser updates, or security verification prompts. Since the user manually executes the command, traditional security tools often see the activity as legitimate, making ClickFix an increasingly popular method for delivering malware, stealing credentials, and establishing initial access.
Further reading: Check Point analysis of ClickFix attacks
Hidden Website Instructions Can Manipulate AI Agents
Researchers have identified real-world attacks that use indirect prompt injection to manipulate AI agents through hidden instructions embedded in web content. By combining SEO poisoning with concealed text and metadata, attackers can influence how AI agents interpret information, causing them to trust fraudulent websites, make incorrect decisions, or even initiate unauthorized actions. The research highlights a growing challenge for organizations adopting AI agents: web content itself is becoming an attack surface, and untrusted information can influence AI-driven workflows in ways that are difficult for users to detect.
Further reading: Zscaler research on indirect prompt injection attacks
Single Email Campaign Targets University Research Networks
Researchers identified a suspected China‑aligned threat campaign targeting physics and engineering departments at U.S. and Canadian universities. The attackers exploited vulnerabilities in Roundcube webmail servers through specially crafted emails, using the compromised systems to steal credentials and establish persistent access. The campaign focused on organizations involved in research areas such as astrophysics, particle physics, and national security, demonstrating how a single email can serve as the starting point for broader attacks against high‑value research environments.
Further reading: Proofpoint analysis of the UNK_MassTraction campaign
Ransomware Activity Surges as New Threat Group Takes the Lead
Global cyberattack activity increased significantly in June 2026, with organizations experiencing an average of 2,270 attacks per week—up 17% from the same time last year. Ransomware activity also climbed sharply, increasing 33% year over year, while The Gentlemen overtook Qilin as the most active ransomware group. Researchers noted that attack growth was widespread across industries and regions, demonstrating how quickly new ransomware operators can emerge and scale their operations on a global level.
Further reading: Check Point's June 2026 threat intelligence report
New Phishing Kits Bypass MFA to Target Microsoft 365 Accounts
Researchers have identified two new phishing toolkits, Jalisco and OmegaLord, designed to compromise Microsoft 365 accounts while bypassing or undermining multifactor authentication. Jalisco uses device-code phishing, tricking victims into authorizing attacker-controlled devices through Microsoft's legitimate authentication process, while OmegaLord masquerades as a PDF reader to steal credentials and phone numbers associated with MFA. Once access is obtained, attackers can rapidly search SharePoint and other cloud services for sensitive data, often moving to data theft and extortion within minutes.
Further reading: BleepingComputer: New phishing kits target Microsoft 365 accounts, evade MFA
The Gentlemen Ransomware Continues Its Rapid Rise
Researchers warn that The Gentlemen ransomware operation has quickly become one of the most active ransomware‑as‑a‑service (RaaS) groups worldwide. Originally linked to the Qilin ecosystem, the group has expanded through an affiliate model that offers an unusually high share of ransom payments, helping it attract partners and scale operations rapidly. The group relies on a mix of stolen credentials, exploited internet‑facing systems, initial access brokers, custom malware, and advanced defense‑evasion techniques, contributing to hundreds of victim claims across dozens of countries.
Further reading: Unit 42 analysis of The Gentlemen ransomware
Attackers Hide in Plain Sight With OAuth Application Spoofing
Researchers are tracking a growing technique called OAuth client ID spoofing, where attackers create fraudulent applications that appear to be trusted Microsoft or enterprise services. By mimicking legitimate OAuth applications during authentication requests, threat actors can make consent prompts and login flows appear more credible, increasing the likelihood that users will authorize malicious access. Because the technique abuses legitimate identity and authorization processes rather than exploiting software vulnerabilities, it can be difficult for users and defenders to distinguish fraudulent applications from legitimate ones.
Further reading: Proofpoint analysis of OAuth client ID spoofing
CISA GitHub Leak Highlights the Importance of Secrets Management
A recent CISA postmortem offers important lessons for security teams after a contractor accidentally exposed sensitive credentials, cloud access keys, and internal configuration data in a public GitHub repository for months. The incident underscored the need for continuous secrets scanning, well‑tested credential rotation processes, and clearly defined channels for reporting security issues. CISA also acknowledged challenges in responding to external notifications and emphasized that organizations should regularly test their incident response and key management procedures before a real exposure occurs.
Further reading: Krebs on Security: Lessons Learned from CISA’s Recent GitHub Leak
Ransomware Groups Are Using AI to Increase Extortion Pressure
While much of the discussion around AI and cybercrime focuses on helping attackers gain access, some ransomware and data extortion groups are using AI in a different way: to strengthen their negotiations. Researchers highlighted how groups such as FulcrumSec are using AI to analyze stolen data, identify valuable intellectual property, and generate detailed reports that justify higher ransom demands. By quickly understanding the business value of stolen information, attackers can tailor their extortion efforts and apply greater pressure on victims during negotiations.
Further reading: Risky Business: Ransomware Uses AI to Amp Up Negotiations
Malware Hides Command-and-Control Traffic in Microsoft 365 Calendars
Researchers have uncovered HOLLOWGRAPH, a malware strain that uses compromised Microsoft 365 calendars as a covert command-and-control channel. Attackers place instructions inside calendar events dated far into the future and use Microsoft Graph API communications to blend malicious activity with legitimate Microsoft 365 traffic. The malware can also exfiltrate stolen data through calendar attachments, making detection more difficult because all communications occur through trusted Microsoft cloud services. The discovery highlights how threat actors are increasingly abusing legitimate business platforms to hide malicious activity and evade traditional security monitoring.
Further reading: Group‑IB analysis of HOLLOWGRAPH malware
Unpatched Windows Zero-Day Highlights Ongoing Legacy System Risks
Researchers are warning about a Windows vulnerability dubbed LegacyHive, a zero-day flaw affecting legacy components that could allow attackers to gain elevated access on affected systems. Because an official fix was not yet available at the time of reporting, security researchers released unofficial micropatches to help reduce risk for impacted organizations. The incident serves as a reminder that older system components can continue to introduce security challenges long after they are considered legacy, making vulnerability management and timely patching essential for reducing exposure.
Further reading: BleepingComputer: Windows LegacyHive zero-day flaw gets free, unofficial patches
Microsoft Defender XDR Blind Spot Could Hide External Connections
Researchers have identified a potential blind spot in Microsoft Defender XDR that may cause some outbound internet connections to be overlooked during threat hunting and detection activities. The issue stems from how certain public IPv4 connections are classified as FourToSixMapping instead of Public when IPv4 traffic is carried through IPv6-capable sockets. Security teams that filter detections solely on public IP classifications may unintentionally miss command-and-control traffic or other external communications, creating a false sense of visibility. The findings highlight the importance of regularly reviewing detection logic and validating assumptions within monitoring tools.
Further reading: Cyber Security News: Microsoft Defender XDR Blind Spot Can Hide Public Connections Behind FourToSixMapping
Google Introduces AI Model Focused on Finding Security Vulnerabilities
Google DeepMind has introduced Gemini 3.5 Flash Cyber, a specialized AI model designed to help security teams find, validate, and remediate software vulnerabilities more efficiently. Built specifically for cybersecurity workflows, the model is optimized to scan large codebases, analyze numerous code paths, and identify weaknesses at a lower cost than larger AI models. Google says the technology is intended to help defenders keep pace as vulnerabilities are discovered and exploited more quickly, while access is initially being limited to governments and trusted partners through its CodeMender platform to help reduce the risk of misuse.
Further reading: Google DeepMind: Introducing Gemini 3.5 Flash Cyber
Compromised Outlook Accounts Used to Steal MFA‑Protected Microsoft 365 Sessions
Researchers uncovered a phishing campaign that abuses already-compromised Outlook accounts to distribute convincing business-related messages and steal authenticated Microsoft 365 sessions. Rather than bypassing MFA directly, the attackers use adversary-in-the-middle (AiTM) phishing techniques to capture session cookies after users successfully sign in, giving them access to email, files, and other Microsoft 365 resources. Because the messages originate from trusted Outlook mailboxes and mimic normal business workflows, the attacks can be difficult for users to identify.
Further reading: Cyber Security News: Hackers Abuse Compromised Outlook Accounts to Steal MFA‑Protected Microsoft 365 Sessions
ChatGPT Agent Flaw Could Have Created a Hidden AI Insider
Researchers discovered a vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed attackers to create and control a rogue AI agent inside an organization through a single phishing link. The flaw, dubbed AgentForger, could have given the malicious agent access to the victim’s existing permissions and connected business applications, effectively creating an automated “insider” operating within the organization’s trust boundary. OpenAI has since fixed the issue, but the research highlights the emerging security risks associated with AI agents that can autonomously interact with enterprise data and systems.
Further reading: SecurityWeek: OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider
Attackers Use Teams Vishing and Quick Assist to Gain Remote Access
Researchers observed a campaign in which attackers impersonated IT help desk personnel through Microsoft Teams messages and voice calls to convince employees to launch Quick Assist, Microsoft's built‑in remote support tool. Once access was granted, the attackers installed a custom backdoor called GoGRPC, allowing them to maintain access and conduct follow‑on activity within the environment. The campaign highlights how threat actors continue to combine social engineering with legitimate administrative tools to bypass traditional security controls and gain an initial foothold in organizations.
Further reading: Zscaler research on Teams vishing, Quick Assist, and the GoGRPC backdoor
Teams Vishing Campaign Leads to Ransomware Attacks
Sophos researchers are warning about a Microsoft Teams voice phishing (vishing) campaign that targeted dozens of organizations across North America. In the attacks, criminals posed as IT support personnel and used Teams calls to convince employees to grant remote access to their devices. Once access was obtained, the attackers deployed malware, established persistence, and in several cases ultimately launched Chaos ransomware. Sophos noted a significant increase in Teams vishing incidents during 2026, highlighting how cybercriminals are increasingly using collaboration tools and social engineering rather than traditional phishing emails to gain access to corporate environments.
Further reading: Chaos in Teams Vishing
Behind the Scenes of a Vishing Operation
Okta researchers analyzed a voice phishing (vishing) operation that targeted employees by impersonating IT support staff and guiding victims through fraudulent login and authentication processes. The report highlights how attackers use convincing social engineering, real-time phishing sites, and MFA manipulation to gain access to corporate accounts. Once inside, attackers can leverage single sign-on (SSO) services to access multiple business applications, making a single compromised account a gateway to sensitive company data.
Further reading: Behind the Scenes of a Vishing Operation
Attackers Are Turning Microsoft's Trusted Login System Into Their Latest Phishing Weapon
Security researchers at Check Point have observed phishing campaigns that abuse Microsoft's legitimate authentication infrastructure instead of directing users to fake login pages. In the campaign, emails masquerading as Microsoft Teams and HR notifications lead recipients to a legitimate Microsoft sign-in page, where they are prompted to grant permissions to an attacker-controlled application. Because the login page is genuine, the attack can bypass many of the visual warning signs users have been trained to look for. Researchers identified more than 200 phishing emails targeting approximately 120 organizations and noted that this OAuth permission abuse technique is becoming increasingly common.
Further reading: Attackers Are Turning Microsoft's Trusted Login System Into Their Latest Phishing Weapon
Microsoft's Brand Remains the Top Phishing Target
Check Point's Q2 2026 Brand Phishing Report found that Microsoft was the most impersonated brand in phishing attacks, accounting for 23% of all observed brand impersonation attempts. LinkedIn, Google, Apple, and Amazon rounded out the top five, while ChatGPT entered the top 10 most impersonated brands for the first time. Researchers noted that attackers continue to focus on well-known technology platforms because users are more likely to trust communications that appear to come from familiar brands. The report serves as a reminder to carefully inspect login requests, payment notifications, and account alerts before taking action.
Further reading: Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report
Google Updates Cyber Threat Actor Naming System
Google Threat Intelligence Group (GTIG) has introduced a new naming system for tracking cyber threat actors, replacing complex identifiers with more memorable two-word cryptonyms. The updated approach is designed to help security professionals more quickly understand and communicate threat activity by pairing a unique identifier with a category that reflects the actor's origin, motivation, or activity type. Google says the change will help standardize threat tracking across its intelligence platforms while making threat reporting easier to follow and map to other industry naming conventions.
Further reading: Updated Cyber Threat Actor Naming System
CISA Updates Minimum Elements for Software Bills of Materials (SBOMs)
The Cybersecurity and Infrastructure Security Agency (CISA), together with multiple international cybersecurity partners, has released updated guidance defining the 2026 Minimum Elements for a Software Bill of Materials (SBOM). The update reflects advances in software supply chain security and improvements in SBOM tools since the original guidance was issued in 2021. CISA encourages organizations that develop, purchase, or operate software to request SBOMs from vendors and use available tools to generate, analyze, and manage SBOM data. The guidance is intended to improve visibility into software components and strengthen defenses against supply chain threats.
Further reading: 2026 Minimum Elements for a Software Bill of Materials (SBOM)
AI Could Turn Forgotten DNS Records Into a Large-Scale Cyber Threat
Researchers are warning that artificial intelligence could dramatically increase the effectiveness of dangling DNS takeover attacks, a technique that exploits DNS records that still point to cloud resources that have been deleted. In a research project dubbed DangleGeddon, security firm Silent Push demonstrated how AI could automate the discovery of vulnerable domains, generate takeover scripts, and identify exploitable targets at a scale that would be difficult for human attackers alone. Researchers warn that AI could enable nation-state or cybercriminal actors to weaponize forgotten DNS records to support phishing, malware distribution, and disruption campaigns targeting governments, financial institutions, and critical infrastructure.
Further reading:‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale
Behind the Scenes of a Vishing Operation
Okta researchers uncovered Work Panel, a platform used by cybercriminals to run large-scale voice phishing (vishing) attacks. The service helps attackers quickly create phishing sites, impersonate trusted brands, manage phone-based social engineering campaigns, and capture credentials. The research highlights how vishing operations are becoming more organized and scalable, making it increasingly important to be cautious of unexpected calls requesting credentials, MFA codes, or access to systems.
Further reading: Behind the Scenes of a Vishing Operation
RingCentral-Themed Phishing Targets Microsoft 365 Users
Researchers have identified a phishing campaign that impersonates RingCentral voicemail notifications to steal Microsoft 365 accounts. The attacks use advanced phishing techniques designed to capture authentication tokens and bypass traditional credential protections, giving attackers access to email, Teams, SharePoint, and OneDrive data. The campaign highlights the need to be cautious of unexpected voicemail or account-related emails, even when they appear to come from trusted business services.
Further reading: Phishing Service Spoofs RingCentral to Steal Microsoft 365 Accounts
Kali365 Uses Microsoft's Legitimate Login Process to Steal Accounts
Researchers are warning about Kali365, a phishing kit that abuses Microsoft's legitimate device authentication process to gain access to Microsoft 365 accounts. Instead of directing victims to a fake login page, Kali365 lures users into entering an attacker-provided code on a real Microsoft sign-in page. Once approved, attackers can obtain access tokens that may provide ongoing access to email, documents, Teams, SharePoint, and other Microsoft 365 resources without stealing a password. The campaign highlights how cybercriminals are increasingly abusing trusted authentication workflows to bypass traditional phishing defenses. [thehackernews.com], [ic3.gov]
Further reading: Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
