BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
Unlike pure patch reports, this article describes an ongoing phishing campaign specifically bypassing MFA for Microsoft 365, highlighting concrete risks to access security.
Comparing 7 September 2026 with the previous day 6 September 2026.
Unlike pure patch reports, this article describes an ongoing phishing campaign specifically bypassing MFA for Microsoft 365, highlighting concrete risks to access security.
Authenticated attackers can execute malicious code in user context via path-traversal in file transfer and virtual file-clipboard; updates to version 15.81.5 are available.
Attackers are actively exploiting a previously undocumented vulnerability in PaperCut NG/MF; administrators can initially only check for compromises using incomplete indicators of compromise.
BSI warns of multiple OpenSSL vulnerabilities with RCE, DoS, and information disclosure potential; UPDATE designation indicates patch availability.
PEEP demonstrates a novel post-compromise tactic that abuses legitimate browsers as a backdoor channel and bypasses Chromium security mechanisms without requiring user interaction.
The BSI bundles several kernel vulnerabilities without detailed CVE information in one advisory, underlining the need for a timely kernel update on affected Linux systems.
No changes in this category.
No changes in this category.
No changes in this category.