// 1 CRITICAL · 2 ZERO-DAY · 5 CVE · 6 EXPLOIT IN THE LAST 24H
CYBERSEC

Hotel Wi-Fi DNS Attacks Steal Microsoft 365 Accounts, Bypass MFA

Threat actors compromise hotel and conference center Wi-Fi captive portals to manipulate DNS and steal Microsoft 365 credentials, sess…

Jul 28, 2026views - 1.2k

CYBERSECEXPLOIT

Certighost: Ten Days After the Patch, the Exploit Is Public and the Domain Falls

The Certighost proof-of-concept for CVE-2026-54121 lets a standard domain user impersonate a Domain Controller via AD CS. Released exa…

Jul 27, 2026views - 1.1k

microsoftZERO-DAY

Record Patch Tuesday: Microsoft Fixes 570 CVEs and Two Actively Exploited Zero-Days in AD FS and SharePoint

The July 14, 2026 Patch Tuesday sets a record with 570 CVEs patched, two actively exploited zero-days, and a third publicly disclosed.…

Jul 27, 2026views - 1.2k

cybersecZERO-DAY

LegacyHive: Zero-Day Windows Flaw Patched by 0Patch Before Microsoft

The LegacyHive vulnerability in the Windows User Profile Service enables local privilege escalation. ACROS Security has released free…

Jul 26, 2026views - 1.1k

phishing

Misconfigured Server Exposes Three Evilginx Operations Targeting Microsoft 365

A phishing server with directory listing enabled exposed complete M365 phishing toolkits, two distinct MFA bypass techniques, and evid…

Jul 25, 2026views - 1.1k

phishing

Joint Operation Dismantles Kratos: The AiTM Phishing Kit That Bypasses MFA

German, U.S., and Indonesian authorities have taken down over 200 servers powering the Kratos phishing kit. The code survives among ro…

Jul 25, 2026views - 1.2k

CYBERSEC

Miasma Worm Infects 73 Microsoft GitHub Repos via AI Coding Agents

The Miasma worm compromised 73 Microsoft repositories on GitHub in 105 seconds. The malware activates when a developer opens the repos…

Jul 25, 2026views - 1.5k

CYBERSEC

Device Code Phishing: Legitimate Authentication Becomes the Weapon to Breach M365

Device code phishing exploits Microsoft's legitimate OAuth flow to bypass MFA. Low-cost PhaaS kits like DEBULL and ARToken have indust…

Jul 24, 2026views - 1.3k

CYBERSECZERO-DAY

Microsoft Patch Tuesday July 2026: Two Zero-Days, and the CVSS 5.3 Is More Dangerous Than the 7.8

Microsoft's July 2026 Patch Tuesday addressed 570 CVEs, including two actively exploited zero-days: CVE-2026-56164 in SharePoint Serve…

Jul 23, 2026views - 1.6k

CYBERSEC

German Police Dismantle Kratos, the Kit That Turned AiTM Phishing Into a Franchise

German, U.S., and Indonesian authorities dismantled the Kratos phishing-as-a-service platform, seizing over 200 servers and arresting…

Jul 22, 2026views - 1.5k

CYBERSEC

Microsoft Uncovers OAuth Abuse: Vishing and Supply Chain Attacks Target SaaS

Microsoft has documented ShinyHunters-linked campaigns abusing trusted OAuth relationships in Salesforce through vishing and third-par…

Jul 22, 2026views - 1.7k

zeroZERO-DAY

LegacyHive: Nightmare Eclipse's Ninth Zero-Day Pierces Fully Patched Windows

Nightmare Eclipse has released LegacyHive, a zero-day exploit targeting the Windows User Profile Service to load arbitrary registry hi…

Jul 20, 2026views - 1.5k