A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. "The campaign did no

A sophisticated phishing campaign has been observed exploiting Microsoft 365's device code flow to gain unauthorized access to user accounts. The campaign, which ran from the last week of June into early July, utilized collaboration-themed lures to trick victims into compromising their credentials.
The attackers employed a technique that abuses the legitimate device code authorization flow within Microsoft 365. This method allows users to authenticate to a service on a device that may not have an easy way to enter credentials, such as a smart TV or a gaming console, by visiting a specific URL and entering a code displayed on the device.
In this campaign, threat actors directed victims to a fake Microsoft login page after they clicked on a phishing link embedded in a lure email. These emails often mimicked legitimate communications, potentially related to shared documents or collaboration tools, to appear more convincing.
Once a victim entered their Microsoft 365 credentials on the fraudulent page, the attackers would use these stolen credentials to initiate the device code flow. This process would then prompt the victim to visit a legitimate Microsoft authorization URL and enter a code provided by the attacker.
By completing this second step, the victim inadvertently grants the attacker's application access to their Microsoft 365 account. This grants the attacker a broad range of permissions, enabling them to potentially access emails, files, contacts, and other sensitive data stored within the Microsoft 365 environment.
The effectiveness of this method lies in its ability to bypass traditional multi-factor authentication (MFA) for the initial login, as the device code flow is designed to be a convenient authentication method. While MFA can still be a layer of defense, the attackers are leveraging a legitimate Microsoft process to gain an initial foothold.
The campaign was identified by researchers at ZeroBEC, who observed its activity during the specified timeframe. The use of collaboration-themed lures suggests an attempt to blend in with typical business communications, increasing the likelihood of success.
Organizations using Microsoft 365 should remain vigilant against phishing attempts. Implementing robust security awareness training for employees is crucial, emphasizing the importance of scrutinizing email content, sender addresses, and any requests for credentials or authentication codes.
Additionally, reviewing and restricting the types of third-party applications that can access Microsoft 365 accounts can help mitigate the impact of such attacks. Regularly auditing application permissions and disabling unnecessary ones is a recommended security practice.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed