Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. [...]

Threat actors are leveraging Microsoft Teams voice calls to impersonate IT support staff and trick employees into installing the EtherRAT malware, according to research from Palo Alto Networks' Unit 42. This tactic grants attackers initial access to corporate networks. The operation combines phishing emails, Teams voice calls, legitimate remote management tools, and a custom malware loader to compromise victim systems.
The attack sequence begins with a phishing email containing a lure such as an "Employee Survey" and a malicious PDF attachment. Upon opening the document, the targeted employee receives a Microsoft Teams voice call. The caller impersonates a "System Administrator" and is identified as an external party, indicating they are from a different Microsoft 365 tenant. Audit logs revealed an attacker initiated a chat using an external account, helpdesk@Progressive936.onmicrosoft[.]com, while posing as IT support.
After convincing the victim to share their screen via Microsoft Teams, the attacker guides them through installing legitimate remote access tools like HopToDesk and AnyDesk. Once remote access is established, the attackers download and execute a malicious MSI installer from camorreado[.]click. This MSI file functions as a malware loader. It downloads a legitimate Node.js runtime, decrypts embedded malicious payloads, and ultimately deploys EtherRAT.
EtherRAT is a cross-platform remote access trojan developed in Node.js. It provides attackers with comprehensive control over compromised systems, enabling them to execute commands, manipulate files, exfiltrate data, and establish persistence. A notable feature of EtherRAT is its use of Ethereum smart contracts to retrieve its active command-and-control server information, which complicates efforts to disrupt its operations. This malware has previously been associated with state-sponsored attacks and has since been adopted by various other threat groups.
Unit 42 researchers discovered an open directory on a distribution server containing multiple versions of the malware installers, from v1 to v9. This suggests the ongoing development and active use of this campaign.
This latest campaign highlights a growing trend of attackers exploiting Microsoft Teams to breach corporate networks. In March, a similar campaign targeted financial and healthcare organizations by using spam emails followed by Teams calls from individuals impersonating IT staff. Victims in that instance were persuaded to launch Quick Assist sessions, which led to the deployment of the A0Backdoor malware.
In April, Microsoft issued a warning about attackers increasingly using external Microsoft Teams accounts to impersonate helpdesk personnel. These attackers would then convince employees to grant them remote access to their devices. Once inside a network, these threat actors would conduct reconnaissance, spread to other devices, and steal data.
Microsoft has been implementing new protections within Teams to counter these evolving threats. Earlier this year, the company introduced warnings to identify external callers and chats, aiming to protect users from potential phishing and vishing attacks. More recently, Microsoft introduced a new administrator policy for Teams that automatically places suspected third-party bots into the meeting lobby, requiring manual approval from organizers before they can join.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed