A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]

A new malicious component, dubbed HollowGraph, has been identified using Microsoft 365 mailboxes, specifically their calendar features, as a covert command-and-control (C2) channel. This module is believed to be part of the Cavern C2 framework, which has previously been associated with an Iranian threat actor targeting entities in Israel.
HollowGraph leverages the Microsoft Graph API for its primary communication, authenticating with hardcoded details from a compromised Microsoft 365 account. These details, including the Microsoft Entra ID tenant ID, application (client) ID, client secret, target mailbox address, C2 domain, and two RSA keys, are stored in a configuration file named `logAzure.txt`, designed to mimic a legitimate log file. The RSA keys facilitate a hybrid encryption scheme, combining RSA and AES-256-GCM algorithms, to secure both inbound and outbound communications over Microsoft Graph.
The malware uses the mailbox calendar as a dead-drop mechanism. It creates calendar events dated May 13, 2050, with specific title formats. Commands from the attacker and exfiltrated data are concealed within files attached to these calendar entries. HollowGraph is programmed to retrieve commands from events scheduled within a fixed one-hour window between 22:00 and 23:00 UTC on May 13, 2050. It supports two main commands: `GET`, to search for entries with a specific ID format and decrypt instructions, and `SEND`, to create new calendar entries with encrypted stolen data.
In addition to the encrypted Microsoft Graph channel, HollowGraph maintains a secondary, unencrypted communication channel via DNS tunneling. This channel is used to receive updated Microsoft Entra ID credentials (tenantId, clientId, clientSecret, and mailbox) for authentication to Microsoft Graph. It retrieves these values through IPv6 AAAA record queries to the attacker-controlled domain `cloudlanecdn[.]com`, subsequently updating the `logAzure.txt` configuration file. Each 16-byte IPv6 address provides 14 usable payload bytes, which the malware assembles into UTF-8 text for configuration updates.
At least 12 systems have been infected with HollowGraph, with three actively communicating with the threat actor between June 3 and July 9. The targeting appears focused on organizations in Israel, suggesting an espionage motive. While researchers have noted technical similarities between HollowGraph and the Iranian-nexus threat actor Lyceum, there is currently insufficient evidence for a high-confidence attribution to Lyceum. However, the link to the Cavern framework is assessed with high confidence.
The sophisticated nature of HollowGraph, including its use of trusted cloud infrastructure for C2, hybrid encryption, DNS tunneling for credential refresh, and highly selective targeting, indicates significant technical capabilities and operational maturity on the part of the threat actor.
Organizations are advised to monitor Microsoft Graph and Microsoft 365 audit logs for suspicious application-driven calendar activity, especially events scheduled far into the future or those with unusual subjects and attachments. Specific indicators of compromise include the `cloudlanecdn[.]com` domain and the `logAzure.txt` file. Implementing Conditional Access, restricting and auditing OAuth client-credential applications, and monitoring outbound DNS for tunneling patterns are also recommended security measures.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed