LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
security

Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.

zeroday.news ·

A recent report indicates that threat actors are exploiting Bring Your Own Device (BYOD) policies to gain unauthorized access to Microsoft 365 environments and corporate data. The attack chain reportedly involves voice callers as an initial vector, suggesting a social engineering component to compromise user devices or credentials.

The core of the reported attack appears to center on the abuse of Microsoft's Graph API. This API is a powerful tool that allows programmatic access to data and intelligence across Microsoft 365, Windows 10, and Enterprise Mobility + Security. Threat actors are reportedly leveraging its capabilities to identify high-value targets within organizations, likely by enumerating users, groups, and their associated permissions or data access. This reconnaissance phase is critical for pinpointing individuals whose compromised credentials would yield the most significant access to sensitive information or systems.

Following the identification of lucrative targets, the access gained through this BYOD exploitation and Graph API abuse is reportedly being passed to extortion groups. Specifically, the report names ShinyHunters, a group known for data theft and subsequent extortion attempts. This suggests a monetization strategy where initial access brokers, potentially the voice callers, sell their validated access to more specialized groups focused on data exfiltration and financial gain.

The BYOD aspect of this threat highlights a persistent challenge for organizations. While BYOD policies offer flexibility and cost savings, they introduce a broader attack surface as personal devices may lack the stringent security controls present on corporate-issued hardware. This class of flaw often exploits the blurring lines between personal and professional use, where a compromised personal device, even if initially targeted for non-corporate reasons, can become a conduit to enterprise resources.

Mitigation strategies for this type of threat typically involve a multi-layered approach. Strong authentication, such as multi-factor authentication (MFA), is crucial to prevent unauthorized access even if credentials are stolen. Device management solutions can enforce security policies on BYOD devices, ensuring they meet minimum security standards before accessing corporate resources. Furthermore, robust identity and access management (IAM) practices, including least privilege principles and regular access reviews, can limit the impact of a compromised account.

This incident underscores the evolving sophistication of threat actors who combine social engineering with technical exploitation of widely used enterprise platforms. The integration of initial access brokers with specialized extortion groups like ShinyHunters demonstrates a mature cybercrime ecosystem. Organizations must continuously adapt their security postures to account for both human-centric vulnerabilities and the potential for abuse of legitimate enterprise APIs in their defense strategies.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.