LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication

microsoft 365 news

2 stories
backdoorhigh

Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel

Cisco Talos researchers have identified a new Rust-based backdoor, dubbed Antino, which a China-linked threat actor known as UAT-11587 is using to conduct espionage against government and policy organizations in Asia. The backdoor uniquely leverages Microsoft 365 services, specifically Outlook and OneDrive, for its command-and-control (C2) communications, allowing its traffic to blend in with…

phishinghigh

Forg365 Phishing Platform Leverages AI for Microsoft 365 Account Theft

A new phishing-as-a-service (PhaaS) platform named Forg365 has emerged, specializing in the theft of Microsoft 365 accounts. The platform integrates adversary-in-the-middle (AiTM) and device code phishing techniques with AI-assisted lure generation, and provides a browser extension for persistent access to compromised accounts.