Counterfeit LastPass Authenticator Installer Exploits Microsoft-Signed Driver to Disable Antivirus and EDR

Counterfeit LastPass Authenticator Installer Exploits Microsoft-Signed Driver to Disable Antivirus and EDR

A counterfeit LastPass Authenticator installer available on GitHub installs a Windows kernel driver that disables antivirus and other security applications before a password theft program executes, according to researchers from LastPass and Delphos Labs on September 17. The driver is signed by Microsoft’s hardware compatibility program, received zero detections on VirusTotal during an August check…

Read More
CISA warns of ongoing exploitation of three Linux kernel vulnerabilities

CISA warns of ongoing exploitation of three Linux kernel vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the exploitation of three vulnerabilities in the Linux kernel, one of which is classified as critical. These three security flaws were individually reported last week and have severity ratings that range from medium to critical. Notably, one of them, identified as CVE-2025-39964,…

Read More
BigBear Microsoft 365 Phishing Service Circumvents MFA at 258 Organizations

BigBear Microsoft 365 Phishing Service Circumvents MFA at 258 Organizations

A phishing-as-a-service platform known as BigBear 2.0 has successfully circumvented multi-factor authentication (MFA) for 258 organizations, resulting in the theft of over 5,000 Microsoft 365 credentials. Researchers from the cybersecurity firm CloudSEK gained administrative access to the control panel and discovered that the service operated 42 VPS nodes, all specifically configured to target Microsoft 365…

Read More
Executives Targeted by Phony IT Calls in Microsoft 365 Data Theft and Extortion Schemes

Executives Targeted by Phony IT Calls in Microsoft 365 Data Theft and Extortion Schemes

Threat hunters have revealed information about a large-scale data theft and extortion threat group that is focusing on Microsoft 365 and other software-as-a-service (SaaS) platforms through IT help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. This activity primarily targets directors, vice presidents, and other high-ranking officials, and is being monitored by Arctic Wolf…

Read More
Exploitation of Magento StyleSmuggler Zero-Day Leads to Linux Backdoor Deployment

Exploitation of Magento StyleSmuggler Zero-Day Leads to Linux Backdoor Deployment

A zero-day flaw known as “StyleSmuggler,” which impacts all versions of Magento and Adobe Commerce, is currently being exploited in attacks aimed at deploying a backdoor. The initial incident of exploitation was documented on September 4, targeting a system that had the latest security updates installed. According to e-commerce security firm Sansec, Adobe Enterprise Support…

Read More
Microsoft Exchange Online outage leads to email disruptions and authentication problems

Microsoft Exchange Online outage leads to email disruptions and authentication problems

Microsoft is currently looking into a significant service disruption that is resulting in authentication difficulties, connection issues, delays in email delivery, and various other complications for users of Microsoft 365. The company first acknowledged this situation (identified as EX1464935 in the admin center) at 5:30 PM UTC, following a surge of reports from users on…

Read More
Microsoft alerts about TerminalFix attacks utilizing reverse tunnels

Microsoft alerts about TerminalFix attacks utilizing reverse tunnels

A new variant of ClickFix, named TerminalFix, employs deceptive Cloudflare CAPTCHA prompts on compromised sites to deceive victims into running harmful PowerShell commands within Windows Terminal. In contrast to standard ClickFix attacks that frequently result in infostealer malware infections, this operation utilizes a multi-stage intrusion process that ultimately provides attackers with a reverse tunnel into…

Read More
Cronos blockchain resumes operations following $74 million Tectonic exploit

Cronos blockchain resumes operations following $74 million Tectonic exploit

The Cronos blockchain network has restarted its trading activities after a price-manipulation incident involving the Tectonic cryptocurrency lending platform, which enabled an attacker to borrow $74 million. Recent reports indicate that the perpetrator artificially boosted the price of Tectonic’s TONIC token by a factor of 100, subsequently using it as collateral to secure real assets….

Read More
Microsoft: August updates disrupt printing and PDF export in WPF applications

Microsoft: August updates disrupt printing and PDF export in WPF applications

Microsoft has acknowledged that updates to the .NET Framework issued during the August 2026 Patch Tuesday are causing issues with printing and PDF export in certain applications. According to a Windows release health alert reported by BleepingComputer, this known problem specifically impacts applications utilizing the Windows Presentation Foundation (WPF) UI framework, which is an open-source…

Read More
Microsoft Teams now allows admins to prevent external bots from joining meetings

Microsoft Teams now allows admins to prevent external bots from joining meetings

Microsoft is introducing a new policy for Teams meetings that enables administrators to automatically prevent all recognized external bots from participating in Teams meetings. This feature enhances a previous Teams policy launched in June, which implemented more intelligent bot protection by ensuring that all identified bots are marked in the lobby and need organizer approval…

Read More
Back To Top