This website uses cookies

Read our Privacy policy and Terms of use for more information.

The vulnerability numbers this month tell the real story: critical and high-severity disclosures from major vendors have jumped roughly five times over their pre-spring baseline, and researchers are pointing to Anthropic's AI-driven bug-hunting project as a big reason why.

That's good news in theory — more flaws found before criminals find them — except the data also shows attackers exploiting new zero-days in about a day on average now. More bugs and faster exploitation at the same time is not a comfortable combination.

That speed shows up everywhere in today's patch list. Citrix NetScaler, MikroTik routers, PaperCut, Magento, JetBrains's TeamCity-linked breach — all cases where attackers moved on a flaw almost as soon as it became public, sometimes before a fix even existed.

SonicWall's latest zero-day pair drew extra criticism because the company gave customers a patch but no indicators of compromise, leaving defenders to guess whether they'd already been hit.

The rest of the day's news is about attackers finding cheaper ways in than exploits: fake IT helpdesk calls on Teams, OAuth consent screens the FBI is now warning people about by name, QR codes hidden in PDFs, and invisible Unicode characters slipped into phishing emails to dodge filters.

None of it is flashy, but it's the stuff that actually gets clicked. Combine that with AI agents apparently coordinating on an abandoned wiki to cheat at tasks, and it's clear both attackers and automated systems are getting better at working around

Critical and high-severity vulnerability disclosures from major vendors including Microsoft, Google, Apple, Cisco, and IBM jumped to roughly 2,500 by July, nearly five times the pre-spring baseline, with researchers linking the spike largely to Anthropic's AI-driven Project Glasswing, which reportedly surfaced over 10,000 undisclosed flaws. Meanwhile, exploitation speed has collapsed: the zero-day exploitation rate now stands near 87 percent, median time-to-exploit is about one day, and more than half of 2025 ransomware-linked CVEs were exploited before patches existed.

Researchers have identified a Chromium-based post-exploitation toolkit called PEEP that turns Google Chrome and Microsoft Edge into persistent remote-access tools. The malware lets attackers who already have administrative privileges or code-execution access steal browser data, hijack sessions, manage files, and run shell commands on compromised systems. It functions as a follow-on tool rather than an initial infection vector.

A researcher known as Nightmare Eclipse published a privilege-escalation zero-day dubbed "FalconFlank" that lets attackers get a SYSTEM-level command prompt on fully patched Windows 11 25H2 and Windows Server 2025 machines by abusing CrowdStrike Falcon's malicious-macro remediation feature. No CVE has been assigned yet; CrowdStrike says it's investigating and is telling customers to disable the Microsoft Office File Suspicious Macro Removal policy setting while relying on Cloud Anti-malware for Office Files protection instead. The same researcher has released other privilege-escalation and denial-of-service zero-days this week affecting Kaspersky, Avast, and Nvidia software, following earlier disclosures against several Microsoft products since April.

Researchers at ReliaQuest found that Microsoft 365's RejectDirectSend control, meant to block unauthenticated Direct Send email spoofing internal accepted domains, can be bypassed by using an empty envelope sender (MAIL FROM:<>), letting attackers send unauthenticated messages that display convincing internal "From" addresses. Between September 2025 and August 2026, ReliaQuest observed the technique used against executives, finance, and procurement staff in phishing lures, with at least one high-confidence phishing message reaching an inbox because the spoofed sender was on an allow list. Microsoft's guidance doesn't cover empty-sender cases, and ReliaQuest recommends IP- or certificate-restricted inbound connectors as a stronger defense than domain-based checks alone.

Microsoft has detailed an ongoing campaign in which unnamed threat actors pose as IT helpdesk staff on Microsoft Teams to trick employees at various enterprises into granting remote access via screen-sharing or RMM tools. Once inside, attackers install malware loaders, conduct reconnaissance, move laterally through Active Directory, and ultimately steal data and deploy ransomware. Microsoft recommends internal helpdesk authentication phrases, staff training on external-tenant indicators, and Defender for Office 365's Safe Links and ZAP protections.

The FBI's Internet Crime Complaint Center has issued a warning about "OAuth consent phishing," an attack that lets hackers hijack Google and Microsoft accounts without stealing passwords. Attackers impersonating officials or media figures send victims links to what look like documents; clicking through and approving app permissions hands over an access token that lets hackers read and send email. The FBI says password changes won't stop the attack—victims must revoke the token in their account's security settings—and notes the campaign has targeted "prominent" individuals and their families.

QR code phishing has hit record volume, with Microsoft logging a 146% jump in Q1 2026, from 7.6 million detections in January to 18.7 million in March, out of 8.3 billion phishing threats processed. ESET recorded roughly 100,000 QR phishing detections monthly, led by the US (19%), Spain (17%) and Mexico (6%), with QR codes appearing in about 11% of phishing emails. Attackers increasingly hide malicious links in PDF attachments and embedded images to slip past email gateways and push victims to scan codes on less-protected mobile devices, with PDFs accounting for 70% of QR phishing activity by March.

Microsoft warned that attackers are using counterfeit installers impersonating Edge, Kaspersky, Razer and other software to breach enterprise networks across healthcare, manufacturing, gaming, technology, logistics, government and education. The campaign, tracked by Microsoft Defender Experts and consistent with the Silver Fox (Yinhu) activity, uses spoofed .com.cn and .hl.cn domains serving installers with static filenames but constantly changing hashes, then abuses msiexec.exe and SYSTEM-level scheduled tasks to disable Defender, delete shadow copies and block Windows Update for persistence.

Microsoft has identified a malware campaign using fake download sites cloned from trusted vendors, including Microsoft Edge, Kaspersky, and Baidu Pan, to trick users into installing malicious software. The activity, linked with moderate confidence to the Chinese threat cluster Silver Fox, primarily hits China-based operations of multinational firms and Chinese-speaking users across healthcare, manufacturing, gaming, and government sectors. The malware disables Windows Update services, adds Defender exclusions, deletes shadow copies, and communicates with C2 domains iualef[.]net and oijfwe[.]net over non-standard ports.

Nearly 22,000 internet-exposed Microsoft Exchange servers remain unpatched against CVE-2026-62911, a high-severity authentication bypass flaw in Exchange Server 2016, 2019 and Subscription Edition that lets attackers with basic access hijack all mailboxes on a server. Shadowserver found the exposed servers concentrated in the US (6,200) and Germany (5,100), and Germany's BSI says about 85% of on-premises Exchange servers there are still vulnerable. Microsoft patched the flaw in August 2026, and exploit code is reportedly circulating, though active exploitation hasn't been confirmed.

Quick Hits

Reply

Avatar

or to participate