Daily Recap, phishing activity escalates with an AiTM campaign abusing SharePoint to steal Microsoft credentials, compromise inboxes, and bypass MFA in the energy sector, while vishing kits synchronize fake login pages with live calls targeting Google, Microsoft, and Okta. Ransomware and exploits dominate the headlines, from Osiris using POORTRY to disable protections and exfiltrate data to Wasabi, to INC recovery of encrypted data and Ploutus ATM jackpotting linked to Tren de Aragua, alongside critical vulnerabilities in FortiCloud SSO, SmarterMail, InetUtils telnetd, and widespread security updates from GitLab, Outlook iOS, curl, and Teams. #SharePoint #AiTM #Microsoft #Google #Okta #Osiris #POORTRY #Wasabi #INC #Ploutus #TrenDeAragua #FortiCloudSSO #FortiOS #SmarterMail #InetUtils #telnetd #GitLab #Outlook #curl #Teams #Pwn2OwnAuto #FALSECUB #TamperedChef #NetNTLMv1 #MnCHOICES #ActiveDirectory
Phishing & Vishing
- Attackers abused SharePoint links in a multi-stage AiTM phishing campaign against the energy sector to steal Microsoft credentials, take over inboxes, create persistence via inbox rules, delete evidence, and tamper with MFA â SharePoint Phish, SharePoint Phish
- Commercial vishing/phishing kits now synchronize fake login pages with live callers to intercept MFA and SSO tokens (targeting Google, Microsoft, Okta), enabling large-scale helpdesk scams and account takeovers that only phishingâresistant methods like FIDO passkeys reliably stop â Vishing Kits, Vishing Kits, Vishing Kits
Vulnerabilities & Exploits
- Attackers are bypassing Fortinetâs FortiCloud SSO via CVE-2025-59718, creating admin accounts and exporting configs on devices reported as patched (affecting FortiOS 7.4.9/7.4.10); admins should disable FortiCloud SSO and audit for suspicious logins â Fortinet SSO, Fortinet SSO, Fortinet SSO
- An authenticationâbypass in SmarterMail (CVE-2026-23760) is being exploited to reset admin passwords and hijack instances soon after the patch was released â SmarterMail Flaw, SmarterMail Flaw
- A critical CVE-2026-24061 in GNU InetUtilsâ telnetd lets remote attackers bypass login and gain root via a crafted USER environment value and is being actively probed â InetUtils Telnetd
- Researchers revived and accelerated Linux page cache attacks (TU Graz), enabling precise keystroke and crossâcontainer spying across kernels back to 2003; only CVE-2025-21691 is mitigated so far â Page Cache
- CISA added four Known Exploited Vulnerabilities to its catalog; organizations should review the KEV list and apply mitigations immediately â CISA KEV
Ransomware & Crime Operations
- A new ransomware family called Osiris used a custom driver named POORTRY in a BYOVD-style attack to disable protections, exfiltrate data to Wasabi buckets, and deploy hybrid per-file encryption against a major foodâservice franchisee â Osiris Ransomware
- An operational security failure by the INC ransomware gang left Restic-based backups intact, allowing researchers to recover encrypted data from 12 U.S. organizations and produce detection rules â INC Recovery
- Two Venezuelans were convicted for ATM jackpotting using Ploutus malware and linked to the Tren de Aragua syndicate; they face deportation after sentences and restitution â ATM Convictions
Security Updates & Product Bugs
- GitLab released critical patch updates (18.8.2, 18.7.2, 18.6.4) fixing multiple highâseverity flaws including a 2FA bypass and DoS issues; selfâmanaged admins should upgrade immediately (may require DB migrations) â GitLab Patch
- Outlook for iOS (5.2602.0) can crash or freeze on iPad after a codingâflag change; Microsoft recommends workarounds (Airplane Mode) while a fix rolls out â Outlook iOS
- curl is ending its HackerOne bugâbounty program after a flood of lowâquality/AIâgenerated reports; HackerOne submissions accepted only until 2026â01â31, with direct GitHub reporting thereafter â Curl Bounty
- Microsoft Teams will add Brand Impersonation Protection to warn users of suspicious external VoIP calls (targeted release midâFebruary) to help prevent voiceâbased brand impersonation â Teams Warnings
Policy, Legal & Industry
- Germany expelled a Russian diplomat accused of spying on the Ukraine war effort after probes linked embassy contacts to alleged intelligence collection on military aid and drone testing sites â Diplomat Expelled
- Ireland will draft legislation to permit courtâauthorized lawâenforcement use of spyware and electronic scanning equipment, with claimed legal safeguards under development â Ireland Spyware
- A Spanish judge closed the probe into alleged Pegasus spyware surveillance after Israel failed to cooperate with information requests, citing breaches of international obligations â NSO Probe
- The UK House of Lords backed an amendment to ban children under 16 from social media within a year and ordered guidance and studies on digital consent and addictive design â Social Media Ban
- The Bank of Englandâs CBEST assessments found widespread failures in basic cyber hygiene across financial firms, urging sustained remediation in patching, identity, detection, encryption, and incident response â BoE Report
Research, Events & Contests
- At Pwn2Own Automotive 2026 researchers earned $1,047,000 for exploiting 76 zeroâdays across IVI systems, EV chargers, and car OSes; vendors have 90 days to patch before public disclosure â Pwn2Own Auto
- Weekly bulletins highlight attackers using everyday files and trusted services to gain access (e.g., FALSECUB, TamperedChef, malvertising), emphasizing lowâfriction and patient operations â ThreatsDay
- Live webinar on rethinking email security for midâsized orgs (1PM ET) will cover behavioral analysis, realâtime risk scoring, and AIâdriven defenses to stop sophisticated email attacks â Email Webinar
Breaches & Operational Security
- Manage My Health confirmed a lateâ2023 intrusion that accessed documents in the My Health Documents portal and warned of fraudsters impersonating the service for phishing while working with regulators and IDCARE â Manage My Health
- A weekly âIn Other Newsâ roundup covered major items including proposed âŹ1.2B GDPR fines, Mandiantâs NetâNTLMv1 rainbow tables, Cloudflare WAF bypasses, Snap Store hijacks, and large breaches like MnCHOICES â News Roundup
Operational Security & Identity
- Hybrid work has driven surging Active Directory password resets and remote lockouts, increasing helpdesk costs; selfâservice credential tools can reduce workload and save organizations significant sums â AD Resets
- An industry perspective warns that unmanaged IT/OT/IoT and cloud assets act as unseen attack portals (âUpside Downâ), calling for continuous visibility, segmentation, and crossâfunctional response to prevent lateral spread â Upside Down