Daily Recap, phishing and malware activity stayed active, including EvilTokens compromising 12,000 Microsoft accounts, Contagious Interview infecting 30,000 devices and stealing $10.71M in crypto, and TASK#STOMP exfiltrating Wi‑Fi passwords, screenshots, and business files. Attackers also used fake LastPass and Google sign-in lures to deploy the Rapuncel stealer and other components, while defenders tracked newly patched and actively exploited flaws like D-Link DIR-822A (CVE-2026-86296, CVE-2026-86510) and a CISA-flagged Zyxel issue plus three Linux kernel vulnerabilities. #EvilTokens #ContagiousInterview #TASKSTOMP #Rapuncel #LastPass #DIR-822A #CVE-2026-86296 #CVE-2026-86510 #Zyxel
Malware & Phishing
- Phishing and malware operations continued to spread, with EvilTokens compromising 12,000 Microsoft accounts, Contagious Interview infecting 30,000 devices and stealing $10.71M in crypto, and TASK#STOMP exfiltrating Wi‑Fi passwords, screenshots, and business files. – EvilTokens, Contagious, TASK#STOMP
- Attackers used fake LastPass and Google sign-in lures to deploy a kernel-level EDR killer, the Rapuncel stealer, and bogus AI subscription pages. – LastPass, AI Scams
Vulnerabilities & Exploitation
- D-Link warned of a maximum-severity zero-day in DIR-822A routers (CVE-2026-86296) plus a second public-PoC flaw (CVE-2026-86510), while urging users to keep devices off the internet. – D-Link Zero-Day
- CISA ordered federal agencies to patch an actively exploited Zyxel bug linked to data theft and flagged three Linux kernel flaws under active exploitation. – Zyxel Flaw, Linux Flaws
- WordPress patched the Click2Shell vulnerability, which could let attackers run PHP on the server. – Click2Shell, Click2Shell Exploit
- A new Windows Defender zero-day can block Microsoft antivirus updates, weakening endpoint defenses. – Defender Zero-Day
Cloud, Privacy & Platform Risk
- Google was fined €403 million and separately hit with a $463 million penalty over EU/GDPR location-data violations. – Google Fine, Location Fine, GDPR Fine
- BigCommerce warned merchants of a data breach tied to Ribon apps, highlighting supply-chain exposure in e-commerce ecosystems. – BigCommerce Breach
- Microsoft said it will retire Microsoft 365 Companion apps in December and fixed broken Excel copy/paste for all users. – Companion Apps, Excel Fix
Identity, AI & Social Engineering
- Deepfake and impersonation risks are rising, with new data showing more CISO concern over voice-cloning and CEO-style fraud used to steal intellectual property. – Deepfake Risks, CEO Impersonation
- The US proposed an AI incident alert system in talks with China as governments weigh safeguards for model failures and abuse. – AI Alert System
- Fastly announced real-time controls for enterprise AI models and agents, aiming to improve governance and runtime oversight. – Fastly AI
Regional Threats & Infrastructure
- Japan dismantled its first North Korean laptop farm as US and allies detailed a wider remote-work fraud scheme. – Laptop Farm
- Water utilities face new exposure concerns after researchers found infostealer data tied to the sector. – Water Exposure
- A cheap fake base station can still track 5G subscribers, underscoring ongoing telecom privacy risks. – 5G Tracking
Compliance & Policy
- NIS2 compliance guidance and a pending CISA workforce assessment reflect mounting pressure on security teams and public-sector readiness. – NIS2 Guide, CISA Assessment
- A webinar promises real-world lessons from Google Workspace breach investigations. – Workspace Webinar
- Passwork released an efficiency guide to help teams save time before the 2026 audit. – Passwork Guide