Daily Recap, Microsoft 365 experienced a service outage impacting Teams and SharePoint, while Exchange Online also faced a mailbox quarantine issue during active repair. Multiple Linux and application risks were reported, including the RefluXFS root-privilege flaw and the Windmill authentication-bypass data exposure being exploited, alongside new threats such as msaRAT routing C2 through Chrome and Edge. #Microsoft365 #Teams #SharePoint #ExchangeOnline #RefluXFS #root #Ubuntu #snap-confine #Windmill #Chrome #Edge #msaRAT
Microsoft Issues
- Microsoft 365 users faced an outage affecting Teams, SharePoint, and other services while Exchange Online also saw a mailbox quarantine issue under active repair β M365 Outage, Mailbox Fix
Linux & Desktop Flaws
- A new RefluXFS Linux flaw can let local attackers gain root privileges, adding to a separate Ubuntu snap-confine bug that could also grant root on default desktop installs β RefluXFS Flaw, Ubuntu Root
- A Windmill vulnerability is being exploited to read arbitrary server files without authentication, exposing sensitive data on vulnerable systems β Windmill Flaw
- An Adobe Acrobat extension flaw could let malicious sites read WhatsApp Web data, widening browser-based privacy risk β Acrobat Flaw
Malware & AI Threats
- New msaRAT malware hides its command-and-control traffic by routing through Chrome and Edge browsers, making detection harder β msaRAT
- JadePuffer agentic attacks are now targeting AI model data with ransomware, showing how generative AI systems are becoming direct extortion targets β JadePuffer
- Malware is also being used against AI tools in software development environments, reinforcing growing supply-chain and GenAI risk β AI Tool Attack, GenAI Risk
Enterprise Breaches & Ransomware
- Upbound said a breach led to $13 million in fraudulent Acima leases, highlighting the financial impact of account compromise β Upbound Hack
- Stadler, the Swiss rail giant, rejected a $12.3M ransom demand after a cyberattack, underscoring continued pressure from extortion crews β Stadler Ransom
- Suno and Paidwork disclosed breaches affecting tens of millions of accounts, adding to a wave of large-scale exposure incidents β Mass Breaches
Government, Policy & Geopolitics
- Check Point warned that a SmartConsole zero-day is being exploited in attacks, while federal agencies broadened an alert on Iran-linked OT activity β SmartConsole Zero-Day, Iran OT Alert
- South Korea disclosed a data breach impacting diplomats worldwide, and the White House accused a Chinese company of distilling Anthropicβs Fable model β Korea Breach, AI Distillation
- CISA info-sharing protections were extended in the House defense bill, while a study found most federal cyber reporting rules are duplicative β CISA Extension, Rules Study
- France moved toward a social media ban for under-15s, reflecting rising regulatory pressure on online platforms β France Ban
- ANCHOR-CI was proposed as a way to repair decades of broken government-industry collaboration on critical infrastructure β ANCHOR-CI
Supply Chain & Security Research
- GitHub is cutting public bug bounty payouts and moving top rewards to a VIP tier, changing incentives for researchers β GitHub Bounty
- Palo Alto Networks announced plans to acquire observability platform provider Embrace, signaling continued consolidation in security tooling β Palo Alto Deal
- An InfraTrust report outlined which infrastructure flaws admins should patch first to reduce exposure more quickly β InfraTrust Report