daily cyber × ai intelligence

index

tagged

[sharepoint]

5 editions · 6 items

July 23, 2026

  • SharePoint CVE-2026-50522 exploitation widening. Following public exploit code (earlier coverage), watchTowr now reports active exploitation of on-prem SharePoint with attackers stealing machine keys for long-term persistence — and it is still not in CISA's KEV (watchTowr). Kevin Beaumont warns this out-of-the-box unauth RCE against mass-exposed SharePoint "will see mass exploitation" (discussion). · Vulnerabilities & Exploits

in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident

July 3, 2026

  • Cisco Talos dissected an EvilTokens affiliate panel branded ARToken, a phishing-as-a-service platform targeting Microsoft 365 with 80+ API endpoints for device-code phishing, Primary Refresh Token (PRT) persistence, mailbox access, BEC, and SharePoint exfiltration — sharing infrastructure with the EvilTokens kit documented by Sekoia and Microsoft. Related reporting covers ConsentFix/ClickFix OAuth token theft that hijacks accounts "in three seconds." Talos, BleepingComputer. · Cloud & Identity
  • CISA added CVE-2026-45659, a SharePoint Server RCE via untrusted-data deserialization (CVSS 8.8), to the KEV catalog after confirming active exploitation — despite Microsoft's earlier "exploitation less likely" assessment. BleepingComputer, The Register. · Vulnerabilities & Exploits

in Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire