August 26, 2026
- A forum actor is circulating target lists for two authentication-bypass flaws. DailyDarkWeb reports roughly 14,000 hosts potentially relevant to SharePoint CVE-2026-55040 and a separate list of roughly 24,000 internet-facing hosts for macOS Screen Sharing CVE-2026-65400. These are exposure claims, not proof of vulnerable versions or compromise.
· Vulnerabilities & Exploits
in Oracle WebLogic Is Under Active Attack
August 25, 2026
- Rapid7 published analysis of SharePoint RCE CVE-2026-63520. CERT-EU's updated advisory covers the wider on-prem SharePoint chain, noting public PoC code and observed exploitation of CVE-2026-50522 alongside CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644 — and recommends rotating credentials on any exposed server, not just patching (Rapid7, CERT-EU).
· Vulnerabilities & Exploits
in The Rogue Agent Staged an Apology, Then Pushed More Malware
August 24, 2026
- ShinyHunters named BOK Financial and CyrusOne, with the CyrusOne listing citing a rejected $13M demand and claiming 12.9 million Salesforce records plus 645 GB of uncompressed SharePoint data, 182,000+ customer rows and 8,300+ rows of employee PII (@DarkWebInformer). The group also claims to have breached security firm ReliaQuest but has published no proof (campuscodi).
· Threat Activity & Cybercrime
in Four Days Dark: Iran-Linked Intrusion Knocked a UK Power Plant Offline
July 23, 2026
- SharePoint CVE-2026-50522 exploitation widening. Following public exploit code (earlier coverage), watchTowr now reports active exploitation of on-prem SharePoint with attackers stealing machine keys for long-term persistence — and it is still not in CISA's KEV (watchTowr). Kevin Beaumont warns this out-of-the-box unauth RCE against mass-exposed SharePoint "will see mass exploitation" (discussion).
· Vulnerabilities & Exploits
in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident
July 3, 2026
- Cisco Talos dissected an EvilTokens affiliate panel branded ARToken, a phishing-as-a-service platform targeting Microsoft 365 with 80+ API endpoints for device-code phishing, Primary Refresh Token (PRT) persistence, mailbox access, BEC, and SharePoint exfiltration — sharing infrastructure with the EvilTokens kit documented by Sekoia and Microsoft. Related reporting covers ConsentFix/ClickFix OAuth token theft that hijacks accounts "in three seconds." Talos, BleepingComputer.
· Cloud & Identity
- CISA added CVE-2026-45659, a SharePoint Server RCE via untrusted-data deserialization (CVSS 8.8), to the KEV catalog after confirming active exploitation — despite Microsoft's earlier "exploitation less likely" assessment. BleepingComputer, The Register.
· Vulnerabilities & Exploits
in Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire