August 18, 2026
- TWINLOOT hides its command-and-control inside trusted Microsoft services. The previously undocumented, PyArmor-hardened Python implant uses SharePoint Online files for tasking and abuses Teams and other Microsoft cloud services during credential theft, persistence and lateral movement. The Hacker News describes the framework’s modular design; Dark Reading covers its cloud-based evasion advantages. · Threat Activity & Supply Chain
in Three Fast-Moving Flaws Put GitLab and AI Infrastructure on Alert