Microsoft fixed a remote code execution flaw in SharePoint caused by deserialization of untrusted data that can be exploited by an authenticated attacker with low complexity and no user interaction. The bug impacts SharePoint Server Subscription Edition, 2019, and 2016 — enterprises should prioritize patching due to broad deployment and likely rapid exploit development.
Source: Help Net Security
Trend Micro Apex One zero‑day actively exploited; CISA issues warning (CVE-2026-34926)
A path traversal vulnerability in Trend Micro’s Apex One endpoint platform has been exploited in the wild, with Trend noting observed attempts and CISA flagging urgent risk. Organizations should apply available updates immediately, review Apex One telemetry for suspicious file paths, and harden EDR management interfaces.
Source: Help Net Security
FBI flags Kali365 kit abusing Microsoft’s device code flow to steal tokens — no password needed
A phishing-as-a-service called Kali365 abuses Microsoft 365’s OAuth device code flow to obtain access tokens after victims complete MFA on legitimate Microsoft pages. Because MFA fires on the victim’s device, not the attacker’s, defenders should restrict device code flow via Conditional Access, monitor refresh-token usage, and enforce out‑of‑band verification for resets.
Source: Bitdefender Hot for Security
CISA urges immediate patching of exploited LiteSpeed cPanel plugin zero‑day
An already-resolved flaw in the LiteSpeed cPanel plugin was exploited as a zero‑day to execute scripts with root privileges on Linux servers. Hosting providers and site operators should update the plugin without delay and review systems for signs of post‑exploitation persistence.
Source: SecurityWeek
700+ education and tech sites hijacked via Ghost CMS flaw to push “ClickFix” malware
Attackers abused a Ghost CMS vulnerability to compromise hundreds of legitimate sites, serving fake Cloudflare verification pages that pressure users into installing malware. The campaign blends SEO and brand impersonation; organizations should patch Ghost CMS, audit themes/plugins, and warn users against unexpected “verification” prompts.
Source: Malwarebytes Labs
LA Metro breach linked to Iranian state‑sponsored infrastructure
An attack initially claimed by a hacktivist persona has been tied to infrastructure used by Iranian government threat actors, underscoring ongoing risks to U.S. critical services. The incident reportedly took weeks to recover from, highlighting the operational impact when transit and public systems are targeted.
Source: SecurityWeek
Google TIG: Chinese‑language phishing‑as‑a‑service ecosystems surge
Google’s Threat Intelligence Group reports mature Chinese‑language PhaaS offerings increasingly rival traditional Russian‑language markets, largely targeting non‑Chinese entities. Services marketed via Telegram bundle kits, hosting, and support, signaling broader accessibility and scale for credential theft operations.
Source: Help Net Security
You May Also Be Interested In... Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data
Drupal SQL injection CVE-2026-9082 added to CISA KEV amid active attacks
‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems