THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Talos: ARToken phishing-as-a-service targets Microsoft 365 with device-code and token persistence

Cisco Talos reports ARToken as a phishing-as-a-service platform focused on Microsoft 365 accounts, exposing 80+ API endpoints used to automate attacks. The kit supports device code phishing, Primary Refresh Token persistence, BEC operations, and SharePoint data exfiltration—meaning attackers can move beyond initial login into ongoing account access. For defenders, the big takeaway is to monitor for token abuse and anomalous OAuth/device-code flows, not just credential theft.

Source: Cisco Talos


Ousaban campaign: steganography and phishing PDFs geofenced to Spain and Portugal

FortiGuard Labs details ongoing Ousaban attacks targeting the Iberian Peninsula using phishing PDFs that blend evasion techniques (including steganography) with geographically aware targeting. The campaign starts with lures designed to prompt user interaction, then shifts to evasive C2 behavior to reduce detection and prolong access. Organizations with users in these regions should tighten controls around PDF-driven social engineering and validate suspicious “update” prompts and embedded content.

Source: FortiGuard Labs (Fortinet)


AI-assisted malware gets practical: “browser-native ransomware” emerges from model-driven reasoning

Check Point Research describes a scenario where an AI model independently connected a theoretical browser weakness to a working ransomware technique, without traditional exploitation steps, installs, or attacker expertise. The result is malware logic that operates inside the browser context—blurring the line between “tooling” and “weaponization.” The key insight for security teams: assume agentic systems will increasingly translate concepts into functional attack chains, so browser and endpoint telemetry must be treated as primary defensive inputs.

Source: Check Point Blog


Exposure management under pressure: vulnerabilities take a larger share of critical risk, but few alerts validate

Check Point’s 2026 Exposure Gap Report highlights a sharp rise in vulnerabilities accounting for 42.6% of critical exposure (up from 18.7% in 2025). Equally important: only a small portion of vulnerability alerts are validated as truly exploitable, reinforcing that prioritization must be context-driven. The practical takeaway is to invest in exploitability validation, environment-aware scoping, and rapid remediation workflows rather than treating alert volume as a security strategy.

Source: Check Point Blog


CISA adds SharePoint RCE CVE-2026-45659 to KEV after active exploitation

CISA warned that threat actors are actively exploiting a SharePoint remote code execution vulnerability (CVE-2026-45659) after it was added to the KEV catalog. This class of issue matters because RCE in collaboration platforms can lead to rapid lateral movement and credential access, especially where SharePoint-integrated workflows are broadly accessible. Teams should immediately confirm patch status (and compensating controls where patching is delayed) and hunt for signs of exploitation attempts consistent with deserialization-based payload delivery.

Source: SecurityWeek


Progress Kemp LoadMaster: pre-auth RCE shows active exploitation attempts

Multiple reports indicate that Progress Kemp LoadMaster’s pre-auth command injection flaw (referenced as CVE-2026-8037 / CVSS 9.6) is seeing exploitation attempts in the wild. Pre-auth RCE is especially dangerous because it removes authentication from the attacker’s path, turning internet exposure into a direct breach route. Organizations running LoadMaster should prioritize patching, validate whether any systems are exposed, and review logs for command execution or anomalous appliance behavior.

Source: SCMagazine / Huntress coverage


You May Also Be Interested In... Chrome needs another whopper update to fix 382 security bugs
What the AI patch gap means for enterprise security
Catching ransomware on the wire before it locks the file server
Cybersecurity — July 2, 2026 | Briefing24