SharePoint zero-day steals IIS keys; PhaaS operator arrested
Threat intel firm WatchTowr confirms attackers are exploiting the critical SharePoint RCE (CVE‑2026‑50522) to extract IIS machine keys, letting them retain footholds even after servers are patched. The bug enables unauthenticated code execution on on‑premise SharePoint Server, forcing admins to patch and immediately rotate machine keys.
Police in Germany and the US seized more than 200 servers, crippling Kratos, a phishing‑as‑a‑service platform used in ~15,000 campaigns per month across 35 countries. The service’s Indonesian developer was arrested, cutting off a lucrative €300k revenue stream and halting thousands of credential‑stealing attacks.
Project CAV3RN introduced a .NET Native AOT module that hides its command‑and‑control traffic inside Outlook calendar events via Microsoft Graph, and falls back to DNS AAAA replies when Graph auth fails. This dual‑use of everyday cloud services lets the malware blend in with legitimate traffic, complicating network detection and remediation.
Elastic Security Labs uncovered a DPRK‑aligned campaign that lured developers on Slack with fake coding‑interview jobs, then delivered a trojanized repository hidden inside SVG images. The payload steals browser passwords, crypto wallets, files and installs a Socket.IO remote‑access backdoor. Compromising a single developer gives attackers footholds for broader supply‑chain attacks.
Hackers accessed a subset of Craneware's environment and stole employee, customer and partner records, including many file names. While most data is non‑sensitive, the breach affects the firm that powers revenue and pharmacy systems for thousands of US hospitals, prompting regulator notifications and a market dip.
Subscribe free