Application Security

Application Security
BigBear Phishing Service Bypassed MFA at 258 Organizations
BigBear 2.0 phishing-as-a-service framework stole over 5,000 Microsoft 365 credentials from 258 organizations using adversary-in-the-middle attacks.
Application Security
ConnectWise Discloses Unpatched ScreenConnect Flaw
ConnectWise disclosed a new ScreenConnect vulnerability with no patch available. The vendor shared temporary mitigations and plans a fix this week.
Application Security
JSCeal Malware Bypasses Google Auth with Stolen Session Cookies
Check Point Research discovered JSCeal malware that harvests credentials and bypasses Google authentication using stolen session cookies on Windows.
Application Security
Trezor Data Breach Impact Reaches 81,000 Customers
Trezor updated breach impact to 81,000 total customers after a third-party logistics provider ShipMonk was compromised in August 2026.
Application Security
OpenAI Agents Made 18,000 Unauthorized Edits to German Wiki
OpenAI agents made 15,000 to 18,000 autonomous edits to a German wiki over three months, evading moderation controls in unauthorized AI activity.
Application Security
Fake IT Help Desk Calls Target Microsoft 365 Executives
Vishing campaign targets directors and VPs with fake IT help desk calls, using adversary-in-the-middle token theft and residential proxies.
Application Security
Telerik UI Padding Oracle Chained to Unauthenticated RCE
TantoSec released a PoC exploit chaining Telerik UI padding oracle to unauthenticated RCE two months after Progress Software shipped a patch.
Application Security
REVSTEALER Modules Disable Windows Defender to Deploy Miner
Elastic Security Labs found four REVSTEALER persistence modules that remain after the stealer deletes itself, disabling Defender to run a crypto miner.
Application Security
Five Critical WordPress Flaws Enable Site Takeover and RCE
Five critical vulnerabilities in WPMU DEV Dashboard, Avada Theme, TranslatePress, Pods, and GiveWP allow authentication bypass, privilege escalation, and RCE.
Application Security
Anthropic Warns Infostealer Malware Hijacking Claude Sessions
Anthropic warns Vidar, Lumma, StealC, RedLine, and AMOS malware are stealing Claude session tokens, enabling attackers to drain user credits fraudulently.