
Attackers Use BYOD Weaknesses to Access M365 via Graph API
Threat actors exploit BYOD gaps through vishing to gain M365 access, then use Microsoft Graph API to enumerate corporate structure

Threat actors exploit BYOD gaps through vishing to gain M365 access, then use Microsoft Graph API to enumerate corporate structure

Cybercriminals harvest AI session tokens from infostealer malware logs to hijack Google, Anthropic, and OpenAI accounts, bypassing MFA through token

Google released Chrome security update on September 9 patching CVE-2026-87491, an out-of-bounds write in V8 engine — the seventh actively

SophosLabs published analysis of PoisonedRefresh, a fileless Linux rootkit that injects PHP web shells directly into F5 BIG-IP APM Apache

Security researchers disclosed a vulnerability in OpenAI’s Artifactory enabling unauthorized cross-account artifact access and covert data exfiltration.

Boston Scientific disclosed that an August cyberattack will materially impact Q3 and full-year sales and earnings. Recovery is taking longer

Researchers disclosed PEEP, a toolkit that hijacks Chrome and Edge browsers as backdoors by injecting malicious extensions that execute host

Zero-day StyleSmuggler flaw enables code execution on all Magento and Adobe Commerce versions. Attackers deploy Linux backdoors on e-commerce sites.

Hackers are exploiting two chained MikroTik RouterOS vulnerabilities to take full control of routers with SSH services exposed to the

Security researcher Nightmare Eclipse publicly released proof-of-concept zero-day exploits for CrowdStrike, Nvidia, and Avast that escalate to System privileges.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.