Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

Attackers abuse npm and its mirrors to host fake CAPTCHA phishing pages

Researchers at OX Security found a campaign using two dozen npm packages as free phishing infrastructure rather than as malware aimed at developers. Each package is just a single HTML page, harmless to install, but once served through npm content-delivery mirrors like unpkg it becomes a live, fully rendered fake Cloudflare CAPTCHA page hosted on a trusted domain. The page then redirects victims to ClickFix-style phishing infrastructure, and while it currently forwards to a legitimate site, it can be reconfigured to deliver any phishing payload. The trick is not infecting people who install the packages, but abusing the registry and its mirrors as validated, reputable storage for attacker content.

Check
Treat fake CAPTCHA and ClickFix pages as hostile even when served from trusted domains like unpkg, and educate users not to run commands or steps a CAPTCHA prompt tells them to perform.
Affected
Anyone lured to a fake CAPTCHA page hosted on a trusted npm mirror; the pages redirect to ClickFix phishing, exploiting the reputation of legitimate infrastructure to bypass suspicion and some blocking.
Fix
Monitor and filter for HTML content served from package-mirror domains, block known phishing and ClickFix infrastructure, apply reputation-aware web filtering rather than trusting domains outright, and train users on fake CAPTCHA lures.

Mirage2FA phishing service hijacks Microsoft 365 sessions and bypasses two-factor

A commercial phishing-as-a-service toolkit called Mirage2FA has hit around 4,500 organizations by abusing legitimate Microsoft 365 login flows to steal passwords and session cookies and bypass two-factor authentication. Because it captures the session cookie after a real login completes, the attacker inherits an authenticated Microsoft 365 session and any single-sign-on connected services, defeating multi-factor authentication. Researchers at ANY.RUN linked the campaign to more than 9,000 potential compromise events and found that nearly half of targeted addresses may have been affected, with most victims in the United States across technology, manufacturing, and education. Hijacking one session can expand into connected apps and internal workflows.

Check
Move toward phishing-resistant authentication such as passkeys or hardware security keys, since attacker-in-the-middle kits like this defeat ordinary two-factor by stealing the session after login.
Affected
Microsoft 365 organizations relying on passwords plus standard two-factor authentication; Mirage2FA steals the post-login session cookie to hijack authenticated sessions and single-sign-on services, extending access well beyond the first account.
Fix
Adopt phishing-resistant multi-factor authentication, shorten session lifetimes and bind sessions to devices, monitor for anomalous token use and impossible-travel sign-ins, and revoke sessions on suspicion rather than trusting a successful login.

ShinyHunters leaks Carhartt data, but half the records were synthetic test data

The extortion group ShinyHunters published data stolen from workwear maker Carhartt after the company refused a 3.3 million dollar ransom, but analysis showed the leak was smaller than it first appeared. The raw dump held nearly 25 million email addresses, yet breach-tracking service Have I Been Pwned found millions were synthetic records that matched no real people, leaving about 12.9 million genuine addresses along with names, phone numbers, and physical addresses. A researcher traced the data to Carhartt's customer analytics warehouse, contaminated with a standard retail benchmarking dataset used for testing. The detailed contact and identity profiles still create real risk of targeted phishing for those affected.

Check
Affected Carhartt customers should be alert to targeted phishing and scam calls using their real name, address, and phone number, and treat unexpected messages referencing recent orders with suspicion.
Affected
About 12.9 million Carhartt customers whose emails, names, phone numbers, and physical addresses were leaked; the detailed profiles support convincing phishing, even though millions of the leaked records were synthetic.
Fix
For defenders, verify breach claims before reacting since raw dumps can be inflated with synthetic data, and keep test and benchmark datasets out of production stores that hold real records.

Attackers chain two miniOrange WordPress SSO flaws to forge admin logins

Attackers are exploiting two critical authentication-bypass flaws in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, chaining them to forge login responses and sign in as an administrator. The first flaw, CVE-2026-61979, lets the plugin accept an attacker-chosen signature algorithm, so the identity provider's public key can be abused as a shared secret to forge a valid signature; the second, CVE-2026-15981, makes the plugin treat a signature-verification error as success. Both were fixed in July, but the vendor only alerted free-edition users, leaving paid editions unpatched. Security firm Patchstack traced an attack in mid-August where the two were chained to steal an administrator session cookie.

Check
Update the miniOrange SAML Single Sign On plugin on all WordPress sites, including paid editions that were not alerted, and audit for unexpected administrator accounts and sessions.
Affected
WordPress sites using the miniOrange SAML 2.0 Single Sign On plugin (CVE-2026-61979, CVE-2026-15981); chaining the two lets an unauthenticated attacker forge a SAML response and obtain an administrator session.
Fix
Patch or remove the plugin, rotate WordPress salts and admin passwords to invalidate stolen sessions, check for rogue admins, and put a web application firewall in front of login endpoints.

Critical Keycloak flaw lets attackers take over any account via password reset

A critical flaw in Keycloak, the widely used open-source identity and access management server, lets an unauthenticated attacker take over any account through its password-reset flow. Tracked as CVE-2026-18963, the bug is improper state validation in the reset-credentials flow: a crafted request to the reset endpoint pushes the authentication session straight to the password-update step, so the action token Keycloak normally emails is never required, and the attacker sets new credentials for a chosen user. It needs no user interaction and works against any account, including administrators. Red Hat fixed it in Keycloak 26.7.2 and related releases; there is no confirmed exploitation yet.

Check
Upgrade Keycloak to a fixed release such as 26.7.2, and if you ran a vulnerable version, revoke active and offline sessions and rotate client secrets, since tokens may already have been issued.
Affected
Organizations running Keycloak with the forgotten-password feature enabled on a vulnerable version (CVE-2026-18963); an unauthenticated attacker can reset and take over any user or admin account without the email verification step.
Fix
Patch promptly, then treat exposure as possible account compromise: revoke sessions, rotate accessible client secrets, review identity links and admin permissions, and remember downstream services may hold tokens issued before patching.

Unpatched Calix router flaw lets attackers expose devices behind home networks

An unpatched flaw in Calix residential routers used by several US broadband providers lets a remote, unauthenticated attacker create port-forwarding rules that expose devices on the local network to the internet. Tracked as CVE-2026-75501, the missing-authentication issue affects the Calix GS7 XGS model on a specific firmware version, and Calix supplies gear to large providers including Cox and Brightspeed. The researcher who found it reported it to the vendor in June, got no response, and disclosed through CERT/CC after further attempts failed. Because it lets an attacker punch holes through the router's network address translation, internal devices that were never meant to be reachable can be exposed. No fix is available.

Check
If you operate or manage affected Calix broadband routers, ask the provider or vendor about a fix and mitigations, and check devices for unexpected port-forwarding rules exposing internal systems.
Affected
Networks behind affected Calix GS7 XGS routers on the vulnerable firmware (CVE-2026-75501); a remote, unauthenticated attacker can add port-forwarding rules that expose internal devices to the internet, and no patch exists.
Fix
Press the broadband provider and Calix for a firmware fix, restrict remote management where possible, monitor for unauthorized port-forwarding entries, and place sensitive internal devices behind an additional firewall until resolved.

Crime group uses AI to mass-hack servers and deploy a Linux rootkit backdoor

Cisco Talos detailed a financially motivated, Chinese-speaking group it tracks as UAT-10147 that breaks into internet-facing Windows and Linux web servers at scale and installs malware for data theft and search-engine-optimization fraud. The group weaves AI tools through its operations, from exploiting known vulnerabilities to generating payloads, and Talos even found AI-generated code comments left in the source of its Linux kernel rootkit. Its cross-platform implant, SPECTRE, offers credential theft, process injection, encrypted command-and-control, and driver-based bypassing of endpoint detection. Investigators also recovered prompt logs from AI coding assistants on the attackers' own machines, a concrete look at adversaries using the same agent tools defenders do.

Check
Patch internet-facing web servers promptly since the group exploits known flaws at scale, enforce protections that block unsigned driver loads, and deploy endpoint detection with kernel-level visibility on Windows and Linux.
Affected
Organizations running internet-facing IIS or Linux web servers with unpatched known vulnerabilities; the group gains access at scale, deploys a rootkit and cross-platform backdoor, disables endpoint detection, and steals credentials and data.
Fix
Prioritize patching exposed servers, enable hypervisor-protected code integrity to counter driver-based evasion, monitor east-west traffic from web servers to internal Linux hosts, and hunt for kernel rootkits and unexpected HTTPS beacons.

Teams help desk impersonation delivers SynkLoader and a fake lock screen

Researchers at Expel found a new malware toolkit, SynkLoader, spread through Microsoft Teams messages in which attackers pose as a company's IT help desk. Using their own Microsoft tenant and an onmicrosoft.com address for credibility, they talk an employee into installing a fake "PowerShell Cleaner" hosted on Microsoft's own Azure storage. Once installed, SynkLoader can load modules including a convincing full-screen fake Windows lock screen that captures the user's password, plus a reverse proxy, remote shell, and remote desktop control. Its focus on counting Active Directory systems suggests it is used by a ransomware group or access broker to size targets. The fake lock screen can be escaped with Alt+Tab or Ctrl+Alt+Delete.

Check
Tell staff to verify unsolicited IT-support messages in Teams through a known internal channel before installing anything, and hunt for unapproved MSI installs, new scheduled tasks, and in-memory PowerShell.
Affected
Organizations allowing external Teams messages, where an attacker impersonating IT support can deliver SynkLoader; it steals passwords via a fake lock screen and provides proxy, shell, and remote-desktop access toward likely ransomware.
Fix
Restrict or closely monitor external Teams communication, block untrusted MSI downloads and known command-and-control infrastructure, watch for suspicious scheduled tasks and Python or PowerShell activity, and train staff on help-desk impersonation lures.

Cisco patches nine Crosswork and Secure Workload flaws, five rated a perfect ten

Cisco released fixes for nine vulnerabilities across its Crosswork network-automation platforms and Secure Workload software, five of them rated 10.0. Four affect Crosswork Data Gateway, Network Controller, and Planning regardless of configuration, and include a SQL injection flaw, a missing-authentication flaw, and external control of the file system, each scored 10.0, plus an insufficiently protected credentials issue at 9.9. Five more affect Secure Workload in both cloud and on-premises deployments, led by a 10.0 improper access control flaw and a 9.9 command-injection flaw. Cisco found them in internal testing using AI models and says none are exploited yet, but there are no workarounds, so patching is the only fix.

Check
Upgrade Crosswork to 7.2.1-SP and Secure Workload to 3.10.9.1 or 4.0.4.16, and note that Secure Workload cloud tenants must still upgrade agent and connector software themselves.
Affected
Organizations running Cisco Crosswork 7.2.1 or earlier, or Secure Workload 3.10 or 4.0 branches; multiple 10.0 flaws allow SQL injection, authentication bypass, file-system control, and command injection, with no workarounds.
Fix
Apply the fixed releases promptly since there are no workarounds, prioritize internet-reachable instances, and for Secure Workload cloud deployments confirm agent and connector components are upgraded, not just Cisco's cluster.

Microsoft Defender's own boot driver can be turned against security tools

Check Point researchers showed at Black Hat that Microsoft Defender's own legitimately signed boot-time cleanup driver, BTR.sys, can be abused to delete security software during startup. The driver, bundled inside Defender to finish removing malware after a reboot, can perform arbitrary kernel-level file and registry operations, and a released proof-of-concept wiped the entire Defender stack from a fully updated Windows 11 machine with tamper protection on. Unlike bring-your-own-vulnerable-driver attacks, this uses a driver present in every Windows since Windows 7, so it cannot be blocklisted. It requires administrator rights with a specific privilege, so Microsoft considers it a trust-boundary issue rather than a bug and will not patch it.

Check
Restrict the SeLoadDriverPrivilege to only accounts that truly need it, since the technique depends on it, and build detection for unexpected loading of the BTR.sys boot driver.
Affected
Windows systems from Windows 7 through 11 where an attacker gains administrator rights with SeLoadDriverPrivilege; they can use Defender's own signed boot driver to delete endpoint security tools before those tools load.
Fix
Limit local administrator rights and the driver-load privilege, monitor for boot-time driver abuse and security services vanishing, and prioritize detection engineering while the technique is public but not yet seen in attacks.