Related Threat Clusters
-
Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…
57 articles · Updated June 9, 2026 -
Critical CVE-2026-69836 in Microsoft Entra ID Exploited in the Wild
Microsoft disclosed a critical remote code execution vulnerability in Entra ID, tracked as CVE-2026-69836, which has been actively exploited in the wild. This flaw, stemming from unsafe deserialization of untrusted…
42 articles · Updated August 21, 2026 -
Microsoft Exchange 'Ghost-Sender' Flaw Enables Widespread Email Spoofing
A newly identified vulnerability in Microsoft Exchange, termed 'Ghost-Sender', allows attackers to spoof any email address, bypassing standard email authentication controls. This flaw affects organizations using…
2 articles · Updated June 9, 2026 -
Microsoft Exchange Online Misclassifies Legitimate Emails as Phishing
Microsoft is investigating an incident affecting Exchange Online that began on February 5, 2026, where legitimate emails are being incorrectly flagged as phishing and quarantined. This issue has disrupted business…
13 articles · Updated February 10, 2026 -
Fraudsters Exploit Help Desks to Redirect Employee Paychecks
In December 2025, fraudsters executed a simple attack that involved a help-desk call to redirect a physician's salary into their own account. This incident, investigated by Binary Defense's ARC Labs, highlights…
4 articles · Updated February 11, 2026 -
Microsoft Exchange Online to Deprecate SMTP AUTH Basic Authentication
Microsoft is set to deprecate SMTP AUTH Basic Authentication for all Exchange Online tenants. This change addresses security vulnerabilities associated with sending usernames and passwords in clear text, which can be…
2 articles · Updated January 29, 2026
Recent Intelligence Reports
- Threataft Blog News Aug 21, 2026 CVE-2026-65801: Microsoft Exchange Online SSRF - CVSS 10 threataft.com Open source — threataft.com · August 21, 2026
- June 2026 Monthly Patch — Csa.Sg · June 10, 2026
- Ghost — Gbhackers · June 9, 2026
- Payroll pirates are conning help desks to steal workers' identities and redirect paychecks — www.theregister.com · April 11, 2026
- Payroll pirates conned the help desk, stole employee's pay — Theregister · February 11, 2026
- Payroll pirates are conning help desks to steal workers' identities and redirect paychecks — Theregister · February 11, 2026
- Microsoft Exchange Online Flags Customers Legitimate Email as Phishing — Cybersecuritynews · February 9, 2026
- Microsoft Exchange Online to Deprecate SMTP AUTH Basic Authentication for Tenants — Cybersecuritynews · January 29, 2026