The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming active…
Cybersecurity researchers have uncovered a new Python-based implant framework called TWINLOOT that abuses trusted Microsoft services for command-and-control (C2) operations. The malware,…
Backdoor.TurnBroadcomC2 infrastructureCarbon Black
TWINLOOT is a modular Python implant hardened with PyArmor that uses SharePoint Online and Microsoft Teams TURN relays for command-and-control. It steals…
Microsoft SharePoint Weak Authentication Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based…
CVE-2026-63520 is the code execution component of a SharePoint exploit chain, fixed in August 2026. Chaining with CVE-2026-55040 enables unauthenticated RCE.