DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
A threat actor known for deploying Warlock ransomware by exploiting vulnerabilities in on-premises SharePoint servers since mid-2025. Uses tools like Velociraptor, Cloudflare…
Ransomware deployed by threat actor Storm-2603, often exploiting known vulnerabilities in on-premises SharePoint servers. Used in parallel with other techniques to establish…
Microsoft SharePoint is the affected product in CVE-2026-55040, a critical authentication bypass vulnerability. The flaw allows unauthenticated attackers to forge JWT tokens…
TWINLOOT authenticates to an attacker's Azure tenant and uses the Graph API to interact with SharePoint drives for command and control.
Microsoft SharePoint vulnerability (CVE-2026-55040) allows security feature bypass and is under active exploitation.