O-UNC-066 uses voice phishing combined with deceptively authentic phishing websites and manually controlled PHP panels to steal access from Microsoft 365 customers.
Passwords remain widespread in enterprises because they are familiar, not because they are secure — security teams are therefore migrating to identity-based authentication.
Faster detection reduces financial damage from individual breaches, but does not prevent the underlying compromise — only prevention lowers structural risk.
Atlassian Bamboo, Bitbucket, Confluence, Crucible, Fisheye and Jira are affected by multiple vulnerabilities enabling code execution and security bypasses.
An unpatched denial-of-service vulnerability in Alibaba’s XQUIC library enables HTTP/3 server crashes through simple, protocol-compliant QPACK requests; Alibaba has not responded since April 2026.
SAP patches three critical security vulnerabilities (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761) in NetWeaver, AppRouter and Commerce Cloud that enable memory corruption, DoS attacks and token theft.
State-backed Russian hacker groups such as Berserk Bear and Energetic Bear infiltrate routers through outdated firmware and default configurations to gain long-term network access — not solely through zero-day exploits.