CISA has added four critical, actively exploited vulnerabilities in macOS, SharePoint, vCenter and Microsoft IKE to the KEV catalog, including CVE-2026-65400 with a CVSS score…
The newly discovered Python implant TWINLOOT uses SharePoint Online and Microsoft Teams as complete command-and-control infrastructure, thereby bypassing classic network-based detection mechanisms.
TWINLOOT abuses SharePoint, Teams TURN, and the victim’s own Edge instance as command-and-control channels within legitimate Microsoft infrastructure, thereby evading detection systems that blanket-trust Microsoft…
A critical SharePoint authentication bypass vulnerability (CVE-2026-55040, CVSS 9.1) is being actively exploited following the publication of a PoC, and unpatched systems should be updated…
Attackers compromised the SharePoint servers of the Swiss Federal Office of Information Technology, taking over hundreds of user accounts in the process.
Attackers exploit CVE-2026-50522 to steal machine keys from SharePoint servers, enabling them to generate valid authentication tokens and maintain persistent access even after patching.