Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, compromising hospitality-related networks worldwide to steal credentials, access cloud environments, and deliver malware to travelers. https://t.co/bnizYidwOk
Since early May 2026, the threat actor has conducted widespread but targeted traffic manipulation attacks involving networks served by captive portals. In some cases, users were redirected through actor-controlled phishing infrastructure, while other activity led to the delivery of malware on impacted systems.
Microsoft assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard and details the malware, tradecraft, and cloud-focused techniques used throughout the campaign, including device code phishing and credential theft activity targeting travelers.
Get detections, mitigation, and hunting guidance from this Microsoft Threat Intelligence blog post.
The systematic guide to bypassing XSS filters and WAFs.
Learn the methodology that maps filter behavior, exploits human assumptions, and finds bypasses others miss.
https://t.co/VitLMY22oI
Proofpoint published research on OWAReaper, a browser implant exploiting CVE-2026-42897 in Outlook Web Access.
What stands out is that everything happens inside the browser. It uses GitHub queries for commands and CDN proxies or DNS tunnelling for exfil. For most orgs out there, this is impossible to detect...
All it takes is a crafted email that triggers JS inside an authenticated OWA session in the browser. The XSS executes under the context of the victim’s session permissions.
OWAReaper can:
�� Steal mailbox data
• Persist through localStorage and IndexedDB
• Use GitHub commit search for C2
• Exfiltrate through CDN proxies and DNS tunneling
Patching blocks initial exploitation, but existing persistence may remain.
If you're running on-prem Exchange, first of all, I'm sorry 😂; you should hunt for suspicious mailbox permissions, OAuth tokens, and browser storage artifacts. Also check for unusual GitHub, CDN, or DNS traffic that matches the pattern from this article (good luck with that).
https://t.co/rwapeZihyR
🛑 One malicious webpage visit was enough to compromise Tor Browser. No settings changes. No extra clicks.
Firefox JIT flaw, CVE-2026-10702, runs code inside the browser’s renderer process and forms the first stage of an Android 17 root chain.
Read how the exploit works: https://t.co/92ObVWyORg
‼️🚨 CVE-2026-63030 // wp2shell-poc: Proof-of-concept for an unauthenticated SQL injection in WordPress core that chains to remote code execution, via REST batch route confusion.
PoC: https://t.co/ZZIufPdeKR
Today the UK’s National Crime Agency (NCA) announced that Thalha Jubair and Owen Flowers, members of the Scattered Spider criminal group, were each sentenced to five years and six months imprisonment for conducting a cyberattack targeting Transport for London. Flowers was also sentenced for infiltrating and damaging the networks of 2 US-based healthcare companies.
International coordination is critical to countering groups like Scattered Spider, whose members continue to victimize organizations around the world and cause significant financial and operational harm. We will continue to investigate cybercriminal actors, disrupt their activities, and hold them accountable.
https://t.co/DFZAJqZhKq
Every time Brazil play, our 🇧🇷 servers get flooded.
We assume Brazilians abroad are connecting to our Brazil servers to watch the World Cup for free on the CazéTV YouTube channel.
We've added a bunch more servers to help with that. Please don't break these too.
> Peter Stokes
> Scattered Spider guy
> Arrested
> Microsoft helps FBI
> Read court documents
> Page 12
> Microsoft tracks Stokes from GDID
> Microsoft Global Device Identifier (GDID)
> Stokes used Windows
> Page 34
> GDID assigned to each OS install
> GDID unique to each device
> GDID only change if OS wiped
> Stokes GDID 6755467234350028
> GDID reported internet activity to Microsoft
> GDID showed Stokes using Ngrok
> GDID reported Stokes IP address
> GDID showed Stokes web activity
> GDID showed timestamps of web activity
> GDID mapped with video game activity
> GDID showed games played
> GDID undocumented
> GDID only mentioned in one MSDN document
> Azure UCDOStatus
> Azure Monitor Logging
‼️🚨 An alleged member of the criminal cyber hacking group Scattered Spider has been arrested in Finland and extradited to the United States to face federal criminal conspiracy charges in the Northern District of Illinois
Back in April 10, 2026, Peter Stokes, a 19-year-old Estonian-US dual citizen known by the online alias "Bouquet", was apprehended at Helsinki Airport in Finland while attempting to board a flight to Japan.
More: https://t.co/Jp1n00d9vo
Really liked this SpecterOps write-up.
EDR gives defenders visibility and response options you absolutely want.
But no serious attacker treats EDR as the end of the road. They probe, learn, change their approach, and try again.
SOTA LLMs make that process faster.
EDR is critical. It is not magic.
https://t.co/RZyb8297Qh
➡️ New report out today by Jake, Dino, Ahmed Farouk, @MittenSec, @angelo_violetti, and @r3nzsec.
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
🔎 A user searching for ManageEngine OpManager was led to a fake download site and installed a trojanized MSI.
🐝 That install launched BumbleBee, which brought in AdaptixC2 and gave the threat actor a foothold in the network.
🔐 From there, the actor created privileged accounts, moved to domain controllers and backup servers, dumped credentials, and exfiltrated data.
💥 The intrusion ended with Akira ransomware across the root domain, followed by a return two days later to encrypt a child domain.
https://t.co/vLNQaelbna
#FortiBleed Update
Even top-tier threat actors make rookie mistakes. 🤦♂️
The crew behind the massive #FortiBleed campaign accidentally left their operational server exposed. We took a look inside, and the breadcrumbs are wild:
🎯 Defense industry VPN creds
🎯 Heavy NATO targeting bias
🎯 Russian-speaking fingerprints
The biggest plot twist? We’ve officially linked this operation to the Lynx / INC ransomware group.
The full technical teardown is dropping soon. Keep an eye out for the timely alerts you need to mitigate risks and strengthen your security posture. 👀👇
https://t.co/3QZHmuFLyK
#CyberSecurity #ThreatIntel #Fortinet #Ransomware #SOCRadar
Two young men have admitted mounting a cyber attack on Transport for London (TfL), which cost tens of millions of pounds in losses and inconvenienced thousands of customers.
The NCA and @CityPolice investigated Thalha Jubair and Owen Flowers after TfL’s network was infiltrated between 31 August and 3 September 2024.
Jubair and Flowers, who were arrested last year were both members of the online criminal collective known as Scattered Spider.
Read the full story ➡️ https://t.co/JrZQt8zPBN