New breach: Udemy had 1.4M email addresses leaked yesterday following an extortion attempt by ShinyHunters. Data included name, address, phone, employer info and instructor payout method. 56% were already in @haveibeenpwned. Read more: https://t.co/qxq9LkoMqs
🚨 Bitwarden CLI 2026.4.0 was compromised as part of the ongoing Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
We’ll continue updating our coverage as more details are confirmed.
https://t.co/G0aakn8swq
☁️ Azure Monitor Alerts Weaponized for 🎣 Callback Phishing
Threat actors are exploiting Microsoft Azure Monitor alerts to send phishing emails that look like legitimate Microsoft notifications. Because these alerts originate from [email protected] and pass SPF/DKIM/DMARC checks, they easily bypass traditional email defenses. The lure? Fake billing alerts urging recipients to call fraudulent support numbers—leading to credential theft or remote access compromise.
https://t.co/Al7PHoFmBe
To counter this, I’ve built a high-fidelity KQL detection leveraging the EmailEvents schema and the IsFirstContact field. For most enterprise users, receiving a first-contact email from [email protected] (without being Azure portal users) is a strong indicator of phishing callback attempts.
👉 Defenders: deploy this KQL to monitor inbound emails and flag suspicious Azure Monitor alert abuse.
KQL Code:
https://t.co/16siODK9Sy
#Cybersecurity #AzureMonitor #Phishing #DetectionEngineering
Microsoft introduces Backup and Recovery for Microsoft Entra ID!
Entra Backup and Recovery solution enables you to quickly recover from malicious attacks or accidental changes by reverting your core tenant objects to any previous state within the last 5 days.
With automated backups and granular recovery capabilities, it ensures minimal downtime and supports your business continuity in the face of unexpected disruptions.
Entra automatically generates one backup per day, retaining the last 5 days of backup history.
You can recover key properties of the following core tenant objects:
- Users
- Groups
- Applications
- Conditional access policies
- Service principals
- Organization
- Authentication methods
- Authorization policy
- Named locations
#EntraID #Microsoft365 #Microsoft
Threat Actors are "Bringing Their Own Forensics"
In a recent ClickFix campaign, we saw threat actors likely related to Interlock Ransomware, running Volatility (https://t.co/Vq0vkvWutb) directly on victim machines.
Commonly a tool for defenders, the TAs are using it to:
"On the Exchange email server, the threat actor used a legitimate Windows executable, SystemSettingsAdminFlows.exe, which allows users to customize or configure the system settings to user’s preference. This LOLBIN was used to disable Windows... "
Report: https://t.co/Mdbthjk2PA
⚠️ FortiOS Authentication Bypass Vulnerability Lets Attackers Bypass LDAP Authentication
Source: https://t.co/GLWZL6S5bz
Fortinet has disclosed a high-severity authentication bypass vulnerability in FortiOS, tracked as CVE-2026-22153 (FG-IR-25-1052), that could allow unauthenticated attackers to sidestep LDAP authentication for Agentless VPN or Fortinet Single Sign-On (FSSO) policies.
The flaw resides in the fnbamd daemon and requires specific LDAP server configurations enabling unauthenticated binds. The issue stems from improper handling of LDAP authentication requests.
An attacker could exploit this under certain setups, such as those permitting anonymous binds, to gain unauthorized access without valid credentials.
#cybersecuritynews #vulnerability
Today I am releasing the details about the FortiGate Symlink persistence method.
The patch could be byppassed and Fortinet has now fixed that: https://t.co/8OK4EstutC
PSIRT: https://t.co/uqCDmFW0I6
Tool here: https://t.co/4G2eBg2xVR
https://t.co/noySPASsVf
🚨 Yesterday, CISA added CVE-2026-24858 into their KEV list - an authentication bypass vulnerability in various Fortinet products, which enabled attackers with a FortiCloud account and a registered device to log into other devices registered to other accounts.
Per Fortinet PSIRT:
> This vulnerability was found being exploited in the wild by two malicious FortiCloud accounts, which were locked out on 2026-01-22.
Around this timeframe we observed actor(s) abusing Forticloud pathways, attempting to inject SP-initiated SAML state into a FortiCloud SSO login path using the hostname "abdylla.turkmenabat.]tech".
A notable data point in the payload is the SAML_SP_LOGIN_DUMP cookie, which Fortinet uses to persist and validate Service Provider-initiated SAML login state, ensuring that only authentication responses corresponding to a locally initiated session are accepted. This is a fairly strong indication of an attempt to replay or inject SAML authentication state via an "alternate authentication path", as CVE-2026-24858 is described to be abusable via, but this analysis should currently be treated as unverified.
185.246.188.74 belongs to a TOR exit node.
MDO:⛔Ability to block external Teams user via Defender Portal
MC1200058 - Roll out starts in Jan 2026 integration between Microsoft Teams and Microsoft Defender for Office 365 that allows security admins to manage blocked external users in Teams through the Tenant Allow/Block List (TABL) in the Microsoft Defender portal.💪
#Cybersecurity #Teams #TABL
The BBC documentary I was in on the retail cyber attack is now out on iplayer!! It was great to see @J4vv4D on there too!
It’s a good documentary and should be a salient reminder to all businesses it can happen to anyone so prepare now!
https://t.co/q5CxGvVUB3