🕵️ RESEARCH & DEEP DIVES
-
HollowGraph malware uses Microsoft 365 calendar for stealthy C2 communications — BleepingComputer
HollowGraph malware abuses Microsoft 365 calendar events to receive commands and exfiltrate data, targeting organizations in Israel.- Targets Microsoft 365 mailboxes, focusing on organizations in Israel
- Uses Microsoft Graph API with hardcoded credentials to access mailbox calendar
- Commands and stolen data hidden in calendar events dated May 13, 2050
- Employs hybrid RSA and AES-256-GCM encryption for secure C2 communication
- Uses DNS tunneling via IPv6 AAAA queries to update Microsoft Entra ID credentials
-
Authenticated RCE in EGroupware via Malicious eTemplate Upload (CVE-2026-40187) — CVE ThreatInt
Authenticated administrators can execute OS commands on EGroupware servers by uploading malicious eTemplate XML files.- Applies to EGroupware versions 26.0 and earlier
- Vulnerability allows OS-level Remote Code Execution (RCE)
- Exploited by uploading a malicious eTemplate XML file (.xet) to the /etemplates VFS mount
- Attack leverages PHP eval() call with unescaped backtick characters to execute shell commands
- Requires authenticated administrator privileges to exploit
-
Exposed Server Reveals AI-Assisted Phishing Toolkit Targeting Windows via WebDAV — The Hacker News
An AI-assisted phishing toolkit delivers infostealers via WebDAV shares to Windows users, primarily in Mexico.- Targets Windows users, primarily in Mexico, via fake government ID lookup sites
- Delivers infostealer malware through WebDAV shares using .scr executables disguised as PDFs
- Exploits WebDAV working-directory hijack vulnerability (CVE-2025-33053) and tests 59 signed binaries for hijack
- Operator used generative AI tools to develop, test, and document phishing delivery methods
- Campaign logged 77,098 requests over 5.5 days with 96.9% launch activity from Mexico
-
Attackers Use 'TFF Trap' Fileless Loader to Deploy RATs in BEC Phishing Campaigns — Dark Reading
Attackers use fileless loaders in business email compromise phishing campaigns to deploy multiple remote access trojans and stealers.- Targets include victims of business email compromise (BEC) phishing campaigns
- Delivers remote access trojans (RATs) and stealers like Agent Tesla, Remcos, XWorm, Best Private Logger
- Uses fileless techniques and loaders with low detection rates to evade security tools
🔓 CVEs & KEV
- 19 CVEs reported with the worst scoring 8.0 — Various sources