Passkey-Themed Phishing Attacks Lead to Microsoft 365 Data Theft
Article Link: https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/
- Microsoft says groups linked to ShinyHunters, Helix, and other extortion operations are using passkey and single sign-on lures to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.
- Attackers research employees, impersonate IT help desks by phone or message, then direct victims to fake Microsoft login pages or legitimate device-code authentication flows that grant access to attacker-controlled applications.
- Once inside, operators inspect assigned applications, authentication settings, SharePoint, OneDrive, Outlook, and other connected services. Microsoft observed data collection lasting hours or days, helping the activity blend with normal business traffic.
- Microsoft recommends phishing-resistant multifactor authentication, limiting sensitive cloud resources to managed devices, and disabling device-code authentication when unnecessary. Compromised accounts require revoked sessions and tokens, reset credentials, removal of attacker-added authentication methods, and fresh enrollment of legitimate methods.
What does this mean for me?
- Attackers are adapting to newer authentication methods by tricking users rather than breaking the technology itself. Be cautious of unexpected calls, texts, or emails claiming to be from IT support, and never approve login requests or authentication prompts that you did not initiate yourself.
Florida DMV Database Breached Through Stolen Police Account
Article Link: https://tech-insider.org/flhsmv-confirms-plant-city-login-breach-2026/
- Florida’s Department of Highway Safety and Motor Vehicles confirmed that attackers accessed its driver database using login credentials belonging to a Plant City Police Department employee, exposing information contained in a system used by law enforcement and other authorized agencies.
- Investigators determined the employee’s credentials had been improperly stored on a personal electronic device, giving the intruders a path into the state’s Driver and Vehicle Information Database, known as DAVID.
- The department says the intrusion was contained after detection and there is no continuing unauthorized access. The incident shows how credentials stored outside managed business systems can create exposure far beyond a single user or device.
- FLHSMV revoked the compromised access and worked with law enforcement during the investigation. The case reinforces keeping work credentials off personal devices unless approved by your organization, limiting access to authorized systems, and promptly disabling accounts when compromise is suspected.
What does this mean for me?
- Storing work usernames and passwords on personal devices or in unapproved locations can put sensitive systems at risk. Keep work credentials in approved systems only, and immediately report any suspected account compromise or lost devices to your IT team.
ConnectWise Releases Fix for ScreenConnect Remote Access Vulnerability
Article Link: https://www.bleepingcomputer.com/news/security/connectwise-warns-of-new-screenconnect-flaw-without-patch/
- ConnectWise released ScreenConnect 26.6.5 to address a remote access flaw affecting cloud and on-premises deployments. ScreenConnect is widely used by managed service providers, IT departments, and support teams for remote troubleshooting, patching, and system maintenance.
- Tracked as CVE-2026-84869, the vulnerability can allow files to be transferred and executed through an active remote session without proper authorization or confirmation from the host under certain conditions. Versions earlier than 26.6.5 are affected.
- ConnectWise automatically updated cloud-hosted environments, while organizations running ScreenConnect on their own infrastructure must install version 26.6.5 or later. ScreenConnect vulnerabilities have previously been exploited by ransomware operators and state-backed groups, including attacks in 2024 that used the platform to deploy malware.
- Customers unable to update immediately can temporarily remove file-transfer permissions from user roles. After patching, ConnectWise recommends reviewing accounts and permissions, changing passwords, enabling multifactor authentication, and updating host clients and access agents.
- Additional information: https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin
What does this mean for me?
- Remote support tools are powerful because they can access and control computers from afar. When prompted to update software or restart your device, doing so promptly helps ensure critical security fixes are applied before attackers can take advantage of known vulnerabilities.
Russian Hackers Used Claude AI to Automate Malware Evasion
Article Link: https://www.securityweek.com/anthropic-says-russian-hackers-used-claude-ai-to-automate-malware-evasion/
- Anthropic says a Russia-linked espionage group matching Midnight Blizzard used Claude during operations targeting more than 20 organizations, including government ministries, defense and intelligence bodies, embassies, think tanks, and drone manufacturers.
- The attackers used Claude to test whether malware was detected by security products. When flagged, AI agents automatically modified, rebuilt, and redeployed the tools, repeating the cycle until they evaded detection again.
- Anthropic says the approach shortens a process that historically required attackers to manually rewrite malware after detection, allowing capable actors to “close the loop” faster than defenders can respond. The campaign also compromised hotel Wi-Fi providers, hijacked WhatsApp accounts, and stole proprietary drone technology.
- Anthropic disrupted the activity, strengthened safeguards, and shared intelligence with authorities and industry partners. The company also says organizations need to treat AI API keys and agent integrations with the same scrutiny as production credentials.
What does this mean for me?
- AI can help both defenders and attackers work faster. This means phishing emails, scams, and malware may become more convincing, making it even more important to verify unexpected requests, avoid suspicious downloads, and report unusual activity.
U.S. Offers $10 Million Reward for Iranian Official Accused of Directing Cyberattacks
Article Link: https://therecord.media/us-reward-amir-yaryab-iran-irgc-cyberattacks
Article Link: https://therecord.media/us-reward-amir-yaryab-iran-irgc-cyberattacks
- The U.S. State Department is offering up to $10 million for information leading to the location of Amir Yaryab, an Iranian official accused of directing hacking operations against infrastructure and organizations across the United States, Europe, and the Middle East.
- Yaryab allegedly leads the Islamic Revolutionary Guard Corps’ Cyber-Electronic Command and oversees multiple Iran-linked hacking units responsible for espionage, disruptive attacks, and campaigns targeting government agencies, private companies, and essential infrastructure in the United States and allied countries.
- Targets attributed to these groups span defense, news, shipping, hotels, airlines, energy, finance, telecommunications, and water utilities. U.S. officials say Iranian actors have breached more than 100 water-sector entities across at least 12 states since late July.
- The reward follows Justice Department accusations against Iran-linked hackers for breaching government and United Nations email accounts, while the Treasury Department has sanctioned Iranian nationals tied to attacks on essential infrastructure.
What does this mean for me?
- Nation-state cyber threats increasingly target organizations of all sizes and industries, not just governments. Following basic security practices such as using strong passwords, enabling multifactor authentication, and remaining alert to phishing attempts helps reduce risk across the broader organization.
Phishers Use Invisible Unicode Characters to Evade Email Filters
Article Link: https://www.theregister.com/security/2026/09/04/ascii-smuggling-isnt-just-an-ai-security-risk/5294595
- Microsoft uncovered a phishing campaign using ASCII smuggling, a technique built around invisible Unicode characters, to disguise words inside email messages. Activity peaked above 2.37 million messages in late February and remained elevated for months.
- Rather than hiding instructions for AI systems as seen in prompt injection attacks, attackers inserted non-rendering tag characters inside financial terms so keyword and signature matching could miss them. To recipients, the words still appeared normal.
- Most messages came from roughly 150 finance-themed sender domains, with a distinctive weekday pattern and little weekend activity. Microsoft says techniques associated with AI research can also migrate into traditional phishing and spam campaigns.
- Microsoft recommends stripping or normalizing invisible Unicode characters before content is checked by keyword, signature, or regular-expression filters. Teams can also watch for spikes in tag characters, disposable finance-themed domains, and weekday-only sending patterns.
- Additional information: https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/
What does this mean for me?
- Email security tools catch many threats, but some malicious messages still get through. If an email creates urgency, asks you to click a link, open an attachment, send money, or provide credentials, take a moment to verify the request before acting, even if it appears legitimate.
