Get tomorrow's brief in your inbox
Date: 2026-07-06
Today: Microsoft SharePoint zero-day under active attack after patches failed to fix the vulnerability. Android 17 drops PIN guess limits from 1,800 attempts to just 20, shipping stricter lockscreen protections. AI agent skills can evade static scanners using self-extracting packing techniques, bypassing defenses over 90% of the time.
Microsoft Patches Failed to Fix On-Prem SharePoint, Now Under Zero-Day Attack
Microsoft's patches for on-premises SharePoint have failed to remediate a vulnerability that is now being actively exploited in the wild. The zero-day attack affects on-prem SharePoint installations, though specific CVE details and exploit vectors were not detailed in the available reporting. Organizations running on-premises SharePoint should assume they are at risk until Microsoft issues a confirmed fix.
1 claim tracked from arcus media in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| arcus media | East African Gasoil | Energy/Fuel Distribution | Kenya/Tanzania (East Africa) |
Device Code Phishing Attack via Microsoft Website
Attackers are exploiting Microsoft's OAuth 2.0 Device Authorization Grant to phish credentials directly through legitimate Microsoft domains. The attack instructs victims to visit microsoft.com/devicelogin and enter a device code, which grants attackers access tokens to the victim's account. The technique bypasses traditional phishing detection since the URL is genuinely Microsoft-owned. The Device Authorization Grant was designed for smart TVs and IoT devices, but threat actors discovered they can abuse it by displaying fake device codes to victims through social engineering. Once a user enters the code and approves access, attackers receive valid OAuth tokens for the victim's Microsoft account, including access to email, OneDrive, and Azure resources.
SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners
Researchers at Hong Kong University of Science and Technology demonstrated that malicious "skills" for AI coding agents can evade static scanners over 90% of the time using self-extracting packing techniques. Skills are small instruction packages that agents like Claude Code and OpenAI Codex load to gain new capabilities, and they run with full agent access to files, terminals, and credentials. The SkillCloak tool rewrites malicious skills to appear clean using two methods: character swapping and command splitting to break pattern matches, and self-extracting packing that hides payloads in directories scanners skip (like .git/) with a harmless-looking decoder. Across eight scanners and 1,613 real malicious skills, the packing trick bypassed each scanner more than 90% of the time. The researchers released a runtime checker called SkillDetonate that caught 97% of attacks by monitoring behavior rather than appearance, though it runs slower than static scanners.
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data
A flaw in Opera GX allowed malicious websites to silently install browser mods and use CSS injection to steal data from pages the victim visited, including reconstructing full Gmail addresses with no user interaction. The vulnerability leveraged Opera GX's auto-install behavior for GX Mods, which are browser reskins shipped as .crx files. A malicious page could install a mod silently by loading a hidden iframe pointed at a .crx file, with only a notification bar as indication. The mod's CSS applied universally to every page, enabling a universal CSS injection that used attribute selectors to leak values character by character through background image requests. Opera patched the flaw in Opera GX version 130.0.5847.89 and found no evidence of wild exploitation. The bug bounty team rated it P1 (top severity) and paid the maximum $5,000 award.
Russians Posing as Signal Support to Launch Phishing Attacks
Russian threat actors are impersonating Signal support staff to conduct phishing campaigns targeting Signal users. The attacks likely involve social engineering to trick users into providing credentials, recovery codes, or device access. Signal does not have traditional support staff that would contact users directly, making any unsolicited "support" contact a red flag. No further technical details on the attack vector or payload were provided in the available reporting.
TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions
Researchers at Shandong University demonstrated TrojPix, a covert channel that exfiltrates data from air-gapped computers by modulating on-screen pixels to make video cables radiate radio signals a nearby receiver can decode. The technique achieved 8.1 Mbps throughput and a 208-meter range in testing, though not simultaneously. TrojPix requires malware already on the target system and user-level permissions to draw to the screen. It uses imperceptible pixel modulation to hide transmissions either by faking a powered-off display or burying signals in normal screen content. The researchers tested across nine monitor brands and fifteen video cables. This is lab research, not a wild attack. Countermeasures include fiber-optic video links, cable and room shielding, and preventing malware installation.
MFA-Optional Banks Leave Accounts Wide Open for Thieves
Financial institutions that make multi-factor authentication optional rather than mandatory are leaving customer accounts vulnerable to credential theft and account takeover. When MFA is optional, users who do not enable it rely solely on passwords, which are routinely compromised through phishing, data breaches, and credential stuffing attacks. Banking security should enforce MFA by default rather than treating it as an opt-in feature. The article did not specify which banks currently have optional MFA policies.
Android 17 Drops PIN Guessing Limit from 1,800 Attempts to 20
Android 17, released last month, reduced the maximum failed lockscreen attempts from 1,800 to 20 with aggressive timeouts between attempts. The previous Android 16 allowed ten wrong guesses in the first minute, scaling up to 1,800 attempts over five years. The new system allows just five failed attempts in the first minute, with the twentieth PIN guess available only after 14 years of waiting, after which no more guesses are allowed. The system includes duplicate guess detection so users are not penalized for entering the same incorrect PIN multiple times. The feature shipped broadly with Android 17 after being added to Android 16 QPR2 in December 2025. Phone makers will roll out the OS update over the coming months.
DEF CON Franklin Project Enlists Hackers to Harden Critical Infrastructure
DEF CON is expanding its security research efforts to critical infrastructure through the Franklin Project, which will involve the entire DEF CON conference rather than just a single village. The initiative follows the success of the voting village, which has produced influential security reports. DEF CON founder Jeff Moss announced the expansion to apply the same research model to broader critical infrastructure systems beyond voting machines.
EQT Buys Majority Share in Swiss Cybersecurity Firm Acronis
Private equity firm EQT acquired a majority stake in Swiss cybersecurity and data protection company Acronis at an equivalent valuation of over $3.5 billion for the entire firm, though the exact portion sold was not specified. Acronis provides backup, disaster recovery, and cybersecurity solutions primarily targeting managed service providers and enterprises.
AdaptHealth Discloses Breach to SEC
American medical equipment maker AdaptHealth notified the SEC of a security breach in which an intruder accessed patient data and internal documents stored in a cloud-based platform. The attackers contacted the company on June 15, and no hacking or ransomware group has claimed responsibility yet. Based on the timeline and details, AdaptHealth appears to be a victim in a hacking spree targeting the Oracle PeopleSoft platform.
Grand Line Hacked by Ukrainian Hacktivists
Ukrainian hacktivist group Cyber Anarchy Squad claims to have wiped 3,000 servers and workstations, 700 virtual machines, and all backups at Russian construction company Grand Line, allegedly stealing over 650 TB of documents. The breach occurred in May but was only disclosed recently. Grand Line is one of Russia's largest construction companies.
Alibaba Bans Employees from Using Claude
Chinese tech company Alibaba banned employees from using Anthropic's Claude model for work-related tasks. The article content was truncated, and additional details on the reasoning were not provided in the available text.
New Java-Based QuimaRAT MaaS Built for Cross-Platform Targeting
LevelBlue identified QuimaRAT, a new Java-based remote access trojan sold as malware-as-a-service targeting Windows, Linux, and macOS. The RAT costs $150 for one month to $1,200 for lifetime access and features a modular architecture supporting encrypted plugins delivered from C2 infrastructure. The malware author advertises a builder generating multiple output formats including JAR, EXE, APP, SH, BAT, and VBS. QuimaRAT offers 74 Windows modules and 46 macOS/Linux modules. The seller also offers Quima Builder (modular builder supporting XLL, LNK, VBS, DOCM, MSC, CPL, CHM formats), Quima Loader (browser-cache payload delivery), and Quima Dropper (HTML/SVG payload generator). The malware is organized as a modular Java project built with Apache Maven and includes embedded Java Native Access native libraries for multi-platform deployment. The author advertises complete stealth on Windows and Linux with no visible UI elements.
Three stories highlight how defenders are losing ground to attackers when traditional defenses are bypassed through legitimate channels: Microsoft's Device Code phishing abuses OAuth 2.0 through real Microsoft URLs, AI agent skill scanners fail against basic obfuscation, and Opera GX's feature meant for customization became a silent data theft vector. Meanwhile, Android 17's dramatic reduction in PIN guess limits shows one platform tightening mobile security after years of generous attack windows. The zero-day SharePoint exploitation after failed patches underscores the risk of incomplete vulnerability remediation in on-premises enterprise systems.