logo

Ghost CMS, Microsoft 365 phishing, and supply-chain malware in active exploitation

ID: 6147aaa4-29e5-5fbb-831e-5fedddf339d6

STIX ID: report--6147aaa4-29e5-5fbb-831e-5fedddf339d6

Feed Name: defend.network

Threat Score
88/100

Date Published: 2026-05-26

Date Updated: 2026-06-21

...
...

This briefing details multiple simultaneous high-severity threats: a widely exploited Ghost CMS SQL injection (CVE-2026-26980) compromising 700+ sites for ClickFix attacks; Kali365 phishing-as-a-service abusing OAuth device code flows to steal Microsoft 365 tokens and bypass MFA; cross-ecosystem supply-chain poisonings (TrapDoor, Laravel Lang) distributing credential-stealing malware across npm, PyPI, Crates.io and Composer; Lazarus Group's RemotePE memory-only RAT targeting finance and crypto; and a CISA contractor leak of AWS GovCloud credentials alongside law-enforcement disruption of the Kimwolf botnet — recommended actions include immediate Ghost patching, enforcing MFA/conditional access, rotating exposed credentials, auditing dependencies and CI secrets, and deploying behavioral EDR.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.