Ghost CMS, Microsoft 365 phishing, and supply-chain malware in active exploitation
ID: 6147aaa4-29e5-5fbb-831e-5fedddf339d6
STIX ID: report--6147aaa4-29e5-5fbb-831e-5fedddf339d6
Feed Name: defend.network
This briefing details multiple simultaneous high-severity threats: a widely exploited Ghost CMS SQL injection (CVE-2026-26980) compromising 700+ sites for ClickFix attacks; Kali365 phishing-as-a-service abusing OAuth device code flows to steal Microsoft 365 tokens and bypass MFA; cross-ecosystem supply-chain poisonings (TrapDoor, Laravel Lang) distributing credential-stealing malware across npm, PyPI, Crates.io and Composer; Lazarus Group's RemotePE memory-only RAT targeting finance and crypto; and a CISA contractor leak of AWS GovCloud credentials alongside law-enforcement disruption of the Kimwolf botnet — recommended actions include immediate Ghost patching, enforcing MFA/conditional access, rotating exposed credentials, auditing dependencies and CI secrets, and deploying behavioral EDR.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
