logo

Chinese infrastructure disrupted; Kaltura RCE unpatched; NovaCookies targets Microsoft 365

ID: 75908899-6ef5-50ba-bd7c-07f6fdad6512

STIX ID: report--75908899-6ef5-50ba-bd7c-07f6fdad6512

Feed Name: defend.network

Threat Score
88/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: defend.network

...
...

This briefing highlights multiple high-priority threats: U.S. authorities disrupted Chinese state-linked QScan/QTRouter infrastructure used against critical U.S. networks; Kaltura mwEmbed has two unpatched RCEs allowing arbitrary file read and code execution; the NovaCookies AitM phishing kit abuses DocuSign to steal Microsoft 365 sessions and is sold as a service; a CISA red team exposed detection gaps at critical infrastructure organizations; and Microsoft issued fixes for ~398 vulnerabilities including one actively exploited — immediate patching, monitoring, and defensive reviews are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.