Mirage2FA hits 4,500 orgs; Oracle Weblogic RCE, NVIDIA AI poisoning, WordPress plugin flaws
ID: 7d116cdf-3fd4-5cd9-a22a-96f893668b8d
STIX ID: report--7d116cdf-3fd4-5cd9-a22a-96f893668b8d
Feed Name: defend.network
This briefing synthesizes multiple high‑severity threats: a widespread Mirage2FA phishing‑as‑a‑service campaign compromising ~4,500 organizations via Microsoft 365 login spoofing; an unauthenticated NVIDIA NemoClaw/Ollama vector enabling persistent model poisoning; Oracle HTTP Server/WebLogic improper access control (CVE-2026-21962) added to CISA KEV with an urgent patch deadline; and MiniOrange SAML WordPress authentication bypasses — plus related DDoS and voice‑AI phishing activity — and provides prioritized mitigation actions (patching, log review, API isolation, and user training).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
