Microsoft, Drupal, Linux critical patches; OAuth phishing bypasses MFA on 340+ orgs
ID: 9725fbb6-f2a0-5eac-87e1-a6a3f467c01e
STIX ID: report--9725fbb6-f2a0-5eac-87e1-a6a3f467c01e
Feed Name: defend.network – Daily Threat Briefings
**Executive Summary:** Microsoft disrupted a malware-signing service tied to ransomware distribution; an EvilTokens OAuth phishing service has bypassed MFA across 340+ Microsoft 365 organizations; Drupal is issuing urgent core security updates (May 20); a public PoC exists for Linux kernel LPE CVE-2026-31635; and the Trapdoor Android campaign is generating massive ad-fraud traffic—organizations should patch immediately, audit OAuth consents, restrict local access, and remediate malicious Android apps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
