logo

Microsoft, Drupal, Linux critical patches; OAuth phishing bypasses MFA on 340+ orgs

ID: 9725fbb6-f2a0-5eac-87e1-a6a3f467c01e

STIX ID: report--9725fbb6-f2a0-5eac-87e1-a6a3f467c01e

Feed Name: defend.network – Daily Threat Briefings

Threat Score
78/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

...
...

**Executive Summary:** Microsoft disrupted a malware-signing service tied to ransomware distribution; an EvilTokens OAuth phishing service has bypassed MFA across 340+ Microsoft 365 organizations; Drupal is issuing urgent core security updates (May 20); a public PoC exists for Linux kernel LPE CVE-2026-31635; and the Trapdoor Android campaign is generating massive ad-fraud traffic—organizations should patch immediately, audit OAuth consents, restrict local access, and remediate malicious Android apps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.