~/greenteam/nerd

Tuesday, May 26, 2026

Daily digest

The FBI warning about Kali365 targeting Microsoft 365 via OAuth device code phishing is the most operationally urgent item today for anyone running M365 GCC High โ€” read that one first.

cybersec BleepingComputer

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

The FBI issued a warning about Kali365, a phishing-as-a-service platform that hijacks Microsoft 365 accounts by abusing OAuth device code authentication flows to steal session tokens and bypass MFA entirely. Because it targets the authentication mechanism itself rather than credentials, traditional MFA protections are ineffective. Organizations running M365 GCC High should audit OAuth device code flow permissions and consider restricting or blocking device code authentication where not required.

cybersec The Hacker News

Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions

Microsoft patched CVE-2026-45659, a CVSS 8.8 remote code execution vulnerability in SharePoint caused by deserialization of untrusted data โ€” no special conditions required for exploitation. The flaw affects multiple SharePoint Server versions and warrants priority patching for any on-premises SharePoint deployments, including hybrid configurations common in GCC High environments. Organizations should apply the update immediately given the low exploitation barrier.

cmmc Federal News Network

OMB revamps cyber event logging requirements

A new OMB memo rescinds prior federal cyber event logging mandates and replaces them with updated requirements designed to reduce compliance burden while maintaining security visibility. The changes affect how federal agencies and their contractors structure and retain log data, which has direct implications for CMMC audit readiness under NIST 800-171 AU controls. Administrators should review the new memo to determine if current logging configurations remain compliant.

cybersec BleepingComputer

CISA orders feds to patch actively exploited Drupal vulnerability

CISA added an actively exploited SQL injection vulnerability in Drupal CMS to its Known Exploited Vulnerabilities catalog and gave federal agencies a short deadline to remediate. While Drupal may not be a primary stack component, any internet-facing CMS in a federal or DoD contractor environment running Drupal needs immediate attention. The active exploitation status elevates urgency beyond routine patch cycles.

cybersec BleepingComputer

Microsoft Defender can now automatically isolate hacked endpoints

Microsoft is testing automatic endpoint isolation in Defender for Endpoint, which will quarantine compromised machines without manual SOC intervention to stop lateral movement. This capability is directly relevant to Intune-managed endpoint fleets, where automated containment can significantly reduce dwell time in the event of a breach. The feature is currently in testing and should be evaluated for deployment readiness in controlled environments.

cybersec The Hacker News

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning

Iranian state-sponsored group Nimbus Manticore (UNC1549) launched a fresh campaign using phishing lures impersonating aviation and software companies across the U.S., Europe, and the Middle East, deploying novel malware families MiniFast and MiniJunk V2. The campaign appears to be a direct response to the late-February 2026 U.S.-Israeli military action against Iran, suggesting an uptick in retaliatory cyber operations targeting defense-adjacent sectors. Defense contractors and aerospace suppliers should treat this as a heightened threat indicator.

cybersec Krebs on Security

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

Dutch authorities seized 800 servers and arrested two co-owners of hosting companies that provided infrastructure used by Russian intelligence for cyberattacks, influence operations, and disinformation campaigns inside the EU. The companies had taken over the infrastructure of Stark Industries Solutions, an ISP previously sanctioned by the EU for enabling Russian cyber operations. The takedown disrupts a significant piece of Russian offensive cyber staging infrastructure.

infrastructure BleepingComputer

Microsoft: Domain Controller lookup may fail on Windows Server 2016

Microsoft confirmed a known issue where installing the KB5087537 May 2026 security update on Windows Server 2016 can cause domain controller lookup failures, potentially breaking authentication across the environment. This is a high-impact regression for any organization still running Server 2016 domain controllers or member servers, which remain common in hybrid GCC environments. Administrators should test before broad deployment and monitor Microsoft's support article for a fix.

cybersec The Hacker News

KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

A high-severity zero-day vulnerability (CVE-2026-5426, CVSS 7.5) in the KnowledgeDeliver LMS stemming from hard-coded ASP.NET machine keys was exploited to drop the Godzilla web shell and Cobalt Strike Beacon. Hard-coded machine keys are a recurring ASP.NET attack vector โ€” this incident is a reminder to audit all ASP.NET applications in your environment for static or default machine key configurations. The flaw is now patched, but active exploitation before the patch warrants checking for indicators of compromise.

infrastructure Red Hat Blog

Convert and upgrade your RHEL-like system to RHEL in one go

Red Hat introduced a unified convert-and-upgrade workflow that collapses the previously separate Convert2RHEL and Leapp steps into a single process, allowing migration from CentOS Stream 9 directly to RHEL 10 in one operation. This reduces complexity and the need for separate Ansible automation playbooks for each migration phase, which is a practical win for shops managing large RHEL fleet migrations via Ansible. Organizations still running CentOS derivatives should evaluate this path as CentOS end-of-life timelines continue to pressure migrations.

cybersec The Hacker News

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

Threat actors exploited CVE-2026-26980 (CVSS 9.4), a critical unauthenticated SQL injection flaw in Ghost CMS's Content API, to compromise over 700 sites and inject malicious JavaScript used in ClickFix social engineering campaigns. ClickFix attacks trick users into manually running malicious commands, making them effective even against patched endpoints. Any internet-facing Ghost CMS instances should be patched immediately; the high CVSS and active mass exploitation make this critical priority.

cmmc Federal News Network

Hybrid by design: Engineering the new model for federal AI delivery

Booz Allen and Future Tech outline an approach to federal AI deployment using hybrid cloud architectures, edge AI, and GPUs to meet security and performance requirements in government environments. The model is designed to address FedRAMP and data sovereignty constraints that complicate pure-cloud AI adoption in agencies handling controlled unclassified information (CUI). While vendor-authored, the piece contains concrete architectural patterns relevant to GovCloud and hybrid CUI environments.