Friday, July 10, 2026
Daily digest
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
Threat actor O-UNC-066 is conducting voice-phishing (vishing) campaigns that trick Microsoft 365 users into enrolling an attacker-controlled passkey in Microsoft Entra, bypassing MFA and enabling data extortion. The attack uses a panel-controlled phishing kit purpose-built to abuse the Entra passkey enrollment flow. Multiple sectors have been targeted.
Why it matters: Your M365 GCC High tenant uses Entra for identity — if passkey enrollment is not restricted to compliant/managed devices via Conditional Access policy, this attack path is viable against your users. Audit your Entra passkey registration policy and consider requiring Intune-compliance attestation before any new credential enrollment is permitted.
New Forg365 Phishing Platform Uses AI to Target Microsoft 365 Accounts
A new phishing-as-a-service platform called Forg365 combines adversary-in-the-middle (AiTM) proxy attacks with device code phishing and uses AI to generate convincing lures, specifically targeting Microsoft 365 credentials. The platform is available to low-skill threat actors as a service, lowering the barrier to sophisticated session-token theft against M365 tenants.
Why it matters: AiTM attacks defeat standard MFA by stealing session tokens rather than credentials — Conditional Access policies requiring compliant device and continuous access evaluation (CAE) are the primary mitigations. Verify CAE is enabled in your GCC High tenant and that device code flow is blocked for accounts that don't require it.
New Helix Vishing Group Emerges in SharePoint Data Theft Attacks
A new threat group called Helix is stealing data from SharePoint environments using vishing, device code phishing, and MFA abuse. The group focuses on identity-layer compromise rather than malware, making endpoint detection less effective. The operation is data-extortion focused.
Why it matters: SharePoint Online in GCC High likely holds CUI — Helix's identity-centric, malware-free approach means your EDR on Intune-managed endpoints won't catch it. Review SharePoint external sharing settings, audit device code authentication grants in Entra, and ensure sign-in risk policies are tuned to flag anomalous token use.
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Microsoft has released a patch for CVE-2026-50656 (CVSS 7.8), a privilege escalation vulnerability in the Microsoft Malware Protection Engine (mpengine.dll) that can grant SYSTEM-level access. The flaw was publicly disclosed with a working proof-of-concept exploit by researcher Nightmare-Eclipse roughly a month before the patch shipped, leaving a significant exposure window.
Why it matters: Defender is running on every Intune-managed Windows 11 endpoint in your fleet — this is a local privilege escalation with public PoC code, meaning it's a realistic post-initial-access stepping stone. Confirm the mpengine update has been pushed via Windows Update or Intune and verify compliance reporting shows no stragglers.
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
A new ransomware family called GodDamn, assessed as a Beast ransomware rebrand, uses a Microsoft-signed malicious kernel driver called PoisonX in a Bring Your Own Vulnerable Driver (BYOVD) attack to kill endpoint security software before deploying ransomware. It has been observed targeting U.S. companies since at least May 21, 2026.
Why it matters: A signed driver that defeats EDR/AV is a direct threat to Defender for Endpoint on your Windows 11 fleet. Verify that Microsoft's vulnerable driver blocklist is current (updated via Windows Update) and that Defender's kernel-mode protection and tamper protection are enabled across all Intune-managed devices.
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
Microsoft has published a detailed analysis of GigaWiper, a destructive Windows backdoor that combines code from multiple malware families into a single operator-controlled platform with selectable payloads: full disk wipe, Windows-partition overwrite, or fake ransomware that destroys the decryption key. The malware is designed for maximum flexibility in causing irreversible damage.
Why it matters: The Microsoft Security Blog post includes indicators of compromise and detection guidance — feed those IOCs into your SIEM and Defender for Endpoint custom detection rules. The destructive-wiper capability is particularly relevant given NIST 800-171 requirements around data integrity and system recovery (3.8.x, 3.11.x).
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
npm version 12 ships with install scripts disabled by default, requiring explicit opt-in, and deprecates granular access tokens (GATs) that could bypass 2FA. Both changes are aimed at reducing supply chain attack surface in the Node.js ecosystem. Organizations using automated pipelines that rely on npm install scripts will need to update their configurations.
Why it matters: If any of your Ansible playbooks, CI/CD pipelines, or self-hosted tooling invoke npm install for Node-based dependencies, silent script execution will now fail by default after upgrading to npm 12 — audit your automation before updating to avoid broken deployments.
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
Datadog Security Labs is warning of multiple overlapping campaigns systematically enumerating corporate GitHub organizations, repositories, and user accounts via the GitHub API, using years-old dormant "ghost" accounts and compromised OAuth tokens to appear legitimate. The activity is consistent with pre-attack reconnaissance to identify targets, internal tooling, and secrets.
Why it matters: If your organization uses GitHub for Ansible roles, infrastructure-as-code, or any internal tooling, review your org's GitHub audit log for unusual API enumeration activity and rotate any long-lived OAuth tokens or PATs — compromised tokens grant read access to private repos that may contain secrets or CUI-adjacent configuration data.
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
A researcher has disclosed an unauthenticated denial-of-service vulnerability, dubbed XRING, in XQUIC — Alibaba's open-source QUIC and HTTP/3 library. About 260 bytes of valid QPACK traffic is sufficient to crash any server using the library, and no patch exists as of the disclosure date of July 8, 2026.
Why it matters: If any services in your AWS GovCloud or on-premises environment use XQUIC for HTTP/3 transport, there is currently no patch — check whether any load balancers, reverse proxies, or application servers in your stack pull this library, and consider disabling HTTP/3 on those endpoints as a temporary mitigation.
Microsoft Expects More Windows Security Updates from AI-Discovered Flaws
Microsoft has publicly stated that its increased use of AI-assisted vulnerability discovery in its own codebase will result in a higher volume of security patches for Windows going forward. The company framed this as a proactive security improvement, but it signals that Patch Tuesday cadence and patch volume will grow.
Why it matters: A heavier patching cadence increases the operational burden on your Intune-managed Windows 11 fleet and demands tighter patch SLA tracking — a direct CMMC Level 2 / NIST 800-171 control 3.14.1 concern. Consider whether your current patch ring configuration and compliance reporting can absorb more frequent out-of-band or supplemental updates.
Accenture Admits to 'Isolated Matter' After Crook Tries to Sell Alleged 35GB Haul
Accenture has acknowledged an "isolated matter" after a threat actor claimed to be selling 35GB of data purportedly including source code, API keys, and cloud credentials stolen from the consulting giant. Accenture said it has "remediated the source" of the incident.
Why it matters: Accenture is a major systems integrator and managed-services provider for many defense contractors — if your organization has any Accenture-managed services or shared tooling, treat this as a potential supply-chain exposure event and verify whether any shared credentials, certificates, or API keys need rotation pending more details.
Zimbra Urges Customers to Patch Critical Web Client XSS Flaw
Zimbra has issued an urgent advisory for a critical cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Classic Web Client. The flaw can be exploited by an unauthenticated attacker to execute malicious scripts in the context of a logged-in user's browser session.
Why it matters: If Zimbra is not in your stack, this can be skipped — but if any partner organizations or contractors you exchange mail with run Zimbra, a compromised account there could be used to send weaponized content into your environment.