Archive for September 2026
Device Code Phishing: What SMEs Need to Know
Cybercriminals have started exploiting a login shortcut millions of people already trust. Rather than sending victims to a fake login page or trying to steal a password outright, they persuade employees to authorise an attacker-controlled device through a completely legitimate identity provider — Microsoft, most often. The result is a fast-growing form of social engineering…
Read MoreMcKesson Breach: How the Okta Vishing Attack Happened
An Okta vishing attack — a phone call, not a piece of malware — is how the extortion group ShinyHunters claims it broke into US healthcare and pharmaceutical distribution giant McKesson. McKesson has confirmed unauthorized access to third-party applications and data exfiltration, but has not confirmed the attack path itself: according to ShinyHunters’ own account,…
Read MoreExchange Authentication Bypass Vulnerability Now Exploitable
A working exploit for an Exchange authentication bypass vulnerability is now public on GitHub, and heise.de reports that roughly 85% of on-premises Exchange servers in Germany remain vulnerable three weeks after Microsoft shipped a fix. The catch: for organizations still running Exchange 2016 or 2019, that fix is locked behind Microsoft’s paid Extended Security Update…
Read More
