Daily briefing: Tuesday, September 22, 2026
Microsoft disrupted EvilTokens, a phishing-as-a-service platform that compromised 12,000 accounts, seizing 50 websites and disabling over 150 domains. F5 BIG-IP APM contains a critical heap-based buffer overflow (CVE-2026-94127, CVSS 9.3) actively exploited, with advisories from F5, CERT-EU and the Canadian Cyber Centre. CVE-2026-93952 (CVSS 9.5) in Arista VeloCloud Orchestrator is being actively exploited, with advisories from The Hacker News and Canadian Cyber Centre and CISA listing.
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
Microsoft disrupted EvilTokens, a phishing-as-a-service platform that compromised 12,000 accounts. The disruption involved seizing 50 websites and disabling more than 150 domains targeting Microsoft 365 users.
- Microsoft disrupts AI-assisted platform that compromised 12,000 accounts Ars Technica
- Microsoft Disrupts EvilTokens Device Code Phishing Service Dark Reading
- Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises The Hacker News
- Unmasking EvilTokens: Getting to the root of device code phishing Microsoft Threat Intelligence
Critical Vulnerability in F5 BIG-IP APM
F5 BIG-IP APM has a critical heap-based buffer overflow (CVE-2026-94127, CVSS 9.3) actively exploited.
- Critical Vulnerability in F5 BIG-IP APM CERT-EU
- Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127 Canadian Centre for Cyber Security
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
CVE-2026-93952 (CVSS 9.5) in Arista VeloCloud Orchestrator is being actively exploited. The vulnerability affects on-prem deployments and CISA added it to the Known Exploited Vulnerabilities catalog.
- New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups The Hacker News
- Arista Networks security advisory (AV26-947) – Update 1 Canadian Centre for Cyber Security
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
A zero-day in Meta’s Muse AI assistant allows attackers to hijack it via a terminal command. The hijack enables dictation reroute, instruction injection and theft of the assistant's session token.
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Microsoft patched SharePoint CVE-2026-65660 (CVSS 8.8) on August 11, 2026.
Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.