Daily briefing: Tuesday, September 22, 2026

Microsoft disrupted EvilTokens, a phishing-as-a-service platform that compromised 12,000 accounts, seizing 50 websites and disabling over 150 domains. F5 BIG-IP APM contains a critical heap-based buffer overflow (CVE-2026-94127, CVSS 9.3) actively exploited, with advisories from F5, CERT-EU and the Canadian Cyber Centre. CVE-2026-93952 (CVSS 9.5) in Arista VeloCloud Orchestrator is being actively exploited, with advisories from The Hacker News and Canadian Cyber Centre and CISA listing.

Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

Microsoft disrupted EvilTokens, a phishing-as-a-service platform that compromised 12,000 accounts. The disruption involved seizing 50 websites and disabling more than 150 domains targeting Microsoft 365 users.

Critical Vulnerability in F5 BIG-IP APM

F5 BIG-IP APM has a critical heap-based buffer overflow (CVE-2026-94127, CVSS 9.3) actively exploited.

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

CVE-2026-93952 (CVSS 9.5) in Arista VeloCloud Orchestrator is being actively exploited. The vulnerability affects on-prem deployments and CISA added it to the Known Exploited Vulnerabilities catalog.

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

A zero-day in Meta’s Muse AI assistant allows attackers to hijack it via a terminal command. The hijack enables dictation reroute, instruction injection and theft of the assistant's session token.

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

Microsoft patched SharePoint CVE-2026-65660 (CVSS 8.8) on August 11, 2026.

Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.