Weekly Threat Awareness ReportEntra ID RCE · SharePoint Bypass Exploited · Mirage2FA Session Theft
A critical deserialization flaw in Microsoft Entra ID that can hand an attacker control of the identity platform leads this week, alongside a SharePoint security-feature bypass under confirmed exploitation by TA505, Mustang Panda and other advanced groups, and a WordPress login-page XSS that APT groups including Kimsuky and APT37 are exploiting in the wild. On the campaign side, the Telegram-sold Mirage2FA kit is hijacking Microsoft 365 accounts by stealing the session that MFA was meant to protect, and the newly documented Evooo1Bot botnet is spreading across internet-facing Linux devices. The through-line: identity is the target - the directory itself, the collaboration layer built on it, and the session cookie issued after a successful sign-in.
Vaughn Thomas
Compliance Engineer & Threat Researcher · SOClogix Cyber Group
Technical review: William Johnson, VP of Security Operations
About the Analyst
Vaughn Thomas is SOClogix's Compliance Engineer and principal threat researcher, operating at the intersection of regulatory compliance and active adversary tradecraft. Each week, Vaughn synthesizes intelligence from dark web forums, vendor security advisories, CISA KEV updates, Shodan/Censys exposure data, and real-time telemetry from SOClogix's managed client network - spanning healthcare, financial services, defense industrial base, manufacturing, and local government - to produce actionable threat awareness briefings written for security teams and executive stakeholders at every level. Vaughn actively tracks over 200 threat actor groups and contributes threat sharing intelligence to multiple ISAC communities. His analysis deliberately bridges raw technical findings and business risk so compliance teams and CISOs can act, not just read.
Full bio and published research LinkedIn200+
Threat groups tracked
50+
Intel feeds monitored
3 yrs
Threat research tenure
This Week's Threat Landscape Mindmap
Threat landscape for August 10 - August 16, 2026: top threats, active actors, attack trends, sector exposure, and what to do now.

Vulnerabilities at a Glance
Exploitation status and required action for each client-facing CVE covered this week.
| CVE | Product | Severity | Exploitation Status | Fix | Priority |
|---|---|---|---|---|---|
CVE-2026-69836 | Microsoft Entra ID | Critical | Exploitation not confirmed | Apply Microsoft remediation | URGENT |
CVE-2026-55040 | Microsoft SharePoint | High | Active - APT-linked; public exploit | Patch immediately | URGENT |
CVE-2026-64638 | WordPress (login screen) | High | Active - APT-linked; public PoCs | 7.0.3 (patches back to 4.7) | URGENT |
CVEs Affecting Client Assets
Vulnerabilities identified this week with direct relevance to common enterprise environments. Two are under active exploitation by named advanced threat groups.
CVE-2026-69836 New this weekMicrosoft Entra ID - Remote Code Execution
Deserialization of Untrusted Data (CWE-502) · Unauthorized · Remote
A critical flaw in the core functionality of Microsoft Entra ID lets an unauthorized attacker remotely execute malicious code. It stems from deserialization of untrusted data: the service can be deceived into processing malicious instructions as if they were legitimate, potentially handing control to the attacker. Successful exploitation could give an attacker full control over the affected Entra ID environment, leading to large-scale data breaches, unauthorized access to sensitive company resources, and the compromise of user identities. Because Entra ID is the identity layer in front of Microsoft 365, Azure, and every federated application, any organization relying on it faces the risk of total system takeover while this remains unremediated.
Recommended Actions
- Prioritize remediation of this vulnerability above all other maintenance tasks
- Apply Microsoft's remediation for Entra ID immediately and confirm it has taken effect across your tenant
- Review Entra ID audit and sign-in logs for unexplained administrative changes while remediation is in progress
CVE-2026-55040 New this week Actively exploited Public PoC APT-linkedMicrosoft SharePoint - Security Feature Bypass
Weak Authentication · No credentials required · Network · Actively exploited
A high-risk vulnerability rooted in weak authentication mechanisms within Microsoft SharePoint lets an unauthorized attacker bypass the security features protecting the system, gaining access over a network without valid credentials. Any organization using SharePoint for data management is at risk, and a successful breach could lead to significant data theft, operational disruption, and severe reputational damage. Sophisticated groups including TA505, Bookworm, Mustang Panda, and COBALT DICKENS have been linked to this activity. With public exploit code available on GitHub and significant discussion on social media, the risk of widespread attack is extremely high.
Recommended Actions
- Patch all affected SharePoint systems immediately - confirmed exploitation by advanced actors makes this an emergency change, not routine maintenance
- Start with SharePoint servers reachable from the internet: the flaw is exploitable over the network without valid credentials
- Review SharePoint access logs for unauthenticated activity against protected resources since public exploit code appeared
CVE-2026-64638 New this week Actively exploited Public PoC APT-linkedWordPress Login Screen - Cross-Site Scripting
Cross-site Scripting (CWE-79) · Remote · Fixed in 7.0.3, backported to 4.7
A high-severity cross-site scripting flaw in the WordPress login screen lets an attacker inject malicious code into the login page to trick an administrator or user into running unintended commands - and from there, escalate a simple web-based attack into full control of the site. It is being actively exploited in the wild, with numerous proof-of-concept exploits circulating online. Advanced persistent threat groups including Kimsuky, APT37, and UNC6671 have been linked to the threat environment, marking it as a high-priority target for sophisticated attackers. WordPress has released version 7.0.3 and has also shipped security patches for all older versions dating back to 4.7.
Recommended Actions
- Update to WordPress 7.0.3 immediately
- On an older branch, apply the security release for that branch now - patches are available for every version back to 4.7, so a major upgrade is not a prerequisite
- Verify the installed version on every site you manage rather than assuming automatic updates succeeded
Active Threats & Campaigns
Threat actor activity and disclosed tradecraft with immediate defensive relevance.
Mirage2FA - Telegram-Sold PhaaS Kit Bypassing Microsoft 365 MFA
Mirage2FA is a Phishing-as-a-Service kit sold on Telegram that hijacks Microsoft 365 sessions through an Adversary-in-the-Middle (AiTM) proxy, stealing credentials, MFA responses, and session tokens. Delivery relies on HTML smuggling, fake CAPTCHAs, and cloned Microsoft login pages. The kit does not defeat MFA directly - it captures the authenticated session cookie created after a successful MFA challenge, inheriting the session MFA was meant to protect. ANY.RUN logged 9,426 targeted mailboxes and 4,532 likely compromised across 94 countries, mostly in the US. Session theft dominates the outcome mix: of 9,332 potential compromise events, 4,561 were cookie theft, 3,044 password/2FA captures, and 1,339 SSO logins - a kit optimized for durable account takeover rather than one-shot credential resale. Attribution is commercial-criminal, not nation-state: the platform runs as a multi-tenant, Telegram-managed service (tracked in underground telemetry as LinXcoded), so many downstream actors run campaigns off the same core kit. OSINT artifacts - Telegram bot references in the JavaScript, a .my.id domain, and ASN registration records - point to the aliases LinXcoded and zxcoder; these are operator-linked indicators, not confirmed identity attribution.
Recommended Actions
- Enforce phishing-resistant, AiTM-proof MFA (FIDO2 security keys, passkeys, or certificate-based authentication) for Microsoft 365
- On a suspected compromise, revoke active sessions and refresh tokens - a password reset alone leaves a stolen session cookie valid
- Retire legacy Entra ID authentication endpoints, as flagged in this week's mindmap
Threat Profile
Type: AiTM phishing kit, sold as PhaaS on Telegram
Also tracked as: LinXcoded
Delivery: HTML smuggling, fake CAPTCHAs, cloned Microsoft logins
Scope: 9,426 mailboxes targeted, 4,532 likely compromised
Reach: 94 countries, mostly the US
Attribution: Commercial-criminal, not nation-state
Evooo1Bot - Mirai-Based Modular Botnet Targeting Internet-Facing Devices
Evooo1Bot is a previously undocumented Linux botnet family that reuses the DDoS engine from the publicly leaked Mirai source code and wraps it in a far more modular framework. Its name comes from the hardcoded string "evooo1" found in every binary, and FortiGuard Labs documented the family in August 2026. Observed distribution is concentrated in North America, Europe, and Asia, with a smaller share in South America, and targeting patterns are consistent with automated vulnerability scanning and per-CVE payload selection. Pairing SSH brute-forcing with CVE exploitation gives the operator two growth paths: opportunistic spread through weak credentials, and targeted compromise of unpatched systems.
Recommended Actions
- Disable SSH password authentication on internet-facing devices, or restrict SSH to trusted networks
- Keep internet-facing Linux devices and appliances patched - the botnet selects its exploit payload per CVE
- Replace default or weak credentials on any device that cannot be taken off the internet
Threat Profile
Source: FortiGuard Labs
Lineage: Leaked Mirai DDoS engine
Identifier: Hardcoded "evooo1" string
Spread: SSH brute force + per-CVE exploits
Targets: Internet-facing Linux devices
Distribution: N. America, Europe, Asia; some S. America
Sources
Primary reporting behind this week's briefing.
- · Microsoft Security Update Guide - CVE-2026-69836, CVE-2026-55040
- · WordPress 7.0.3 security release - CVE-2026-64638
- · ANY.RUN - Mirage2FA campaign telemetry
- · Fortra and Abnormal Intelligence - Mirage2FA / LinXcoded research
- · FortiGuard Labs - Evooo1Bot research
Protect your environment
Vaughn Thomas
Compliance Engineer & Threat Researcher, SOClogix
Technical review: William Johnson, VP of Security Operations
Vaughn Thomas
Compliance Engineer
SOClogix Cyber Group
200+
Threat groups tracked
50+
Intel feeds monitored
52×
Reports per year
Get Weekly Briefings Free
This Week at a Glance
Past Briefings
Aug 20, 2026
SharePoint RCE in KEV · WordPress "wp2shell" · YellowKey BitLocker Bypass
Jul 23, 2026
Defender "BlueHammer" in KEV · Qilin Chains PAN-OS Bypass · 1.4M Sites Targeted
Jul 16, 2026
SMA1000 SSRF at CVSS 10 in KEV · AD FS Privilege Escalation · BitLocker Bypass
Get Vaughn's Briefing Every Week
Free weekly threat awareness reports delivered to your inbox. CVEs, active campaigns, and actionable guidance - written for security teams, compliance managers, and executive stakeholders.
Questions about your exposure to anything in this report? SOClogix Shield MDR clients receive proactive detection coverage and patch-priority guidance for the threats above. Talk to our team to schedule a consultation.