Skip to main content
All Threat Briefings
Weekly Threat AwarenessAugust 27, 2026|Vol. 1 · Issue 10

Weekly Threat Awareness ReportEntra ID RCE · SharePoint Bypass Exploited · Mirage2FA Session Theft

A critical deserialization flaw in Microsoft Entra ID that can hand an attacker control of the identity platform leads this week, alongside a SharePoint security-feature bypass under confirmed exploitation by TA505, Mustang Panda and other advanced groups, and a WordPress login-page XSS that APT groups including Kimsuky and APT37 are exploiting in the wild. On the campaign side, the Telegram-sold Mirage2FA kit is hijacking Microsoft 365 accounts by stealing the session that MFA was meant to protect, and the newly documented Evooo1Bot botnet is spreading across internet-facing Linux devices. The through-line: identity is the target - the directory itself, the collaboration layer built on it, and the session cookie issued after a successful sign-in.

VT

Vaughn Thomas

Compliance Engineer & Threat Researcher · SOClogix Cyber Group

Technical review: William Johnson, VP of Security Operations

About the Analyst

Vaughn Thomas is SOClogix's Compliance Engineer and principal threat researcher, operating at the intersection of regulatory compliance and active adversary tradecraft. Each week, Vaughn synthesizes intelligence from dark web forums, vendor security advisories, CISA KEV updates, Shodan/Censys exposure data, and real-time telemetry from SOClogix's managed client network - spanning healthcare, financial services, defense industrial base, manufacturing, and local government - to produce actionable threat awareness briefings written for security teams and executive stakeholders at every level. Vaughn actively tracks over 200 threat actor groups and contributes threat sharing intelligence to multiple ISAC communities. His analysis deliberately bridges raw technical findings and business risk so compliance teams and CISOs can act, not just read.

Full bio and published research LinkedIn

200+

Threat groups tracked

50+

Intel feeds monitored

3 yrs

Threat research tenure

This Week's Threat Landscape Mindmap

Threat landscape for August 10 - August 16, 2026: top threats, active actors, attack trends, sector exposure, and what to do now.

Threat landscape mindmap, August 10-16, 2026. Weekly assessment: edge appliances and identity are the fast lane to domain compromise. Top threats: INC Ransomware SonicWall SMA1000 root VPN takeover, KerberLoss / ResetNightmare AD domain takeover, ChainDrop npm worm, Citrix NetScaler pre-auth RCE.
Weekly assessment: edge appliances and identity are the fast lane to domain compromise. Priority: patch and hunt exposed VPN/edge devices, harden Active Directory identity paths, and treat AI-accelerated phishing and supply chain as default-on threats. View full size

Vulnerabilities at a Glance

Exploitation status and required action for each client-facing CVE covered this week.

CVEProductSeverityExploitation StatusFixPriority
CVE-2026-69836Microsoft Entra IDCriticalExploitation not confirmedApply Microsoft remediationURGENT
CVE-2026-55040Microsoft SharePointHighActive - APT-linked; public exploitPatch immediatelyURGENT
CVE-2026-64638WordPress (login screen)HighActive - APT-linked; public PoCs7.0.3 (patches back to 4.7)URGENT

CVEs Affecting Client Assets

Vulnerabilities identified this week with direct relevance to common enterprise environments. Two are under active exploitation by named advanced threat groups.

CriticalCVE-2026-69836 New this week

Microsoft Entra ID - Remote Code Execution

Deserialization of Untrusted Data (CWE-502)  ·  Unauthorized · Remote

A critical flaw in the core functionality of Microsoft Entra ID lets an unauthorized attacker remotely execute malicious code. It stems from deserialization of untrusted data: the service can be deceived into processing malicious instructions as if they were legitimate, potentially handing control to the attacker. Successful exploitation could give an attacker full control over the affected Entra ID environment, leading to large-scale data breaches, unauthorized access to sensitive company resources, and the compromise of user identities. Because Entra ID is the identity layer in front of Microsoft 365, Azure, and every federated application, any organization relying on it faces the risk of total system takeover while this remains unremediated.

Recommended Actions

  • Prioritize remediation of this vulnerability above all other maintenance tasks
  • Apply Microsoft's remediation for Entra ID immediately and confirm it has taken effect across your tenant
  • Review Entra ID audit and sign-in logs for unexplained administrative changes while remediation is in progress
HighCVE-2026-55040 New this week Actively exploited Public PoC APT-linked

Microsoft SharePoint - Security Feature Bypass

Weak Authentication  ·  No credentials required · Network  ·  Actively exploited

A high-risk vulnerability rooted in weak authentication mechanisms within Microsoft SharePoint lets an unauthorized attacker bypass the security features protecting the system, gaining access over a network without valid credentials. Any organization using SharePoint for data management is at risk, and a successful breach could lead to significant data theft, operational disruption, and severe reputational damage. Sophisticated groups including TA505, Bookworm, Mustang Panda, and COBALT DICKENS have been linked to this activity. With public exploit code available on GitHub and significant discussion on social media, the risk of widespread attack is extremely high.

Recommended Actions

  • Patch all affected SharePoint systems immediately - confirmed exploitation by advanced actors makes this an emergency change, not routine maintenance
  • Start with SharePoint servers reachable from the internet: the flaw is exploitable over the network without valid credentials
  • Review SharePoint access logs for unauthenticated activity against protected resources since public exploit code appeared
HighCVE-2026-64638 New this week Actively exploited Public PoC APT-linked

WordPress Login Screen - Cross-Site Scripting

Cross-site Scripting (CWE-79)  ·  Remote  ·  Fixed in 7.0.3, backported to 4.7

A high-severity cross-site scripting flaw in the WordPress login screen lets an attacker inject malicious code into the login page to trick an administrator or user into running unintended commands - and from there, escalate a simple web-based attack into full control of the site. It is being actively exploited in the wild, with numerous proof-of-concept exploits circulating online. Advanced persistent threat groups including Kimsuky, APT37, and UNC6671 have been linked to the threat environment, marking it as a high-priority target for sophisticated attackers. WordPress has released version 7.0.3 and has also shipped security patches for all older versions dating back to 4.7.

Recommended Actions

  • Update to WordPress 7.0.3 immediately
  • On an older branch, apply the security release for that branch now - patches are available for every version back to 4.7, so a major upgrade is not a prerequisite
  • Verify the installed version on every site you manage rather than assuming automatic updates succeeded

Active Threats & Campaigns

Threat actor activity and disclosed tradecraft with immediate defensive relevance.

Phishing-as-a-ServiceANY.RUN · Fortra · Abnormal Intelligence New this week

Mirage2FA - Telegram-Sold PhaaS Kit Bypassing Microsoft 365 MFA

Mirage2FA is a Phishing-as-a-Service kit sold on Telegram that hijacks Microsoft 365 sessions through an Adversary-in-the-Middle (AiTM) proxy, stealing credentials, MFA responses, and session tokens. Delivery relies on HTML smuggling, fake CAPTCHAs, and cloned Microsoft login pages. The kit does not defeat MFA directly - it captures the authenticated session cookie created after a successful MFA challenge, inheriting the session MFA was meant to protect. ANY.RUN logged 9,426 targeted mailboxes and 4,532 likely compromised across 94 countries, mostly in the US. Session theft dominates the outcome mix: of 9,332 potential compromise events, 4,561 were cookie theft, 3,044 password/2FA captures, and 1,339 SSO logins - a kit optimized for durable account takeover rather than one-shot credential resale. Attribution is commercial-criminal, not nation-state: the platform runs as a multi-tenant, Telegram-managed service (tracked in underground telemetry as LinXcoded), so many downstream actors run campaigns off the same core kit. OSINT artifacts - Telegram bot references in the JavaScript, a .my.id domain, and ASN registration records - point to the aliases LinXcoded and zxcoder; these are operator-linked indicators, not confirmed identity attribution.

Recommended Actions

  • Enforce phishing-resistant, AiTM-proof MFA (FIDO2 security keys, passkeys, or certificate-based authentication) for Microsoft 365
  • On a suspected compromise, revoke active sessions and refresh tokens - a password reset alone leaves a stolen session cookie valid
  • Retire legacy Entra ID authentication endpoints, as flagged in this week's mindmap

Threat Profile

Type: AiTM phishing kit, sold as PhaaS on Telegram

Also tracked as: LinXcoded

Delivery: HTML smuggling, fake CAPTCHAs, cloned Microsoft logins

Scope: 9,426 mailboxes targeted, 4,532 likely compromised

Reach: 94 countries, mostly the US

Attribution: Commercial-criminal, not nation-state

Linux BotnetFortiGuard Labs · August 2026 New this week

Evooo1Bot - Mirai-Based Modular Botnet Targeting Internet-Facing Devices

Evooo1Bot is a previously undocumented Linux botnet family that reuses the DDoS engine from the publicly leaked Mirai source code and wraps it in a far more modular framework. Its name comes from the hardcoded string "evooo1" found in every binary, and FortiGuard Labs documented the family in August 2026. Observed distribution is concentrated in North America, Europe, and Asia, with a smaller share in South America, and targeting patterns are consistent with automated vulnerability scanning and per-CVE payload selection. Pairing SSH brute-forcing with CVE exploitation gives the operator two growth paths: opportunistic spread through weak credentials, and targeted compromise of unpatched systems.

Recommended Actions

  • Disable SSH password authentication on internet-facing devices, or restrict SSH to trusted networks
  • Keep internet-facing Linux devices and appliances patched - the botnet selects its exploit payload per CVE
  • Replace default or weak credentials on any device that cannot be taken off the internet

Threat Profile

Source: FortiGuard Labs

Lineage: Leaked Mirai DDoS engine

Identifier: Hardcoded "evooo1" string

Spread: SSH brute force + per-CVE exploits

Targets: Internet-facing Linux devices

Distribution: N. America, Europe, Asia; some S. America

Sources

Primary reporting behind this week's briefing.

  • · Microsoft Security Update Guide - CVE-2026-69836, CVE-2026-55040
  • · WordPress 7.0.3 security release - CVE-2026-64638
  • · ANY.RUN - Mirage2FA campaign telemetry
  • · Fortra and Abnormal Intelligence - Mirage2FA / LinXcoded research
  • · FortiGuard Labs - Evooo1Bot research
VT

Vaughn Thomas

Compliance Engineer & Threat Researcher, SOClogix

Technical review: William Johnson, VP of Security Operations

Full bio →
VT

Vaughn Thomas

Compliance Engineer

SOClogix Cyber Group

200+

Threat groups tracked

50+

Intel feeds monitored

52×

Reports per year

Global dark web & forum monitoring
Live CISA KEV & NVD tracking
Adversary TTP analysis
Compliance-threat intersection

Get Weekly Briefings Free

Confirmed via email. No spam. Unsubscribe anytime.

This Week at a Glance

CVEs covered3
Actively exploited2
Public exploit code2
APT-linked2
Active campaigns2
M365 mailboxes compromised4,532

Get Vaughn's Briefing Every Week

Free weekly threat awareness reports delivered to your inbox. CVEs, active campaigns, and actionable guidance - written for security teams, compliance managers, and executive stakeholders.

Confirmed via email. No spam. Unsubscribe anytime.

Questions about your exposure to anything in this report? SOClogix Shield MDR clients receive proactive detection coverage and patch-priority guidance for the threats above. Talk to our team to schedule a consultation.