New SynkLoader malware pushed in Microsoft Teams phishing campaign

2026-08-22T07:23:21Z2625a77d6e0ca61ef97da5860801da76e88723a837400a823cc2aa48826a540f
AWSAndroidCISAElementor ProFTPMLflowManicMicrosoft Entra IDMicrosoft TeamsRATRustSynkLoaderTrueConfWordPressactive-exploitationarrayrefcredential-theftdata-breachexposed-access-keysmalwarephishingremote-code-executionsoftware-supply-chain

What happened

BleepingComputer security feed containing reports on active exploitation of critical vulnerabilities, malware campaigns, credential theft, cloud key exposure, supply-chain compromise, and data breaches. The highest-risk items include SynkLoader Teams phishing, actively exploited TrueConf and Microsoft Entra ID flaws, FTP-delivered RATs, a poisoned Rust crate, critical Elementor Pro RCE, exploited MLflow, and exposed AWS keys.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
2625a77d6e0ca61ef97da5860801da76e88723a837400a823cc2aa48826a540f
Enrichment time
2026-08-22T07:23:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New SynkLoader malware pushed in Microsoft Teams phishing campaign · Baitaphish