New SynkLoader malware pushed in Microsoft Teams phishing campaign
2026-08-22T01:23:21Z•ad3036312b26281239169675fbe62a2c8a48cdc899cf3fe253046b40bac593bd
AWSAndroidCISAElementor ProEntra IDFTPMLflowMicrosoft TeamsRATRustTrueConf ServerWordPressactive-exploitationcloud-securitycredential-theftdata-breachmalwarephishingremote-code-executionsoftware-supply-chain
What happened
BleepingComputer security feed covering active exploitation of critical vulnerabilities, phishing and malware campaigns, cloud credential exposure, software supply-chain compromise, data breaches, and high-impact product security issues. Key risks include SynkLoader distributed through Microsoft Teams phishing, exposed active AWS keys enabling account takeover, actively exploited TrueConf Server and MLflow flaws, a maximum-severity Entra ID vulnerability, FTP banner abuse delivering RATs, a poisoned Rust crate, and critical Elementor Pro remote code execution.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- ad3036312b26281239169675fbe62a2c8a48cdc899cf3fe253046b40bac593bd
- Enrichment time
- 2026-08-22T01:23:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.