Catan and Mouse

2026-07-06T20:51:59Z1781aeeb48f8e9a956e526975cd595b0c28bf42fe41ec3b4fb72684c9783eb4b
ARTokenBECCOM abuseDICOMMediaAreaMediaInfoLibMicrosoft 365OrthancPRT persistencePrimary Refresh TokenSharePoint exfiltrationdevice-code-phishingemail-compromiseheap-overflowpatch-tuesdayphishing-as-a-servicereverse-engineeringsnort-rulesthreat-huntingvbdecvulnerability-research

What happened

Cisco Talos blog feed (June–July 2026) covering multiple research and intel topics: a detailed breakdown of “ARToken,” an EvilTokens affiliate phishing‑as‑a‑service panel targeting Microsoft 365 (80+ API endpoints for device‑code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration); disclosure of MediaArea heap‑based buffer overflows in MediaInfoLib; a DICOM/Orthanc heap overflow technical white paper; an introduction to COM misuse by Windows threats and a how‑to for scripting vbdec via its live COM interface for agentic reverse engineering; a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisco_talos
Record identifier
1781aeeb48f8e9a956e526975cd595b0c28bf42fe41ec3b4fb72684c9783eb4b
Enrichment time
2026-07-06T20:51:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Catan and Mouse · Baitaphish