Martin Lee: Running through the Arctic (and the threat landscape)
2026-07-01T20:52:00Z•853b34f6709731b14977962e3f2d3fb21aab66d9462d63c860bc13efe2e9b6bc
ARTokenBECCOM abuseDICOMEvidenceForgeEvilTokensGDCMMediaAreaMediaInfoLibMicrosoft 365Microsoft Patch Tuesday 2026-06OrthancPRT persistencePrimary Refresh TokenSharePoint exfiltrationWindows COMdevice-code phishingemail compromiseheap-based buffer overflowphishing-as-a-servicepydicomreverse engineeringsynthetic logsvbdecvulnerability research
What happened
This Cisco Talos RSS batch highlights multiple security research posts and tooling updates. Key items: Talos uncovered “ARToken,” an EvilTokens affiliate phishing-as-a-service panel targeting Microsoft 365 that exposes 80+ API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox access and BEC operations, and SharePoint exfiltration. Talos also disclosed four heap-based buffer overflows in MediaArea’s MediaInfoLib, a DICOM heap-overflow case study affecting DICOM/Pydicom/GDCM/Orthanc parsing, and the June 2026 Microsoft Patch Tuesday summary (including Snor
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisco_talos
- Record identifier
- 853b34f6709731b14977962e3f2d3fb21aab66d9462d63c860bc13efe2e9b6bc
- Enrichment time
- 2026-07-01T20:52:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.