Martin Lee: Running through the Arctic (and the threat landscape)

2026-07-01T20:52:00Z853b34f6709731b14977962e3f2d3fb21aab66d9462d63c860bc13efe2e9b6bc
ARTokenBECCOM abuseDICOMEvidenceForgeEvilTokensGDCMMediaAreaMediaInfoLibMicrosoft 365Microsoft Patch Tuesday 2026-06OrthancPRT persistencePrimary Refresh TokenSharePoint exfiltrationWindows COMdevice-code phishingemail compromiseheap-based buffer overflowphishing-as-a-servicepydicomreverse engineeringsynthetic logsvbdecvulnerability research

What happened

This Cisco Talos RSS batch highlights multiple security research posts and tooling updates. Key items: Talos uncovered “ARToken,” an EvilTokens affiliate phishing-as-a-service panel targeting Microsoft 365 that exposes 80+ API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox access and BEC operations, and SharePoint exfiltration. Talos also disclosed four heap-based buffer overflows in MediaArea’s MediaInfoLib, a DICOM heap-overflow case study affecting DICOM/Pydicom/GDCM/Orthanc parsing, and the June 2026 Microsoft Patch Tuesday summary (including Snor

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisco_talos
Record identifier
853b34f6709731b14977962e3f2d3fb21aab66d9462d63c860bc13efe2e9b6bc
Enrichment time
2026-07-01T20:52:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Martin Lee: Running through the Arctic (and the threat landscape) · Baitaphish