Catan and Mouse

2026-07-02T20:51:51Z9a735cd36f510ae3b6671d4fb25c9e9fbe9f414cefcd055bfba672fd28b88066
AI-enabled threat intelARTokenBECCOM abuseDICOMEvilTokensGDCMMediaAreaMediaInfoLibMicrosoft 365OrthancPRT persistencePatch Tuesday June 2026SharePoint exfiltrationSnort rulesdevice-code phishingheap overflowphishing-as-a-servicepydicomreverse engineeringthreat huntingvbdec

What happened

Cisco Talos blog roundup covering multiple research and analysis items. Notable findings: ARToken — an EvilTokens-derived phishing-as-a-service panel targeting Microsoft 365 with 80+ API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, email access, BEC workflows, and SharePoint exfiltration; discovery of four heap-based buffer overflow vulnerabilities in MediaArea’s MediaInfoLib; a DICOM-focused white paper demonstrating heap overflow exploitation in medical imaging stacks (pydicom, GDCM, Orthanc); an overview of COM usage by Windows threats and a new workflow

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisco_talos
Record identifier
9a735cd36f510ae3b6671d4fb25c9e9fbe9f414cefcd055bfba672fd28b88066
Enrichment time
2026-07-02T20:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Catan and Mouse · Baitaphish