Catan and Mouse
2026-07-02T20:51:51Z•9a735cd36f510ae3b6671d4fb25c9e9fbe9f414cefcd055bfba672fd28b88066
AI-enabled threat intelARTokenBECCOM abuseDICOMEvilTokensGDCMMediaAreaMediaInfoLibMicrosoft 365OrthancPRT persistencePatch Tuesday June 2026SharePoint exfiltrationSnort rulesdevice-code phishingheap overflowphishing-as-a-servicepydicomreverse engineeringthreat huntingvbdec
What happened
Cisco Talos blog roundup covering multiple research and analysis items. Notable findings: ARToken — an EvilTokens-derived phishing-as-a-service panel targeting Microsoft 365 with 80+ API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, email access, BEC workflows, and SharePoint exfiltration; discovery of four heap-based buffer overflow vulnerabilities in MediaArea’s MediaInfoLib; a DICOM-focused white paper demonstrating heap overflow exploitation in medical imaging stacks (pydicom, GDCM, Orthanc); an overview of COM usage by Windows threats and a new workflow
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisco_talos
- Record identifier
- 9a735cd36f510ae3b6671d4fb25c9e9fbe9f414cefcd055bfba672fd28b88066
- Enrichment time
- 2026-07-02T20:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.