Microsoft Disrupts EvilTokens Device Code Phishing Service
2026-09-22T20:51:34Z•d0f15c131c9c64c0b50063da64651df66d2bfe5ef30374539913cc0c582d46ca
CVE-2026-76460CVE-2026-85706AI-securityAPTCISAChinaCisco-ISEGitHubGitLabMicrosoft-365North KoreaOAuth-abuseRussiaWindowsactive-exploitationagentic-AIdata-breachdevice-code-phishingidentity-attacksindustrial-securitymalware-as-a-servicenpmphishing-as-a-serviceransomwaresupply-chain-attackthreat-intelligencezero-day
What happened
Dark Reading feed covering major cybersecurity developments from September 2026, including Microsoft disruption of the EvilTokens device-code phishing service, OAuth and identity abuse, supply-chain compromises, AI-enabled attacks and governance risks, active exploitation of critical Cisco, GitLab, Windows, and Microsoft vulnerabilities, malware-as-a-service, APT espionage, ransomware extortion, and mobile banking malware. The most urgent items involve actively exploited or maximum-severity vulnerabilities and attacks targeting Microsoft 365, enterprise identity, software supply chains, and AI
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- d0f15c131c9c64c0b50063da64651df66d2bfe5ef30374539913cc0c582d46ca
- Enrichment time
- 2026-09-22T20:51:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.