Attackers call employees’ personal phones to break into Microsoft 365 accounts

2026-09-10T14:51:41Z5e6e421b1b4783b0eb37e9aaffcfceee8a0054c84b7f3e8096f282d60809fc24
CVE-2026-20079CVE-2026-20316AI securityCisco Secure Firewall Management CenterMicrosoft 365OAuth phishingWordPress securityactive exploitationblob URLbrowser-based phishingcredential theftfake softwareinfostealermalware distributionphishingplugin supply chainransomwaresmishingsocial engineeringthird-party risk managementvishing

What happened

Help Net Security RSS items cover active exploitation of Cisco Secure Firewall Management Center vulnerabilities, Microsoft 365 social-engineering and browser-based phishing campaigns, malware disguised as a fake GTA 6 download, credential theft, WordPress plugin supply-chain safeguards, AI governance, and security product or standards announcements. The most urgent item is active exploitation of Cisco FMC vulnerabilities by nation-state and ransomware actors.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
5e6e421b1b4783b0eb37e9aaffcfceee8a0054c84b7f3e8096f282d60809fc24
Enrichment time
2026-09-10T14:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.