Hackers Favor US Eastern Business Hours in M365 Phishing Campaign

2026-09-11T14:52:08Z9092479f35d7a7e27372749899c2fdb60e0b822e0a8c5afb351568b5ea7bb7e4
CVE-2026-86218AI agentsAI securityAndroid malwareDirect SendLazarusMicrosoft 365actively exploited vulnerabilitiesbotnetcredential theftcryptocurrency theftcybercrimedata breachdata extortiongovernment cybersecurityinsider threatnon-human identitiesphishingphishing-as-a-serviceprivacyprivilege escalationransomwareremote code executionshadow AIsupply-chain securityzero-day

What happened

Infosecurity Magazine feed covering September 2026 security news, including Microsoft 365 phishing and credential theft, Android malware, ransomware and data extortion, actively exploited zero-days, supply-chain breaches, AI-agent and shadow-AI risks, cybercrime disruption, and government cybersecurity policy. Notable vulnerabilities include CVE-2026-86218, a critical N-able remote-code-execution flaw; Microsoft’s September update reportedly addressed 974 CVEs including critical issues and zero-days. Several reports describe exploitation in the wild, but most entries are news summaries without

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
9092479f35d7a7e27372749899c2fdb60e0b822e0a8c5afb351568b5ea7bb7e4
Enrichment time
2026-09-11T14:52:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hackers Favor US Eastern Business Hours in M365 Phishing Campaign · Baitaphish