Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
2026-09-13T19:23:59Z•649c5c41ae93fdb63d9a18e46d00a30bce2386961185dd895b370156f3708a87
CVE-2026-20079CVE-2026-42016CVE-2026-85706AI-assisted attacksAPTAndroid malwareCISA KEVCheck PointCisco Secure Firewall Management CenterCitrixFortinetGitLabJFrog ArtifactoryMFA bypassMikroTik RouterOSPaperCutScreenConnectactive exploitationarbitrary file readauthentication bypasscloud account takeovercredential theftdata exfiltrationpasskey phishingpath traversalransomwareremote code executionsoftware supply chain
What happened
The feed highlights active exploitation of critical enterprise vulnerabilities, including Cisco Secure Firewall Management Center authentication bypasses, JFrog Artifactory flaws, GitLab arbitrary file reads, PaperCut vulnerabilities, and issues affecting network and security appliances. It also covers passkey and cloud-account phishing, malware and ransomware campaigns, AI-assisted exploitation, software supply-chain attacks, Android banking malware, exposed AI gateways, and espionage activity using exploit kits. Organizations should prioritize KEV-listed and actively exploited flaws, patch C
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 649c5c41ae93fdb63d9a18e46d00a30bce2386961185dd895b370156f3708a87
- Enrichment time
- 2026-09-13T19:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.