| Development | Details |
|---|---|
| Two independent M365 AiTM campaigns with shared infrastructure emerged. BigBear 2.0 (PhaaS) and PREY-0058 (vishing) both use NodeMaven residential proxies to replay stolen sessions. BigBear stole 5,100+ credentials from 258 orgs. | Shared infrastructure suggests common supply chain |
| MikroTik "MikroTrick" exploitation confirmed active in the wild. CERT Polska warns of CVE-2026-67276/86060, allowing unauthenticated SSH and full admin takeover. | 122,500 devices globally remain exposed |
| China-nexus actors mass-exploiting SharePoint CVE-2025-53770 (CVSS 9.8) for government access across 8+ countries. | Deserialization flaw enabling webshell deployment |
| SAP September Patch Day includes a CVSS 10.0 vulnerability (CVE-2026-44756), no auth required. | State financial/HR SAP systems need immediate assessment |
| CrowdStrike FalconFlank PoC verified - a Falcon Sensor config creates a local privesc path to SYSTEM. | Phase 3 + macro removal enabled agencies affected |
| U.S. State Dept announced a $10M reward for IRGC Cyber Chief Amir Yaryab, head of CyberAv3ngers. | Signals water/wastewater infra remains a priority Iranian target |
| Date | Event | Severity |
|---|---|---|
| Nov 2023 - Jan 2024 | CyberAv3ngers (IRGC) compromise 75+ Unitronics PLCs including 34 U.S. water systems | CRITICAL |
| Jul 2025 | Microsoft confirms in-the-wild exploitation of SharePoint CVE-2025-53770 (CVSS 9.8) | CRITICAL |
| Sep 1, 2026 | SonicWall discloses CVE-2026-83548 (CVSS 10.0) in SMA 1000 - active exploitation | CRITICAL |
| Sep 3, 2026 | MikroTik patches "MikroTrick" chain; 122,500 devices globally still exposed | HIGH |
| Sep 7, 2026 | BigBear 2.0 PhaaS disclosed - 258 orgs compromised, 5,137 credentials stolen | HIGH |
| Sep 8, 2026 | $10M reward announced for IRGC Cyber Chief Amir Yaryab (CyberAv3ngers) | HIGH |
| Sep 8, 2026 | SAP September Patch Day - CVE-2026-44756 (CVSS 10.0) plus 3 more critical CVEs | HIGH |
BigBear 2.0 is an Evilginx2-based PhaaS platform compromising 258 orgs across 40+ countries (474 MFA-bypassed sessions, 1,032 passwords, 4,148 cookies), using custom JavaScript to actively disable FIDO2/WebAuthn.
PREY-0058 calls executives impersonating IT help desk, directing them to rogue portals for session theft. Both use NodeMaven residential proxies to geo-match victim locations, defeating impossible-travel detection.
CVE-2026-67276 (SSH auth bypass) chains with CVE-2026-86060 (privesc via crafted username) for full admin control. CERT Polska confirms active exploitation; 122,500 devices remain exposed despite patches (RouterOS 6.49.21/7.23.4/7.24.2).
Multiple Chinese groups actively exploit CVE-2025-53770 (CVSS 9.8) against on-premises SharePoint, targeting government, financial, manufacturing, tech, and telecom across 8+ countries with webshell deployment. A separate TWOPIPE backdoor campaign targets similar sectors across 19 countries.
The $10M reward for Amir Yaryab (IRGC-CEC chief) is itself an intelligence signal - CyberAv3ngers compromised 75+ Unitronics PLCs including 34 U.S. water systems (2023-24) via default credentials on port 20256, replaced ladder logic, and disabled remote engineering.
SAP's September release has 4 critical CVEs: CVE-2026-44756 (10.0), CVE-2026-58240 (9.8), CVE-2026-76969 (9.4), CVE-2026-66768 (9.0). No exploitation reported yet but demands assessment.
FalconFlank: a verified PoC demonstrates local privesc to SYSTEM via Falcon's macro remediation. No CVE assigned; disable the policy.
| Scenario | Probability | Timeframe | Basis |
|---|---|---|---|
| Additional AiTM phishing campaigns target state M365 tenants using BigBear or similar PhaaS platforms | HIGH (75-85%) | Next 7 days | BigBear's affiliate model incentivizes rapid expansion; 258 orgs already compromised |
| FIDO2-disabling technique proliferates to other PhaaS platforms | HIGH (70-80%) | Next 30 days | Effective, technically straightforward; PhaaS operators share tooling |
| China-nexus actors expand SharePoint CVE-2025-53770 exploitation to additional U.S. state targets | MODERATE-HIGH (60-70%) | Next 30 days | Government is an explicit target; public PoC; many instances lag patching |
| MikroTik exploitation adopted by ransomware affiliates for state/local government access | MODERATE (50-60%) | Next 30 days | Ransomware groups historically adopt weaponized edge exploits within weeks |
| CyberAv3ngers/successor conducts new ICS targeting against U.S. water/wastewater | LOW-MODERATE (30-40%) | Next 90 days | Reward may disrupt operations but signals persistence |
| Ransomware group (Qilin, Rhysida, SafePay) successfully attacks a U.S. state/local entity | HIGH (70-80%) | Next 30 days | All three maintain active targeting; identity-based access is the dominant vector |
Query Entra ID logs for auths from residential proxy ASNs. Escalate: proxy sign-in + SharePoint enumeration or bulk downloads within 60 min.
Compare registered vs. actual auth method in Entra ID. Flag FIDO2 accounts falling back to push/SMS.
Monitor DNS changes; run /system/device-mode/print for compromise flags.
Monitor IIS logs for new .aspx files; alert on w3wp.exe spawning shells.
Alert on exec sign-ins from new devices with SharePoint enumeration or bulk downloads.
Scan for exposed Unitronics PLCs/HMIs (port 20256); verify no default credentials.
| Threat | ATT&CK |
|---|---|
| 1. Residential Proxy Session Replay | T1557 T1539 T1078 |
| 2. FIDO2 Downgrade Detection | T1557 T1539 |
| 3. MikroTik Compromise Indicators | T1190 T1068 T1562.004 |
| 4. SharePoint Webshell | T1190 T1505.003 T1059.001 |
| 5. IT Help Desk Vishing | T1566.003 T1213.002 T1530 |
| 6. ICS/OT Monitoring | T1190 T1078.001 T0831 |
Do NOT block Pastebin[.]com - legitimate service abused for C2/exfil; alert on programmatic access instead. SHA-256: 2a695840f9f1f8dc945009e9fd0df25f51bb148b2d637653b0f2b20583ec1516 +7 more; SHA-1: 77556c57999805fa7815a114da51d91cf24fbea9 +1 more. Full list via Anomali ThreatStream Next-Gen.
- Prioritize SAP patch
- Brief CFOs vishing
- Audit exposed PLCs (port 20256)
- Segment OT
- Verify backups
- Enforce compliance
- Verify SharePoint fixes
- Brief on vishing
- Patch MikroTik at remote sites
- Include SAP for fleet mgmt
The threat landscape has shifted materially this week. AiTM phishing that defeats MFA, actively exploited edge-device zero-days, nation-state SharePoint exploitation targeting government, and an escalating Iranian ICS threat create a multi-vector risk no single control addresses. MFA is necessary but no longer sufficient - when adversaries disable FIDO2 keys and replay sessions through geo-matched residential proxies, defense must shift to device compliance, continuous access evaluation, and behavioral detection. The edge is under siege: MikroTik, SharePoint, SonicWall, SAP - every internet-facing service is a potential entry point.