Skip to main content
New AI-powered DMARC analysis + open REST API See how → →
Intermediate

CISA Warns SharePoint, SimpleHelp Auth Bypass, Russian Spies Target

Brad Slavin
Brad Slavin General Manager

Quick Answer

CISA has warned about critical SharePoint and SimpleHelp authentication bypass vulnerabilities while highlighting Russian cyber espionage activity targeting organizations. Businesses should patch affected systems, strengthen access controls, and monitor for signs of compromise.

cybersecurity threat warning

CISA flags actively exploited SharePoint RCE (CVE-2026-45659)

A high-severity remote code execution flaw in on-premises SharePoint Server, caused by deserialization of untrusted data, was patched by Microsoft in May 2026, and CISA added it to the Known Exploited Vulnerabilities catalog after confirming active exploitation, with federal agencies given until July 4 to patch. Good “patch now” angle for your readers, especially since Microsoft originally rated it “exploitation less likely.”

SimpleHelp RMM auth bypass used to hit MSPs (CVE-2026-48558)

An attacker exploited a flaw in SimpleHelp’s OpenID Connect login to forge a technician session on an internet-facing server, then used the platform’s own file-transfer and remote-execution features to deploy malware researchers dubbed TaskWeaver and Djinn Stealer. Strong supply-chain-risk story for MSP-focused readers. Dmarc Report 9004

FBI/CISA: Russian spies now stealing Signal Backup Recovery Keys

Russian intelligence-linked hackers have shifted from hijacking Signal accounts to tricking targets into handing over Signal Backup Recovery Keys, which let attackers restore an account’s full historical message archive. The State Department is offering a $10 million reward for information on the group known as UNC5792. Great topic tying encryption strength to human social-engineering weakness — very on-brand for a DMARC/email-security audience.

Alleged Scattered Spider member extradited to Chicago

Peter Stokes, 19, a dual US-Estonian citizen and alleged Scattered Spider member, was extradited from Finland and charged with conspiracy, cyber intrusion, and fraud in a complaint unsealed July 1. The complaint describes a May 2025 intrusion against a luxury jewelry retailer where the group demanded roughly $8 million in cryptocurrency. Dmarc Analyzer 3407

Nissan discloses employee data breach tied to Oracle zero-day

Nissan disclosed a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in attacks previously linked to the ShinyHunters extortion group.

KDDI breach exposes 14.2 million logins across six Japanese ISPs

Japanese telecom KDDI disclosed a breach of an email system used by five other ISPs (STNet, JCom, Chubu Telecommunications, NIFTY, and BIGLOBE), potentially exposing email addresses and passwords for up to 14.22 million customers.

NAIC says only public data taken in ShinyHunters PeopleSoft breach

The National Association of Insurance Commissioners says ShinyHunters stole only publicly available data, outdated logs and configuration files after exploiting a zero-day in an Oracle PeopleSoft server — despite the group’s own claims of 3.1 TB stolen.

Nidec hit with $2 million ransomware demand

The Blackfield ransomware gang is demanding $2 million from Nidec Corporation, a major Japanese manufacturer of electronic components for automotive and computing applications. What Is Dmarc 9703

Check Point tests whether AI models will build ransomware tools

Check Point Research published an analysis of an experiment with the DeepSeek AI model, in which researchers asked it to build a “file encryption tool” for a web page — a timely AI-safety angle showing how quickly a model can produce ransomware-adjacent code.

”Mistic” — a self-erasing, memory-only backdoor

A self-destructing, memory-only backdoor designed specifically so incident responders won’t find it has been tied to an initial-access-broker market selling dwell-time access for ransomware deployment.

Citrix patches NetScaler flaws including new “HTTP/2 Bomb” attack

Citrix released fixes for six NetScaler vulnerabilities, including a novel HTTP/2 Bomb denial-of-service flaw and a CitrixBleed-style information disclosure bug — worth flagging since CitrixBleed-class issues have a history of mass exploitation.

Klue/Icarus SaaS supply-chain breach hits nine security firms

Dmarc Check 9702 The Klue/Icarus SaaS supply-chain breach, in which an attacker who compromised a trusted third-party platform used established trust relationships rather than breaching each victim’s perimeter directly, exposed data at HackerOne, LastPass, and other companies whose Klue/Salesforce integrations were compromised.

Tchap, the French government’s Signal alternative, gets hacked

Tchap, a messaging app built by France’s DINUM and ANSSI for government use after foreign chat apps were banned for official work, was hacked in June, with an attacker claiming to have stolen 13.5 GB of data, including tens of thousands of user accounts and government personnel messages — a nice irony angle (a “secure alternative” getting breached).

Medtronic notifies customers after third-party data exposure

Healthcare device maker Medtronic began notifying customers about a breach that exposed their personal data to an unauthorized third party, adding to the steady drumbeat of healthcare-sector incidents this year. Protect customers with SPF, DKIM, and DMARC to strengthen cybersecurity and prevent email spoofing.

Brad Slavin
Brad Slavin

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.

LinkedIn Profile →

Take control of your DMARC reports

Turn raw XML into actionable dashboards. Start free - no credit card required.