Episode Description
Here is your briefing for Tuesday, August 25, 2026. Five stories where a maximum-severity Oracle flaw is already being exploited in the wild, Microsoft 365 phishing campaigns are scaling aggressively, npm supply chains are being weaponized for CAPTCHA phishing, notebook tools are getting hit with MCP injection, and WordPress SAML plugins are handing out admin access. CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog with a perfect 10.0 CVSS score. The flaw in Oracle HTTP Server and WebLogic Server Proxy Plug-in lets unauthenticated attackers with network access create, delete, or modify critical data and gain complete access to everything the plug-in can reach. Patches exist but exploitation is already happening. When a ten-out-of-ten remote unauthenticated bug is live in the wild on enterprise middleware, every exposed instance is a potential beachhead. ANY.RUN researchers tracked a commercial phishing-as-a-service toolkit called Mirage2FA that has targeted thousands of organizations since 2024. It steals passwords and session cookies to hijack authenticated Microsoft 365 sessions, bypassing two-factor authentication and opening doors to SSO-connected services. Forty-eight percent of targeted addresses were potentially compromised, with the US accounting for nearly two-thirds of victims. Once the session is stolen, impersonation and downstream fraud become trivial. Credential and session theft remains the highest-leverage initial access technique. OX Security researchers uncovered twenty-four malicious npm packages that serve as free hosting for ClickFix-style phishing pages. The packages contain a single HTML file that redirects victims to fake CAPTCHA flows designed to steal credentials. The threat actor is not trying to infect developers who install the packages