【已复现】Fastjson 1.2.83 远程代码执行漏洞(QVD-2026-43021)安全风险通告第二次更新
奇安信开源卫士20260721.1430版本已支持对 Fastjson 1.2.83 远程代码执行漏洞(QVD-2026-43021)的检测。
Kali365 is targeting US organizations with device code phishing attacks that abuse legitimate Microsoft authentication. Instead of directing victims to a fake login form, the phishkit sends them to a real Microsoft page, where they authorize access using an attacker-controlled device code. This makes the attack harder for analysts to spot and more dangerous for the business. By obtaining OAuth access and refresh tokens, attackers may gain continued access to Microsoft 365 […]
The post Kali365 Targets US Organizations with Data Theft via Device Code Phishing appeared first on ANY.RUN's Cybersecurity Blog.