View Ridge Security
Back to Cyber HoseVendor Bulletins & Advisories

Microsoft Entra ID RCE flaw exploited in the wild

๐Ÿšจ ACTIVE EXPLOITATION

  • Hackers use FTP banners to deliver E4del and PINHOLE Windows RATs
    Hackers are using FTP server banners to deliver two new Windows remote access trojans.

    • Windows users are targeted by campaigns delivering E4del and PINHOLE RATs.
    • E4del is a Node.js RAT disguised as a digitally signed Discord-like Electron app.
    • PINHOLE steals browser credentials, captures screenshots, manages files and executes commands.
    • Phishing-delivered ZIP archives launch LNK files that retrieve PowerShell scripts from FTP banners.
    • PINHOLE uses shellcode fluctuation and Early Bird APC injection into suspended ApplicationFrameHost.exe processes.
      ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer
  • Fake Gemini installer delivers Vidar infostealer through Google Colab
    Attackers used a fake Gemini installer to deliver Vidar.

    • A Windows device in a Darktrace customer environment in the EMEA region was affected.
    • The fake installer delivered a newer Go-compiled Vidar variant that stole browser credentials and sensitive data.
    • Search results led users to a Google Colab download prompt redirecting to micronsoftwares[.]com.
    • A ZIP archive included Download_Google_Gemini_For_Windows.exe and instructions to run it as administrator and add antivirus exclusions.
    • Vidar communicated with Telegram-based infrastructure including dtm[.]kijangturbo88[.]top, 91.98.98[.]86, and 91.98.111[.]49.
      ๐Ÿ“„ Source: darktrace.com ยท ๐Ÿ“Ž Coverage: helpnetsecurity.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ”“ CVEs & KEV

  • CVE-2026-77751 โ€” CVSS 8.8 โ€” Path Traversal in MISP Object Template Resolution During STIX Import and Expo...

  • CVE-2026-77755 โ€” CVSS 8.7 โ€” Denial of Service in MISP-STIX Import via Malformed or Oversized STIX Documen...

  • CVE-2026-77683 โ€” CVSS 8.6 โ€” Comfast CF-N1-S mbox-config system command injectionA security flaw has been ...

  • CVE-2026-47827 โ€” CVSS 7.5 โ€” BOSH CLI Powershell InjectionCommand Injection in BOSH CLI t...

  • CVE-2026-15576 โ€” CVSS 6.9 โ€” Agent receiver accepts mTLS requests without a client certificateImproper aut...

  • CVE-2026-77761 โ€” CVSS 6.3 โ€” Cross-Document Parser State Contamination in misp-stixA parser state isolatio...

๐Ÿ“‹ ADVISORIES

  • ๐Ÿ“„ Source for Microsoft Entra ID RCE flaw exploited in the wild โ€” msrc.microsoft.com

  • ๐Ÿ“„ Source for Russian Espionage Clusters Hijack Accounts Through OAuth and WhatsApp Linking โ€” cloud.google.com

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check