FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

AI-Orchestrated Phishing Campaigns Targeting the Financial Sector

A new wave of AI-orchestrated phishing campaigns is targeting the global financial sector, utilizing Large Language Models (LLMs) and deepfake synthesis to bypass legacy security perimeters. Attackers are deploying high-velocity automation, executing campaigns at an observed rate of one attack every 19 seconds. Technical vectors include Device Code Phishing designed to hijack OAuth authentication flows, AI-generated malware tailored for financial environments, and sophisticated brand impersonation that evades linguistic-based spam filters. This paradigm shift from manual templates to high-fidelity, automated social engineering significantly increases the success rates of Business Email Compromise (BEC) and session hijacking.

Microsoft 365 Copilot: 'SearchLeak' Indirect Prompt Injection Vulnerability

Researchers at Varonis Threat Labs have identified 'SearchLeak' (CVE-2026-42824), a critical indirect prompt injection vulnerability in Microsoft 365 Copilot Enterprise Search. The vulnerability utilizes a Parameter-to-Prompt (P2P) technique via the ?q= URL query parameter to manipulate the LLM. By exploiting a race condition during incremental HTML rendering, an attacker can inject malicious <img> tags that bypass Content Security Policy (CSP) restrictions. Through the exploitation of Bing’s Image Search imgurl= parameter, the attack facilitates the silent exfiltration of sensitive data—including 2FA codes, SharePoint documents, and emails—by leveraging the user's inherited Microsoft Graph API permissions.


LINK COPIED TO CLIPBOARD