1. Failed to load user data.
  2. Failed to load data. Please try again.

Threat Newsroom

AI-written security news · MLA citations

Accounts unavailable

Full Article

KLAW SECURITY NEWSOctober 7, 2026

Voice Clones, Token Theft and Critical Flaws Put Identity Defenses Under Pressure

A wave of social engineering, account hijacking and severe software vulnerabilities is putting help desks, cloud identities and exposed business systems at risk.

Organizations face a broad and fast-moving threat landscape as attackers target both the people who control access and the systems that enforce it. This week’s reported activity spans AI-enhanced voice phishing, browser-based command lures, token-stealing campaigns and critical vulnerabilities in widely used enterprise products. The common thread is the pursuit of trusted access: criminals are working around passwords and conventional defenses by manipulating employees, abusing authentication flows or exploiting flaws in systems that sit at the heart of business operations.

AI-Enhanced Voice Phishing, or vishing, is a particularly serious challenge for corporate help desks and finance teams. Attackers are reportedly using generative AI to imitate colleagues or executives, pressuring staff to reset multi-factor authentication (MFA) devices or authorize fraudulent wire transfers. A familiar voice is no longer reliable proof of identity. Organizations should require independent verification through a known, separately obtained contact channel, and use multi-person approval for sensitive account changes and financial transactions. Help desk staff should be empowered to pause urgent requests rather than treat urgency or apparent seniority as grounds for an exception.

ClickFix Browser-Based Social Engineering takes a different route to the same goal: persuading users to carry out the dangerous action themselves. A browser prompt may describe a command as a security check or installation step, then direct a person to copy and paste it into a terminal. Because the user initiates execution, the activity can evade defenses built mainly to detect downloaded files. Employees should never run commands from an unsolicited webpage or message. IT teams should limit terminal access and execution privileges where practical, monitor endpoints for unusual script activity, and provide a simple reporting route for suspicious prompts.

Several critical software flaws demand attention alongside these people-focused threats. Apple’s CVE-2026-86950 affects CoreGraphics in iOS, macOS and iPadOS; the reported out-of-bounds write could lead to arbitrary code execution. Cisco Catalyst SD-WAN Manager’s CVE-2026-76504 is an improper handling of URI encoding in an HTTP request that could let an unauthenticated remote attacker gain access with administrator privileges. Fortinet FortiMail’s CVE-2026-104286 combines path traversal with improper handling of a NULL character and may permit unauthenticated attackers to write arbitrary files through crafted HTTP or HTTPS requests. These issues affect products that may be exposed to the internet or trusted with sensitive communications and network administration, making prompt asset identification and vendor-directed remediation essential.

Two Zammad flaws illustrate how separate weaknesses can compound. CVE-2026-102489 is a session fixation vulnerability that can lead to remote code execution as the zammad user; CVE-2026-102490 could then allow that local user to escalate privileges to root. The reported ability to chain them underscores why teams should assess related vulnerabilities together, not as isolated entries on a patch list. Citrix NetScaler ADC and NetScaler Gateway are also affected by CVE-2026-88779, a memory-buffer bounds issue that could cause denial of service. For each product, administrators should check the vendor’s current guidance, identify internet-exposed instances, apply available fixes or mitigations, and watch for signs of compromise. Follow applicable CISA BOD 26-04 requirements and forensic triage guidance; if required mitigations are unavailable, evaluate whether continued use is acceptable.

The identity-focused campaigns show how attackers can bypass protections without cracking a password. The N0va device code phishing campaign targets Microsoft 365, Teams, SharePoint and OneDrive users by tricking them into entering a device code on a malicious site. The legitimate device authorization process can then provide attackers with persistent access tokens. Users should reject unexpected device-code prompts and verify the request through their organization’s approved process. Administrators should restrict device code authentication where it is not needed and review sign-in and token activity for unfamiliar locations, devices or patterns.

The CSuite multi-stage phishing campaign impersonates tools including Microsoft 365, Adobe, Dropbox, Zoom and Google Meet. Counterfeit document pages are used to steal active session tokens, potentially letting attackers bypass password-based controls and MFA after a user has authenticated. Phishing-resistant MFA, such as FIDO2 security keys, can make credential theft harder, but teams must also detect suspicious session use, revoke compromised sessions and investigate unusual access to cloud applications. Strong authentication is not a substitute for monitoring what happens after sign-in.

WaterPlum adds a recruitment-themed lure to the mix. The cryptocurrency-focused malware targets individuals with fake job approaches, steals wallet credentials and provides remote access that may be used to pivot into a victim’s corporate network. Employees should treat unexpected recruiting messages and requests to install interview or assessment software cautiously, especially when they arrive outside normal hiring channels. Organizations should block unauthorized software installation, keep endpoint protections current and make it straightforward for staff to report suspicious approaches without fear of blame.

Across these incidents, attackers are exploiting trust, access and timing. A convincing voice, a familiar cloud-service logo or a routine authentication prompt can all be turned into an entry point; meanwhile, flaws in network, email and support systems can give intruders privileged access or disrupt service. Effective defense therefore requires more than patching or annual awareness training. Organizations need layered controls: least privilege, independent verification for high-impact requests, phishing-resistant MFA, strong session monitoring, timely software updates and rehearsed incident-response procedures. Individuals can help by slowing down when asked to act urgently, refusing unsolicited instructions to run commands or enter authentication codes, and reporting anomalies promptly. The threat landscape will continue to change, but consistent verification and rapid response remain practical ways to reduce risk.