Here Come the AI-Generated BEC Scams
Messages delivered through legitimate third-party email infrastructure had C-suite sender display names, custom signatures, and direct approval notes.
All topics
Messages delivered through legitimate third-party email infrastructure had C-suite sender display names, custom signatures, and direct approval notes.
It’s our one year anniversary! This week we talk about the highlights of the last year, a new high-level phishing campaign that uses Microsoft Teams as an initial access vector, and the takedown of the ancient Sality P2P botnet. Then we offer some book and TV recommendations for the long weekend. Links One year of […]
Unlike standard commodity malware that aims for quick credential theft, this campaign features a manual, hands-on-keyboard scheme designed to escalate rapidly from a single compromised workstation to broad, network-wide access.
The chain leverages two distinct vulnerabilities—an authentication bypass and an unsafe .NET type instantiation flaw—to provide full server control without valid credentials.
The flaw (CVE-2026-50522) affects SharePoint Enterprise Server 2016 and 2019 as well as SharePoint Subscription service. Microsoft released the fix for this vulnerability on July 14.
This week we have some old-school disclosure drama when a researcher used full disclosure after months of silence from Cursor, then we discuss the enormous Patch Tuesday from Microsoft–662 bugs–and what it might mean going forward, and finally some news about DoJ sanctions and Scattered Spider members being sentenced. Links Cursor bug: https://decipher.sc/2026/07/15/bug-in… First VPN […]