top of page

Cobalt Shields — What We're Reading Today

  • Writer: Steve Fabiani
    Steve Fabiani
  • May 27
  • 2 min read

Here are some stories that have caught our eye in the last week. These touch on issues relevant to our healthcare, higher ed, K-12, government, and nonprofit colleagues.

Microsoft released a fix for CVE-2026-45659 (CVSS 8.8), a deserialization-of-untrusted-data flaw in on-premises SharePoint Server that lets an authenticated user with only Site Member permissions execute code remotely — no administrator rights required. The bug affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Microsoft rates it "less likely to be exploited" and no in-the-wild attacks have been reported, but SharePoint flaws have been repeatedly weaponized, so administrators of self-hosted farms should patch promptly. On-prem SharePoint remains common across higher-ed, healthcare, and government, making this a priority update for those IT teams. | Source: The Hacker News

Researchers detailed a refined MuddyWater (Seedworm) espionage campaign in which the IRGC-linked Iranian group abused legitimately signed Fortemedia and SentinelOne binaries to side-load malicious DLLs, then ran Node.js-launched PowerShell for reconnaissance and credential theft via the ChromElevator tool. Nine organizations across four continents were hit — spanning education, public sector, financial services, industrial manufacturing, and professional services — with attackers dwelling about a week inside one South Korean victim and staging stolen data on the public sendit.sh service. The operators showed markedly improved operational security over prior campaigns. Education and government IT teams should hunt for anomalous use of signed vendor binaries and unexpected Node.js or PowerShell activity. Companion analysis: https://www.securityweek.com/iranian-apt-targets-aviation-software-companies-with-updated-tools/ | Source: The Hacker News

Microsoft is previewing an automatic device-isolation capability in Defender for Endpoint that, as part of "automatic attack disruption," cuts a suspected-compromised workstation off from the network while keeping it connected to the Defender service for continued monitoring. The feature aims to contain threats and limit lateral movement without waiting for analyst action, and security teams can manually release devices after investigating through the device inventory. It currently works only on onboarded end-user workstations and remains in preview. The change is relevant to resource-constrained healthcare, education, and government SOCs weighing automated containment against the risk of disrupting legitimate endpoints. | Source: BleepingComputer

Lithuania's State Enterprise Centre of Registers disclosed that more than 600,000 entries from the country's real-estate and legal-entity registers were accessed using stolen credentials belonging to institutions authorized to query the data. Officials suspect a foreign state — an opposition politician pointed to Russia without providing evidence — amid Lithuania's standing as a frequent target of hybrid operations against Europe. Authorities have blocked the suspected accounts and now require credential updates for register access, and the agency's head resigned over the incident. The breach is a reminder for government data custodians that authorized third-party credentials are a prime avenue for large-scale register compromise. | Source: SecurityWeek

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page