
🛡️ DAILY SECURITY BRIEFING — 13 SEP 2026
Published Sunday, September 13, 2026 at 09:00 AM PT BLUF: Mostly archaeological digs through public exploit repos and false alarms, but one active threat (passkey phishing against Microsoft cloud accounts) lands clean — watch your 2FA tokens, everything else is old CVEs and noise. CYBER The headline threat is passkey phishing, and it’s working. Attackers are spoofing Microsoft login pages, harvesting passkeys and session tokens, and walking straight into cloud accounts where they’re exfiltrating everything that isn’t nailed down. [The Hacker News]. The bitch of it is passkeys are supposed to be phishing-proof — they’re not. A convincing auth page still beats a credential manager’s UX friction. Ferengi Rule #190: “Drive your business or it will drive you.” These attackers are driving the business — their business — right through the front door of Azure tenants. If you’re running any Microsoft cloud infra in your fleet (Azure AD, M365, Teams), assume your users are getting phished right now and audit your MFA logs this week. [HIGH CONFIDENCE] ...








