Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes
A coalition led by Microsoft and Health-ISAC has shut down EvilTokens. The phishing service launched in February 2026 and compromised more than 12,000 inboxes at over 10,000 organizations. With a court order from the Eastern District of Virginia, and help from partners including Cloudflare, Coinbase, OpenAI, and Shadowserver, investigators seized 50 websites and disabled more than 150 domains. EvilTokens used device-code phishing, which tricks victims into entering an authentication code on Microsoft’s real sign-in page. That handed attackers access that could survive a password reset. An AI chatbot then read through the stolen mailboxes to find wire transfer talks, vendor invoices, and the best people to impersonate. The service sold on Telegram for a $1,500 sign-up fee plus $500 a month. London’s Metropolitan Police arrested two men on September 11 in connection with the operation.
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
F5 and CISA are warning that attackers have exploited CVE-2026-94127 as a zero-day. The flaw is a critical bug (CVSS 9.8) in BIG-IP Access Policy Manager that lets unauthenticated attackers run code remotely by sending crafted traffic. Only systems where APM acts as an OAuth Authorization Server, with both an access policy and an OAuth profile on a virtual server, can be exploited. BIG-IP APM versions 21.1.0, 17.5.0–17.5.1, and 17.1.0–17.1.3 are affected. F5 has released hotfixes and three indicators of compromise. CISA added the bug to its Known Exploited Vulnerabilities catalog alongside two exploited Check Point flaws, and federal agencies must patch within three days.
Microsoft: September Windows updates break Always On VPN connections
Microsoft has told IT administrators that the September 2026 Windows 11 security updates can break Always On VPN connections. The problem hits VPN profiles set to try a second connection method when the first fails, such as automatic protocol selection between IKEv2 and SSTP. Affected connections can hang at “Connecting” or keep retrying, sometimes with the error “The specified port is already in use.” The updates involved are KB5124012 on version 26H1 and KB5124008 on versions 25H2 and 24H2. There is no permanent fix yet. As a workaround, admins can switch profiles to a single protocol. The same round of updates has also caused problems with Hyper-V, Remote Desktop Services, USB audio, domain logins, and File History backups.
Fake Crypto Wallet App Delivers PamStealer Malware That Hijacks Mac Credentials
A third variant of the macOS infostealer PamStealer is spreading through a fake multichain crypto wallet called “Wavel.” The download is a disk image containing a disguised compiled AppleScript. It kicks off a chain that asks an attacker-controlled server for the decryption key for each infection, so the payload can’t be recovered through static analysis alone. The new Swift-based stealer shows a fake “macOS wants to make changes” password prompt and checks the password locally through macOS PAM, so attackers only get logins that work. It then steals data from 17 browsers, Keychain items, wallet data, shell history, and Git configuration. It hides as a fake Finder.app and keeps itself running through a LaunchAgent, .zshrc changes, and global Git hooks. Defenders should block the listed domains and look for the com.apple.finder.agent LaunchAgent.
North Korean Attackers Hit 30,000 Devices and Steal $10.7m
A joint advisory from agencies in Japan, the US, Australia, and Germany says North Korea’s WaterPlum group, also known as Contagious Interview, infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026. The group stole funds or credentials from over 7,000 crypto wallets and moved at least $10.7 million to North Korea. Posing as recruiters for AI, crypto, and NFT companies, the attackers had developers run malicious npm packages and booby-trapped Visual Studio Code projects during fake coding interviews. These delivered malware including BeaverTail, InvisibleFerret, OtterCookie, and StoatWaffle. The advisory ties WaterPlum to North Korea’s IT worker schemes and notes that Japan dismantled a laptop farm on its soil for the first time. Agencies recommend opening unknown VS Code projects in Restricted Mode and verifying contractors’ identities.