[SIGNALS WEEKLY] Exploited Edge, Social Engineering, and Subtle Evasion
A Teams message from “IT” can now be the first step in a domain takeover: remote-support session, silent install, then AD and WinRM movement.
TL;DR
- [Vulnerabilities] Newly added KEV flaws in internet-facing and control-plane services increase near-term risk of rapid initial access, ransomware, and potential supply-chain abuse.
- [Intrusion Tradecraft] Adversaries are reliably turning Teams-based “IT support” social engineering and remote support tools into domain-wide compromise via AD and WinRM.
- [Phishing / OT] Unicode-based “ASCII smuggling” is eroding content filters while US focus on IRGC-CEC highlights persistent risk of exposed OT/PLC infrastructure.
Current Stories
TL;DR
- [Vulnerabilities] CISA expanded KEV with in-the-wild exploited flaws impacting internet-facing edge and widely used services—raising risk of rapid initial access → ransomware/extortion, and (for dev tooling) supply-chain abuse via stolen artifacts/tokens.
- [Intrusion Tradecraft] Microsoft reported a repeatable playbook: Teams “helpdesk” impersonation → remote support session → malware install → AD/WinRM lateral movement, consistent with hands-on intrusions that end in domain takeover and disruptive outcomes.
- [Geopolitics / OT] New this week: Rewards for Justice published a reward notice for IRGC-CEC official Amir Yaryab. Why it matters operationally: it reinforces US focus on IRGC-CEC-linked activity associated with critical infrastructure targeting and potential OT disruption when exposed control systems are reachable.
References
- (2026-09-02) CISA Adds Seven Known Exploited Vulnerabilities to Catalog
- (2026-09-04) CISA Adds One Known Exploited Vulnerability to Catalog
- (2026-09-02) Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
- (2026-09-03) Amir Yaryab (Rewards For Justice)
- (2026-07-22) Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (AA26-097A)
Emerging Stories
TL;DR
- [Supply Chain / RMM] N-able released an emergency N-central hotfix for a critical issue that could enable server-side RCE; if weaponized, this becomes a management-plane compromise with broad downstream access.
- [Phishing / Evasion] Microsoft observed “ASCII smuggling” (invisible Unicode) being used at scale to bypass content filters, increasing the chance of credential theft and fraud even when keywords look “clean.”
References
- (2026-09-05) 2026.3 HF4 Release Notes
- (2026-09-03) ASCII smuggling crosses over from AI prompt injection to phishing evasion
Forecasts, Detection Opportunities and References...
Forecasts
TL;DR
- Short-term: KEV-driven exploitation will keep rewarding attackers who move fastest on exposed edge and common services, accelerating initial access → ransomware/extortion.
- Long-term: Social-engineering-led access (collaboration + remote support) will remain a high-ROI path to domain compromise.
- Overlooked: Unicode/normalization evasion will steadily erode pure content-based controls, raising pressure for behavioral and identity-centric detections.