Threat Analysis : Cyber News for Small Business
Threat Analysis : Cyber News for Small Business 0 followers
Follow
ScreenConnect Exploited, OAuth Device Phishing, and Pixel Zero-Day

ScreenConnect Exploited, OAuth Device Phishing, and Pixel Zero-Day

Sep 16, 2026 • 13min 28s

Episode description

ScreenConnect Exploited, OAuth Device Phishing, and Pixel Zero-Day

CISA has confirmed active exploitation of a critical ConnectWise ScreenConnect vulnerability, the remote access tool used by countless UK IT providers to support small business clients. Attackers are targeting managed service providers to gain indirect access to entire client portfolios. Meanwhile, the GhostCode phishing campaign is bypassing traditional defences by abusing Microsoft’s legitimate OAuth device code flow, landing in inboxes through web contact forms and requiring no fake login pages. Finally, Google has patched a zero-day privilege escalation flaw in Pixel devices that was exploited in targeted attacks. This briefing explains why these threats matter to UK SMBs, what the attack patterns look like in practice, and what concrete actions business owners and IT managers should take today. Mauven MacLeod delivers the technical detail and the operational context that turns threat intelligence into defensible decisions.

Chapters

  • Introduction Mauven introduces two active threats targeting UK small businesses through legitimate infrastructure: a remotely exploited ScreenConnect flaw and an OAuth device phishing technique that bypasses traditional defences.
  • ScreenConnect: CISA Confirms Active Exploitation CISA has added a critical ConnectWise ScreenConnect vulnerability to its Known Exploited Vulnerabilities catalogue. Attackers are targeting IT providers to gain indirect access to their SMB clients. Business owners are advised to verify their MSP has patched the tool and to understand the supply chain risk.
  • Call to Action A reminder to follow the show and share the briefing with colleagues who need the information.
  • GhostCode: OAuth Device Phishing eSentire has documented the GhostCode phishing kit, which abuses Microsoft’s OAuth device code flow to gain persistent access to Microsoft 365 accounts. The campaign impersonates procurement officers, uses web contact forms, and directs victims to legitimate Microsoft URLs, bypassing traditional phishing defences.
  • Pixel Zero-Day Google’s September 2026 patch for Pixel devices includes a fix for a zero-day privilege escalation vulnerability exploited in targeted attacks. Organisations using Pixel devices should install the update immediately.
  • Closing Remarks Mauven summarises the three practical actions listeners should take: verify ScreenConnect patch status with IT providers, brief staff on OAuth device code phishing indicators, and review OAuth app consents in Microsoft Entra admin centre.

Links

  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://www.esentire.com/
  • https://otx.alienvault.com/
  • https://www.ncsc.gov.uk/
  • https://support.google.com/pixelphone/answer/4457705
Comments0 Activity1 Chapters0 Transcript–
Threat Analysis : Cyber News for Small Business
Threat Analysis : Cyber News for Small Business @ThreatAnalysis Sep 16, 2026
13:28 ScreenConnect Exploited, OAuth Device Phishing, and Pixel Zero-Day
Sep 16, 2026
ScreenConnect Exploited, OAuth Device Phishing, and Pixel Zero-Day
0 0 0
RSS Podcast feed
HomeLinksCreditsMap

Powered by Castopod

Persons