SharePoint Exploitation, AiTM Phishing, and AsyncAPI Supply Chain Attack

SharePoint Exploitation, AiTM Phishing, and AsyncAPI Supply Chain Attack

•

Episode description

SharePoint Exploitation, AiTM Phishing, and AsyncAPI Supply Chain Attack

On 15 July 2026, Mauven MacLeod examines three active threats facing UK organisations. CISA has added three Microsoft SharePoint Server vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed active exploitation targeting on-premises deployments, with particular exposure among professional services firms still running legacy infrastructure. The second story details a misconfigured phishing operation that exposed 218 confirmed victims across twelve countries using Adversary-in-the-Middle techniques that bypass standard multi-factor authentication, including OAuth Device Code Flow attacks against Microsoft 365 and Google Workspace users. Finally, a supply chain attack against the AsyncAPI generator repository saw an attacker exploit a misconfigured GitHub Actions workflow to publish five malicious npm packages containing the Miasma botnet loader, which executes at import time without user interaction. The briefing emphasises that none of these attacks relied on novel techniques or nation-state resources, but succeeded through known vulnerabilities, unpatched systems, and insufficient authentication controls.

Chapters

  • Introduction Mauven opens the 15 July 2026 briefing, noting three stories involving confirmed victims and active exploitation, all stemming from known weaknesses rather than novel attack methods.
  • SharePoint Server: Three CVEs, Active Exploitation, Patch Now CISA has added three Microsoft SharePoint Server vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed active exploitation. The flaws affect on-premises deployments, not SharePoint Online. UK professional services firms, legal practices, and accountancy firms running legacy on-premises infrastructure face elevated risk. Mauven emphasises that KEV listing represents a late warning, not an early one, and calls for immediate patching and documented remediation.
  • Call to Action Mauven encourages listeners to follow the show and share it with colleagues who would benefit from daily threat intelligence briefings.
  • AiTM Phishing: Three Operators Exposed, 218 Confirmed Victims Lexfo researchers discovered a misconfigured Python HTTP server that exposed the infrastructure of three phishing operators, including one with 218 confirmed victims using OAuth Device Code Flow attacks and another operating an Adversary-in-the-Middle platform since 2018. AiTM attacks bypass standard multi-factor authentication by intercepting authenticated session tokens. Mauven explains why phishing-resistant MFA such as FIDO2 is necessary and provides specific guidance on OAuth Device Code Flow recognition and conditional access policy review.
  • AsyncAPI npm Supply Chain: Poisoned Packages, Botnet Loader An attacker exploited a misconfigured GitHub Actions workflow in the AsyncAPI generator repository to exfiltrate a privileged access token, then published five malicious npm packages containing the Miasma botnet loader. The malicious code executes at import time without user interaction. Mauven advises organisations to audit AsyncAPI-related dependencies, review build logs from 14 July, and verify whether technology partners have assessed their exposure.
  • Also Worth Noting The NCSC has announced that certified Cyber Advisors are offering free thirty-minute consultations for small businesses. Microsoft has halted Patch Tuesday updates for some Dell devices following reports of shutdowns and overheating.
  • Closing Remarks Mauven concludes by noting that all three stories involve exploitation of known weaknesses through patience and known techniques, rather than exotic capabilities. The briefing emphasises checking on-premises SharePoint deployments and treating patching as an urgent priority.

Links