Heroes, another exciting day. Keep watching out for social-engineering and adjacent attacks.
Remember, these phishing attacks are basically looking to fool "a smart person in a hurry". Just put an official looking, urgent, call to action in an email...and you might just overload the prefrontal cortex for long enough for the victim to approve an action--even when they know better. It's hacking the flight-or-flight response which attackers know is built into the HumanOS.
Here's a detailed look at the current cybersecurity landscape for September 9, 2025.
Critical Threats
High Severity
Executive Briefing
A new international guidance document is encouraging the widespread adoption of Software Bills of Materials (SBOMs) to bolster software supply chain security. For executives and security leaders, this represents a strategic shift towards greater transparency and proactive vulnerability management. Implementing SBOM practices can significantly reduce risk from incidents like the recent npm package compromise by providing clear visibility into software components and their associated vulnerabilities.
Vendor Spotlight
Spotlight Rationale: Microsoft is selected due to a high-severity threat directly targeting its Microsoft 365 ecosystem. A new phishing campaign is abusing Microsoft's own 'Direct Send' feature, combined with the Axios HTTP client, to bypass traditional email security and compromise user accounts.
Threat Context: Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks
Platform Focus: Microsoft 365 & Microsoft Defender for Office 365
The abuse of legitimate tools like Axios and native platform features like Direct Send makes detection challenging for standard email gateways. This technique allows attackers to craft highly convincing phishing emails that appear to originate from a trusted source, increasing their success rate in stealing credentials and bypassing MFA. Organizations must enhance their M365 security posture with specific detection logic and configuration hardening to counter this evolving threat.
Actionable Platform Guidance: Based on available intelligence, specific configuration adjustments and monitoring are recommended to mitigate this threat vector.
Source: The Hacker News