ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More
A ThreatsDay roundup spans Azure AKS privilege escalation, DAEMON Tools supply-chain abuse, Apple PQC code, and an FBI warning on law-firm targeting.
Intelligence analysis by GPT-5.4 Mini

The bulletin strings together several active security threads: a large Middle East C2 footprint, a high-severity Azure Backup AKS privilege-escalation bug, a DAEMON Tools supply-chain incident, Apple’s PQC release, and SRG’s social-engineering campaign against law firms.
This story is like a report card for bad guys and defenders. It says attackers are still using old tricks that work too well, like fake helpers, sneaky software, and weak spots in cloud systems.
One part is about a cloud bug that could let someone with a small job slip into a much bigger one. Another part is about a popular tool being tampered with so it looked safe while carrying something harmful inside.
It also shows the good guys fighting back. Apple shared new lock-and-key math for future-safe security, and the FBI warned law firms about scammers pretending to be IT staff. It is like fixing the locks while also warning people about someone knocking on the door in a fake uniform.
Analysis
What this roundup emphasizes
The bulletin opens with a broad warning that the threat landscape still leans heavily on low-friction tactics: sketchy loaders, fake installers, exposed infrastructure, and recycled social-engineering lures. From there, it highlights several specific stories that matter to defenders.
Infrastructure and cloud abuse
Hunt.io reported more than 1,350 command-and-control servers across 98 Middle East infrastructure providers over a three-month window, with C2 activity making up the vast majority of the observed malicious artifacts. The report says Saudi Arabia’s STC hosted most of the detected C2 servers in the region, and that botnets such as Hajime, Mozi, and Mirai were seen alongside offensive frameworks like Tactical RMM, Cobalt Strike, and Sliver.
Microsoft also quietly fixed a severe Azure Backup for AKS privilege-escalation flaw that, according to researcher Justin O’Leary, let a user with only the Backup Contributor role reach cluster-admin on AKS clusters. The issue reportedly had a CVSS score of 9.9 and no CVE at the time of the report.
Supply chain and endpoint trust
CISA added the DAEMON Tools supply-chain incident to the KEV catalog as CVE-2026-8398. The article says attackers compromised the vendor’s build or distribution path and trojanized three signed binaries, which is exactly the kind of abuse that makes signature-based trust dangerous when the signing pipeline itself is compromised.
Defense and attacker behavior
Apple published post-quantum cryptography implementations in corecrypto, including ML-KEM and ML-DSA, plus verification tools tied to FIPS 203 and 204. The company frames this as careful expansion of a library used on billions of devices.
The FBI warning on Silent Ransom Group says the actors are impersonating IT support to target law firms through calls and phishing. That fits the same pattern running through the bulletin: attackers keep going after trust, identity, and operational shortcuts rather than forcing their way through hardened defenses.
Key points
- Hunt.io said it found more than 1,350 C2 servers across Middle East providers in three months.
- Microsoft reportedly fixed an Azure Backup for AKS flaw that could lead to cluster-admin access.
- CISA added the DAEMON Tools supply-chain incident to its KEV catalog as CVE-2026-8398.
- Apple open-sourced post-quantum cryptography code in corecrypto for expert review.
- The FBI warned that Silent Ransom Group is targeting law firms with IT impersonation and phishing.



