DAILY BRIEFING
White House taps security firms for offensive hack-back operations
Today's briefing examines active SharePoint authentication bypass exploits, new U.S. hack-back directives, Salesforce and ServiceNow data theft, WhatsApp scam alerts, and Android NFC malware.
5 stories2 min read

Critical infrastructure and enterprise systems face immediate operational pressure today following the public release of exploit code targeting enterprise platforms. Attackers are moving rapidly from proof-of-concept publications to active exploitation, leaving zero margin for delayed patching cycles.
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors are actively exploiting a critical Microsoft SharePoint authentication bypass vulnerability (CVE-2026-55040, CVSS 9.1) following the public release of a proof-of-concept exploit by Rapid7.
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals.
- Why it matters
- Organizations relying on exposed public portals risk unauthorized access and data harvesting due to overly permissive access controls.
Android malware combo takes out loans and relays victims' credit cards
A novel Android NFC relay malware named WindRelay is deployed alongside the SpyNote remote access trojan to capture and transmit live credit card data to attackers in real time while unauthorized loans are taken out.
White House taps security firms for offensive hack-back operations
A new White House memorandum signed by U.S. President Donald Trump directs the National Coordination Center (NCC) to establish a program enabling approved private security firms to perform offensive hack-back operations against foreign cybercrime organizations.
- Why it matters
- This policy shift introduces legal pathways for private entities to engage in active defense and offensive cyber operations targeting external threat groups.
WhatsApp rolls out new feature that flags potential scam messages
WhatsApp has initiated the rollout of an optional local machine learning feature called Scam Alert, designed to detect and warn users of potential scam attempts directly on their devices.
Key takeaways
- Apply July 2026 updates immediately to address active exploitation of the Microsoft SharePoint authentication bypass flaw CVE-2026-55040.
- Review White House directives establishing NCC approval frameworks for private offensive hack-back operations against cybercrime groups.