CRITICALAdvisoryAug 04, 2026
Action required
Hunt for suspicious device code authentication attempts and browser update prompts on corporate endpoints that connected to public Wi-Fi in the last 30 days. Block known CornFlake and ChocoShell C2 domains and monitor for lateral movement from compromised M365 accounts.
Affected products
Microsoft
Linked articles