TeamSystem Attackers Stole the Data That Makes Fake Invoices Look Real

TeamSystem attackers reportedly stole IBANs and accounting records, giving criminals the context needed to make invoice fraud look routine.
Vulnerabilities, defensive security, architecture and operational security.

TeamSystem attackers reportedly stole IBANs and accounting records, giving criminals the context needed to make invoice fraud look routine.

GiveWP CVE-2026-82222 chains plugin-specific account creation, stored PHP objects and a shipped gadget chain into unauthenticated server command execution. Version 4.16.7.2 fixes it.

More than 130 organisations warn that defenders have only months to prepare, but their voluntary pledge includes no deadlines.

CISA says attackers are exploiting a critical ownCloud WebDAV authentication bypass first disclosed in 2023. A known username and a missing signing key can expose a user's files without authentication.

CISA confirms active exploitation of Linux kernel CVE-2026-53362. A public IPv6 fragmentation exploit can turn local access into root and, under specific conditions, escape an unprivileged container.

Cisco warns that model publishers and country labels can hide inherited weights, training data and upstream dependencies.

Veeam ONE patches close a CVSS 10 unauthenticated RCE, arbitrary file read, SQL injection and a 9.3 flaw that can coerce SMB authentication.

Microsoft labels KB5120998 a non-security preview, but it changes administrator protection, AI process isolation, WMIC availability, post-quantum TLS and enterprise deployment behaviour.
Brave now generates unique forwarding addresses that reduce breach exposure and cross-site correlation through a reused primary email.

ATF says a standalone system breach did not reach its enterprise network or eForms, but the isolated environment contained information about investigation targets.