DAILY BRIEFING
Microsoft to block Entra ID script injection attacks starting October
Today's briefing covers AI coding tools leaking internal screenshots to public GitHub repos and modern browser-based phishing techniques bypassing MFA.
5 stories2 min read

At the same time, adversary-in-the-middle phishing kits like Tycoon2FA, Sneaky2FA, and Evilginx continue to simplify session hijacking directly in the browser, rendering traditional password-only MFA insufficient. Organizations must review automated developer workflows and harden session verification protocols.
Know Your Enemy: Browser-Based Attack Techniques in 2026
Browser-based attacks rely heavily on reverse-proxy AiTM phishing kits like Tycoon2FA, Sneaky2FA, and Evilginx to intercept credentials and live session tokens in real time, successfully bypassing MFA mechanisms across platforms beyond traditional email.
- Why it matters
- Organizations relying solely on traditional MFA are exposed to session hijacking across various messaging channels and browser apps.
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
Researchers at Glow discovered over 13,000 internal images from 300+ organizations exposed in public GitHub repositories. AI coding agents instructed to share screenshots of code changes uploaded them to developers' personal public accounts, leaking internal billing records and unreleased features.
- Why it matters
- Organizations using AI coding assistants risk leaking confidential screenshots, customer billing data, and sensitive internal UI features outside company visibility.
Microsoft to block Entra ID script injection attacks starting October
BleepingComputer page returned a Cloudflare bot protection challenge instead of story content.
TeamViewer urges users to patch severe flaws “as soon as possible”
BleepingComputer page returned a Cloudflare bot protection challenge instead of story content.
Bitget hacked via zero-day in third-party security products
BleepingComputer page returned a Cloudflare bot protection challenge instead of story content.
Key takeaways
- Security firm Glow discovered over 13,000 internal screenshots exposed in public GitHub repos created by AI coding agents.
- Exposed data from impacted organizations included internal billing records and unreleased product features.
- Reverse-proxy AiTM kits like Tycoon2FA and Evilginx intercept live credentials and session tokens directly within the browser.