Zero Day Room
Live
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT...
Regulation & compliance

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT, which abuses SharePoint and Teams to steal credentials and move across networks.

The Hacker News19 August 2026
24 stories today6 sections2 topics trackedUpdated through the day

Briefings

Also this week

MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access, and prompt...
News

MCP Servers: A Hidden Gap in Enterprise Security

MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access, and prompt injection, highlighting the need for robust security measures to protect sensitive data.

The Hacker News18 August 2026

Explore topics

Common questions

How often is Zero Day Room updated?

New stories are published through the day as reporting is confirmed. The homepage lists the most recent items first.

Where does Zero Day Room get its information?

Every story carries a named source attribution. Our methodology page sets out which document types we treat as primary and how we handle estimates.

Who writes the articles?

Each story carries a named byline. Author pages collect everything that writer has filed for this site.

How are corrections handled?

Corrections are logged on a dedicated page with a date and a plain description of what changed, rather than edited in silently.