We've got one word for it, and it's usually the wrong one
Reported exploitedMicrosoft DefenderUAT-10820WebDAVOur summary
Cisco Talos has identified an active infection chain abusing WebDAV protocols, attributed to the Russian threat actor UAT-10820, which successfully compromised a Ukrainian government entity. The campaign deploys the Amatera information stealer along with secondary payloads, including ZigCryptoStealer and the NetSupport Manager remote access tool, to establish persistent control and exfiltrate credentials. Simultaneously, the security landscape has tightened with the release of a "ShieldCrash" zero-day exploit that grants SYSTEM-level access to Microsoft Defender, appearing shortly after the September 2026 Patch Tuesday updates were distributed.
Cisco Talos publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.