Threat Brief — 2026-09-24 — Placeholder Domains and Missing CVEs
Executive summary. Two items warrant attention today. The placeholder domain third-party.com, ubiquitous in developer documentation and code samples, is actively serving a ClickFix-style social-engineering page that tricks Windows users into running PowerShell payloads — a practical risk for anyone who copy-pastes example code or clicks through verification prompts on unfamiliar domains. Separately, Microsoft has published an informational acknowledgement that CVE-2026-70125, an Outlook remote code execution vulnerability, was fixed in September 2026 updates but accidentally left out of the original release notes.
Top items
third-party.complaceholder domain weaponised for ClickFix attacks. The domain commonly used as a stand-in in developer documentation and sample code is now hosting a fake Cloudflare verification page that prompts Windows users to execute PowerShell commands. Becausethird-party.comappears in countless tutorials, Stack Overflow answers, and internal codebases, users may trust or encounter the domain in legitimate-looking contexts, making the social-engineering lure more credible than a random domain. No specific threat actor is named in the reporting. (src: BleepingComputer)
- Microsoft acknowledges Outlook RCE CVE-2026-70125 was omitted from September release notes. This is a developing story: Microsoft first published September 2026 CVE acknowledgement updates on 2026-09-22 (MSRC). The new development is the addition of CVE-2026-70125, an Outlook remote code execution vulnerability. Microsoft states the vulnerability was already addressed by updates released in September 2026 and that the CVE was inadvertently omitted from the original security update documentation — this is an informational change only. No public exploit or known in-the-wild exploitation is indicated in the finding. (src: MSRC)
Themes
Supply-chain trust surfaces. Both items exploit trusted intermediaries: a documentation placeholder domain that developers treat as benign, and a vendor disclosure process that briefly dropped a CVE from its release notes. In each case the attack surface is not a new technical flaw but a breakdown in the trust chain between documentation, disclosure, and end-user behaviour.
===
