Microsoft disclosed campaigns where attackers exploited third-party email systems for large-scale financial scam phishing and used passkey-themed social engineering techniques to compromise cloud accounts.
The BigBear 2.0 phishing-as-a-service framework bypassed multi-factor authentication at 258 organizations, compromising over 5,000 Microsoft 365 credentials.
Threat actors use invisible Unicode characters in phishing emails to evade detection by security filters, complicating phishing identification.
Attackers are leveraging invisible Unicode characters originally used to evade AI detection as a new method to obfuscate phishing emails and bypass security filters.
A Russian national has been indicted in the US for a phishing campaign that infected 80,000 freelancers with TVRAT and DarkVNC malware, representing significant cybercrime against remote workers.
A surge of Guildma (Astaroth) malware infections is spreading through Brazilian Portuguese phishing emails, posing risks through data theft and stealthy behavior.
SynkLoader malware is delivered through a Microsoft Teams phishing campaign that uses a fake lock screen to steal enterprise user credentials, enabling unauthorized access.
North Korea’s APT group Kimsuky has implemented an offline AI infrastructure that advances their phishing tactics and automates malware development by integrating AI with internal document search and malware creation tools.
A widespread phishing campaign uses adversary-in-the-middle techniques to compromise Microsoft 365 accounts and target payroll and finance emails.
The Greatness phishing-as-a-service toolkit now uses device code phishing to exploit OAuth 2.0 Device Authorization Grant, bypassing MFA and hijacking accounts.
Talos analyzed prompt logs from various AI applications used by threat actors to understand their evolving tactics, revealing increased sophistication in leveraging cloud-based AI for malicious activities.
North Korean group BlueNoroff uses a phishing kit impersonating Zoom and Microsoft Teams to profile cryptocurrency wallets and deliver malware via social engineering.
CISA warns that Russian state-sponsored group Laundry Bear is exploiting a patched Zimbra zero-click vulnerability combined with phishing to steal emails from enterprise Zimbra Collaboration servers.
Forg365 is a new phishing-as-a-service platform using AI to generate lures and advanced AiTM and device code methods to steal Microsoft 365 credentials. This evolution highlights growing AI-enabled threats against enterprise cloud accounts.
A threat actor known as O-UNC-066 is using a phishing kit to exploit Microsoft 365 users via fake Entra passkey enrollment requests, aiming at data extortion. This tactic spans multiple industry sectors and involves voice-based social engineering.
A new EvilTokens campaign uses ghost phishing to bypass traditional email security by hiding malicious pages until decrypted inside a victim’s browser. This poses high risk to businesses using Microsoft 365 and handling sensitive data.