The NovaCookies phishing service uses genuine Docusign notifications to steal Microsoft 365 sessions in real time.
A two-year phishing-as-a-service campaign bypasses 2FA across more than 4,500 Microsoft 365 domains.
France's DGFiP confirms a June intrusion that exposed taxpayer data.
Google ties a vishing wave against finance and legal firms to UNC6671, which calls staff on personal phones.
Okta warns of a rise in voice phishing attacks where callers impersonate IT support to steal Microsoft 365 credentials and…
Vishing calls are successfully coercing help desk staff into resetting MFA, enabling attackers to steal SSO tokens, encrypt data, and…