Threat actors compromised captive Wi-Fi gateways at hotels to silently redirect business travelers to fake Microsoft 365 login pages.
A vulnerability in OpenAI's ChatGPT workspace agent system could let attackers deploy malicious agents through a single phishing link.
German and US law enforcement seized 200 servers and arrested the alleged developer of the Kratos phishing platform in Indonesia.
Attackers used 3.7 million spoofed OAuth client IDs to enumerate Entra ID user accounts and map application ecosystems.
The Helix group uses vishing and device code phishing to break into SharePoint, then exfiltrates data for extortion or sale.
A live operator phone phishing campaign exploits Microsoft Entra passkey enrollment to plant persistent account access, bypassing MFA with real…
The FBI and partners seized servers, a Telegram bot, and cryptocurrency wallets, while redirecting thousands of phishing domains to a…
Microsoft tracked 8.3 billion email-based phishing threats in Q1 2026 as CAPTCHA-gated attacks more than doubled in March, hitting 11.9…
Sign in to your account