The NovaCookies phishing service uses genuine Docusign notifications to steal Microsoft 365 sessions in real time.
A two-year phishing-as-a-service campaign bypasses 2FA across more than 4,500 Microsoft 365 domains.
A PhaaS platform called Outsider used Google's Gemini AI to generate phishing page code, resulting in millions of stolen credit…