ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 FilesThe Hacker News·Jul 17, 08:56 UTC · Jul 17, 2026Malware130
Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutesHelp Net Security·Jul 16, 00:00 UTC · Jul 16, 2026Malware30
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session TheftThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Data breach45
Extortion crew hijacks Microsoft 365 accounts via fake passkey setupHelp Net Security·Jul 9, 00:00 UTC · Jul 9, 2026Ransomware45
When checking the URL isn't enough: phishing via the Microsoft identity platformKaspersky Securelist·Jul 6, 09:00 UTC · Jul 6, 2026Phishing & fraud30
Threat landscape for SMBs in 2026: fake AI tools, phishing and moreKaspersky Securelist·Jun 25, 10:00 UTC · Jun 25, 2026Phishing & fraud30
European AI adoption hits 99% with regulated data driving most policy violationsHelp Net Security·Jun 19, 11:23 UTC · Jun 19, 2026Malware30
Microsoft 365 users targeted by new phishing threat that bypasses MFAHelp Net Security·May 25, 11:39 UTC · May 25, 2026Phishing & fraud30
FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth TokensInfosecurity Magazine·May 25, 09:30 UTC · May 25, 2026Phishing & fraud30
FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacksThe Record·May 22, 20:04 UTC · May 22, 2026Phishing & fraud30
Cybercriminals turn to AI to bypass modern email security measuresHelp Net Security·Apr 23, 13:36 UTC · Apr 23, 2026Phishing & fraud30
EvilTokens ramps up device code phishing targeting Microsoft 365 usersHelp Net Security·Mar 31, 00:00 UTC · Mar 31, 2026Phishing & fraud130
Operation DoppelBrand Weaponizes Trusted Brands For Credential TheftInfosecurity Magazine·Feb 16, 15:45 UTC · Feb 16, 2026Ransomware45
Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS PlatformsThe Hacker News·Feb 3, 04:12 UTC · Feb 3, 2026Phishing & fraud30
ShinyHunters flip the script on MFA in new data theft attacksHelp Net Security·Feb 2, 00:00 UTC · Feb 2, 2026Ransomware45
Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy FirmsThe Hacker News·Jan 24, 08:04 UTC · Jan 24, 2026Phishing & fraud30
Russia-Linked Hackers Use Microsoft 365 Device Code Phishing for Account TakeoversThe Hacker News·Dec 30, 07:57 UTC · Dec 30, 2025Phishing & fraud130
OAuth Device Code Phishing Campaigns Surge Targets Microsoft 365Infosecurity Magazine·Dec 18, 16:00 UTC · Dec 18, 2025Threat actor45
Group Policy abuse reveals China-aligned espionage group targeting governmentsHelp Net Security·Dec 18, 00:00 UTC · Dec 18, 2025Threat actor45
BIETA: A Technology Enablement Front for China's MSSRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Vulnerability30
China-Aligned UTA0388 Uses AI Tools in Global Phishing CampaignsInfosecurity Magazine·Nov 10, 16:00 UTC · Nov 10, 2025Threat actor45
'Jingle Thief' Hackers Exploit Cloud Infrastructure to Steal Millions in Gift CardsThe Hacker News·Oct 24, 16:01 UTC · Oct 24, 2025Malware30
Attackers target retailers’ gift card systems using cloud-only techniquesHelp Net Security·Oct 22, 00:00 UTC · Oct 22, 2025Vulnerability30
Researchers Warn of Security Gaps in AI BrowsersInfosecurity Magazine·Oct 9, 14:15 UTC · Oct 9, 2025Malware30
Azure AD Credentials Exposed in Public App Settings FileInfosecurity Magazine·Sep 2, 16:00 UTC · Sep 2, 2025Vulnerability30
Phishing Campaign Uses UpCrypter in Fake Voicemail Emails to Deliver RAT PayloadsThe Hacker News·Aug 26, 05:43 UTC · Aug 26, 2025Malware30
Exposing TAG-53’s Credential Harvesting Infrastructure Used for RussiaRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Threat actor45
SonicWall NetExtender Trojan and ConnectWise Exploits Used in Remote Access AttacksThe Hacker News·Jun 26, 07:05 UTC · Jun 26, 2025Malware30
Researchers warn of ongoing Entra ID account takeover campaignHelp Net Security·Jun 12, 00:00 UTC · Jun 12, 2025Threat actor45
New ‘Chihuahua Stealer' Targets Browser Data and Crypto WalletsInfosecurity Magazine·May 14, 12:00 UTC · May 14, 2025Malware30
Hackers Use ClickFix Trick to Deploy PowerShellThe Hacker News·Mar 9, 07:56 UTC · Mar 9, 2025Malware130
GamaCopy Mimics Gamaredon Tactics in Cyber Espionage Targeting Russian EntitiesThe Hacker News·Jan 27, 07:59 UTC · Jan 27, 2025Threat actor45
Tycoon 2FA Phishing Kit Upgraded to Bypass Security MeasuresInfosecurity Magazine·Jan 22, 15:45 UTC · Jan 22, 2025Phishing & fraud30
Phishing-as-a-Service Rockstar 2FA continues to be prevalentSecurity Affairs·Nov 29, 15:36 UTC · Nov 29, 2024Phishing & fraud30
Vietnam’s Infostealer Crackdown Reveals VietCredCare and DuckTailInfosecurity Magazine·Nov 21, 16:30 UTC · Nov 21, 2024Malware30
New PXA Stealer targets government and education sectors for sensitive informationCisco Talos·Nov 14, 11:00 UTC · Nov 14, 2024Malware30
Beware: Fake Google Meet Pages Deliver Infostealers in Ongoing ClickFix CampaignThe Hacker News·Nov 7, 04:20 UTC · Nov 7, 2024Malware30
Grandoreiro banking trojan: overview of recent versions and new tricksKaspersky Securelist·Oct 22, 18:00 UTC · Oct 22, 2024Malware30
Hacker plants false memories in ChatGPT to steal user data in perpetuityArs Technica · Security·Sep 24, 20:56 UTC · Sep 24, 2024Exploit / PoC45