Related Threat Clusters
-
FBI Warns of Kali365 Phishing Kit Targeting Microsoft 365 Users
The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
135 articles · Updated May 22, 2026 -
UNC6783 Exploits BPOs for Data Extortion via Phishing Campaigns
The Google Threat Intelligence Group (GTIG) reported that a financially motivated cybercriminal group, UNC6783, is targeting business process outsourcing (BPO) companies to infiltrate high-value organizations across…
8 articles · Updated April 8, 2026 -
Critical miniOrange SAML SSO Vulnerabilities Allow WordPress Admin Takeover
Two critical authentication bypass vulnerabilities (CVE-2026-61979 and CVE-2026-15981) have been identified in the miniOrange SAML 2.0 Single Sign-On plugin for WordPress, allowing unauthenticated attackers to forge…
8 articles · Updated August 24, 2026 -
New Pink Extortion Group Targets Microsoft 365 via Voice Phishing
The newly identified Pink extortion group has emerged, utilizing voice phishing (vishing) tactics to gain access to Microsoft 365 accounts. Researchers from Unit 42 have tracked the group under cluster designation…
9 articles · Updated June 4, 2026 -
Global Takedown of Tycoon2FA Phishing Service Disrupts Major Cybercrime Operation
A coordinated international effort led by Microsoft and Europol has dismantled Tycoon2FA, a significant phishing-as-a-service platform responsible for bypassing multi-factor authentication and enabling large-scale…
59 articles · Updated March 5, 2026 -
Malicious LLM Proxy Routers Compromise AI Security
A recent study identified 28 malicious LLM proxy routers that can modify AI service responses and access sensitive credentials. The research tested 28 paid routers and 400 free routers, revealing that nine injected…
2 articles · Updated April 15, 2026 -
EvilTokens Phishing Kit Exploits Microsoft 365 with AI-Driven BEC Tactics
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
44 articles · Updated July 1, 2026 -
Uber Freight Investigates Major Data Breach by Helix Hacking Group
Uber Freight is currently investigating a significant data security incident after the Helix hacking group claimed to have stolen nearly one million files from its systems. The breach was announced on August 6, 2026,…
14 articles · Updated August 12, 2026 -
Scattered Spider Reclassified as Decentralized Cybercrime Collective
Scattered Spider, a cybercrime entity linked to various high-profile attacks since 2022, has been reclassified as a decentralized collective rather than a unified group. Group-IB's analysis indicates that it consists of…
2 articles · Updated July 7, 2026 -
Vishing Campaigns Target Organizations via Microsoft Teams and New Operator Console
A vishing campaign, tracked as STAC4749, targeted North American organizations from February to June 2026, using Microsoft Teams to impersonate IT personnel and gain remote access. Attackers deployed a modular toolset,…
9 articles · Updated July 29, 2026
Recent Intelligence Reports
- Lunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI ... — Cybersecurity-Insiders · August 31, 2026
- Lunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI ... — Markets.Businessinsider · August 31, 2026
- Lunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI ... — Cio · August 31, 2026
- McKesson Breach: ShinyHunters Claims 284m Patient Records — Cybernews · August 29, 2026
- McKesson discloses breach after ShinyHunters claims patient data theft — Bleepingcomputer · August 28, 2026
- McKesson discloses breach after ShinyHunters claims patient data theft — Bleepingcomputer · August 28, 2026
- ReliaQuest Rejects Compromise Claims After ShinyHunters Incident — Infosecurity-Magazine · August 25, 2026
- ShinyHunters claims social engineering attack against ReliaQuest | brief — Scworld · August 24, 2026