Related Threat Clusters
-
HOLLOWGRAPH Malware Exploits Microsoft 365 Calendars for Espionage
Group-IB has identified HOLLOWGRAPH, a sophisticated Windows malware that abuses the Microsoft Graph API to covertly exfiltrate files and receive commands through compromised Microsoft 365 calendar events. The malware…
10 articles · Updated July 20, 2026 -
FBI Warns of Kali365 Phishing Kit Targeting Microsoft 365 Users
The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
135 articles · Updated May 22, 2026 -
EvilTokens Phishing Kit Exploits Microsoft 365 with AI-Driven BEC Tactics
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
44 articles · Updated July 1, 2026 -
BigBear 2.0 Phishing Campaign Targets Microsoft 365 Users
The BigBear 2.0 phishing-as-a-service campaign has compromised over 5,137 Microsoft 365 credentials from 258 organizations, utilizing an Evilginx2-based framework to bypass multi-factor authentication (MFA). Discovered…
4 articles · Updated September 7, 2026 -
OAuth Client ID Spoofing Threatens Microsoft Entra Security
Cybercriminals are increasingly using OAuth client ID spoofing to conduct account enumeration against Microsoft Entra, the identity management service. This method allows attackers to infer username and password…
12 articles · Updated July 13, 2026 -
Critical CVE-2026-69836 in Microsoft Entra ID Exploited in the Wild
Microsoft disclosed a critical remote code execution vulnerability in Entra ID, tracked as CVE-2026-69836, which has been actively exploited in the wild. This flaw, stemming from unsafe deserialization of untrusted…
44 articles · Updated August 21, 2026 -
Identity-Based Attacks Target Authentication Systems and Credentials
Recent identity-based attacks have exploited vulnerabilities in authentication systems, targeting credentials and identity infrastructure. Notable incidents include the compromise of over 18,000 routers by APT28 to…
62 articles · Updated May 29, 2026 -
CISA Contractor Exposes Sensitive AWS Credentials on Public GitHub
A contractor for the U.S. Cybersecurity and Infrastructure Security Agency (CISA) left a public GitHub repository named 'Private-CISA' exposed for six months, containing sensitive credentials including AWS GovCloud…
41 articles · Updated May 19, 2026 -
Knight Office Phishing Kit Targets Microsoft 365 Accounts via Session Hijacking
A new phishing kit named 'Knight Office' has been identified, targeting Microsoft 365 accounts by stealing active login sessions instead of passwords. Discovered by Huntress during an investigation of suspicious sign-in…
2 articles · Updated September 2, 2026 -
Credential Theft via Misconfigured Spring Boot Actuator Leads to SharePoint Data Exfiltration
In a recent cybersecurity incident, attackers exploited an exposed Spring Boot Actuator endpoint to harvest credentials from leaked configuration data. They utilized the OAuth2 Resource Owner Password Credentials (ROPC)…
3 articles · Updated March 18, 2026
Recent Intelligence Reports
- BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials — Infosecurity-Magazine · September 8, 2026
- Tracking BigBear 2.0 Evilginx2 Phishing Campaign — Cloudsek · September 7, 2026
- Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks — Thehackernews · September 7, 2026
- Your Cloud Security Checklist Doesn't Work the Way You Think It Does — Thehackernews · September 7, 2026
- In Other News: Microsoft's Cloud Patches, Hacked Dropbox Accounts, Guardio's $1.1B Valuation — Securityweek · September 4, 2026
- In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation — Securityweek · September 4, 2026
- 005 — attack.mitre.org · September 2, 2026
- Idira Secure Infrastructure Access (SIA) — docs.cyberark.com · August 31, 2026