Office 365 is a technology platform tracked across 18 threat clusters and 20 intelligence report mentions on ThreatCluster. First observed October 23, 2025; most recent activity July 23, 2026.
Xu Zewei, a 33-year-old Chinese national, was extradited from Italy to the United States on April 27, 2026, following his arrest in Milan on July 3, 2025. He is accused of participating in cyberattacks directed by the…
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
The Anubis ransomware group launched a cyberattack on the Adriatic Port Authority, crippling operations and causing significant disruptions in maritime logistics. The attack, attributed to Anubis in January 2026,…
In late February 2024, a large-scale phishing campaign known as 'SubdoMailing' was uncovered, exploiting gaps in DMARC safeguards. This tactic allowed attackers to send emails from compromised subdomains, bypassing SPF…
In April 2026, AWS reported that threat actors are exploiting Amazon Cognito refresh tokens to maintain unauthorized access to applications. These tokens, which can be valid for up to 10 years, allow attackers to…
Threat actors are exploiting AWS Organizations by using compromised credentials to remove accounts from organizations. This tactic allows them to bypass Service Control Policies (SCPs) and gain unrestricted access to…
Ernst & Young LLP (EY) has confirmed a data breach involving unauthorized access to a third-party IT service management platform used for tax-related work. The breach, which occurred between March 28 and April 12, 2026,…
ThreatLocker announced an expansion of its zero trust network and cloud access tools aimed at enhancing protection for Managed Service Providers (MSPs) against phishing and network exposure threats. The announcement was…
On May 20, 2026, The Oncology Institute, Inc. was notified of unauthorized access to its systems by Kroll, a third-party vendor. The incident, confirmed in an SEC filing on May 22, 2026, involved patient data…
Harness has launched the AppSec Alliance to address the growing security challenges posed by AI adoption in enterprises. As organizations increasingly utilize AI tools, 62% lack visibility into their usage, and 74%…