Docusign is a tool tracked across 22 threat clusters and 31 intelligence report mentions on ThreatCluster. First observed November 10, 2025; most recent activity July 4, 2026.
DocuSign is a widely used legitimate e-signature platform that is frequently abused in phishing campaigns. Adversaries impersonate DocuSign notifications or e-signing requests to trick recipients into clicking malicious links or divulging credentials, leveraging the platform's trusted status in business workflows.
The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
A coordinated international effort led by Microsoft and Europol has dismantled Tycoon2FA, a significant phishing-as-a-service platform responsible for bypassing multi-factor authentication and enabling large-scale…
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
In early 2026, a surge in phishing attacks utilizing Amazon Simple Email Service (SES) has been reported, exploiting exposed AWS Identity and Access Management (IAM) access keys. Attackers leverage this trusted email…
Ocean, a cybersecurity startup, has raised $28 million to develop an 'agentic email security platform' aimed at countering the surge in AI-generated phishing attacks. The funding round, led by Lightspeed Venture…
Credential phishing has become a leading cyber threat in the UAE, with over 75% of cyber breaches stemming from phishing emails or fraudulent messages. The UAE Cybersecurity Council reports a significant rise in…
A cybercrime operation named The Quarry has been identified as the source of numerous phishing campaigns targeting American taxpayers. These campaigns impersonate the IRS and SSA, exploiting a Phishing-as-a-Service…
UK small and medium-sized enterprises (SMEs) are increasingly vulnerable to sophisticated AI-driven scams, as highlighted by recent reports. The emergence of 'AI scams 2.0' combines traditional social engineering…
A significant supply chain attack has compromised Salesforce-stored data from more than 200 companies through applications published by Gainsight. Salesforce confirmed unauthorized access to customer data and is…
The cybercriminal group TA584 has intensified its operations by deploying Tsundere Bot malware through ClickFix social engineering tactics. This initial access broker has significantly increased its campaign volume,…