Related Threat Clusters
-
FBI Warns of Kali365 Phishing Kit Targeting Microsoft 365 Users
The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
135 articles · Updated May 22, 2026 -
Global Takedown of Tycoon2FA Phishing Service Disrupts Major Cybercrime Operation
A coordinated international effort led by Microsoft and Europol has dismantled Tycoon2FA, a significant phishing-as-a-service platform responsible for bypassing multi-factor authentication and enabling large-scale…
59 articles · Updated March 5, 2026 -
Identity-Based Attacks Target Authentication Systems and Credentials
Recent identity-based attacks have exploited vulnerabilities in authentication systems, targeting credentials and identity infrastructure. Notable incidents include the compromise of over 18,000 routers by APT28 to…
62 articles · Updated May 29, 2026 -
AI-Powered Phishing Campaigns Render Blocklists Ineffective
AI has significantly enhanced phishing tactics, making traditional blocklists obsolete. Attackers utilize AI to generate phishing pages from screenshots in mere minutes, leading to a rapid turnover of phishing domains.…
2 articles · Updated August 5, 2026 -
Phishing Campaign Exploits Google Services to Evade Detection
A sophisticated phishing campaign has been identified that routes victims through Google services, including Google Meet and Google Ads, before landing on a credential-harvesting page for Microsoft 365. This method…
2 articles · Updated August 7, 2026 -
Session Hijacking Threats Bypass Two-Factor Authentication
Recent reports reveal that session hijacking techniques are compromising accounts even with two-factor authentication (2FA) enabled. Attackers exploit session cookies, which are stored in browsers post-login, to gain…
2 articles · Updated August 10, 2026 -
Misconfigured Server Exposes Evilginx Phishing Operations Targeting Microsoft 365
A misconfigured server in Budapest has exposed a phishing operation targeting Microsoft 365 users. The server was running a Python HTTP server with directory listing enabled, allowing access to phishing configurations…
5 articles · Updated July 13, 2026 -
Podcast Discusses Cybersecurity Trends and Ethical Hacking
A podcast released on February 1, 2026, covers various aspects of cybersecurity, including ethical hacking. The discussion emphasizes the importance of understanding cookie usage and data privacy in the context of…
1179 articles · Updated February 1, 2026 -
PhishU Framework Enhances Phishing Simulations with ClickFix and AiTM Proxying
The PhishU Framework has introduced advanced phishing simulation capabilities through its ClickFix and AiTM proxying features. These tools allow operators to conduct realistic phishing campaigns with a focus on user…
2 articles · Updated March 28, 2026 -
Evilginx Phishing Operation Targets 18 U.S. Universities, Bypasses MFA
A coordinated phishing campaign using the Evilginx toolkit has targeted at least 18 American universities, exploiting advanced session-hijacking techniques to bypass multi-factor authentication (MFA) and gain…
2 articles · Updated December 11, 2025
Recent Intelligence Reports
- Two-Factor Authentication Is No Longer As Safe Thanks To This Cybersecurity Trick — Bgr · August 9, 2026
- Aitm Phishing Mfa Bypass Evilginx — hivesecurity.gitlab.io · August 8, 2026
- How AI — Bleepingcomputer · August 5, 2026
- How AI — Bleepingcomputer · August 5, 2026
- Open Directory Exposes Three Evilginx Phishing Operators — Infosecurity-Magazine · July 13, 2026
- Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 — Thehackernews · July 13, 2026
- Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens — Gbhackers · July 13, 2026
- Netcraft warns — www.netcraft.com · June 25, 2026