Evilginx is a tool tracked across 9 threat clusters and 13 intelligence report mentions on ThreatCluster. First observed December 2, 2025; most recent activity July 13, 2026.
The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
A coordinated international effort led by Microsoft and Europol has dismantled Tycoon2FA, a significant phishing-as-a-service platform responsible for bypassing multi-factor authentication and enabling large-scale…
A misconfigured server in Budapest has exposed a phishing operation targeting Microsoft 365 users. The server was running a Python HTTP server with directory listing enabled, allowing access to phishing configurations…
A podcast released on February 1, 2026, covers various aspects of cybersecurity, including ethical hacking. The discussion emphasizes the importance of understanding cookie usage and data privacy in the context of…
The PhishU Framework has introduced advanced phishing simulation capabilities through its ClickFix and AiTM proxying features. These tools allow operators to conduct realistic phishing campaigns with a focus on user…
A coordinated phishing campaign using the Evilginx toolkit has targeted at least 18 American universities, exploiting advanced session-hijacking techniques to bypass multi-factor authentication (MFA) and gain…
The Evilginx framework is being exploited in a new wave of phishing attacks targeting student login portals. These attacks enable hackers to bypass multi-factor authentication (MFA) by creating fake single sign-on (SSO)…
As we approach 2026, the cybersecurity landscape is shifting dramatically. Key trends include the evolving role of the CISO as a financial risk broker, the rise of AI in both creating exploits and automating tasks, and…
ThreatHunter.ai has announced a free 90-day trial of its MILBERT.ai authentication monitoring platform, aimed at helping firms combat AiTM and Evilginx attacks that are bypassing multi-factor authentication (MFA)…