A panel-driven phishing operation is using fake security calls to pressure Microsoft 365 users into registering a new passkey, showing how identity attacks can target the enrollment process instead of the login itself.
A vishing campaign is steering Microsoft 365 users toward counterfeit Microsoft Entra ID login pages, showing how social engineering now targets the identity layer itself.
Proton Pass is discounting its Family plan, and the offer is a reminder that the strongest security tools still depend on how people use them.
A discount may be the headline hook, but the technical story is the shift from malware blocking to detecting phishing, fake websites, and synthetic media before users act.
A callback-phishing lure uses fake account sign-in alerts to pull targets off the inbox and into a live voice scam, where trust is easier to exploit and harder to automate away.
A callback-phishing campaign uses fake sign-in warnings to push recipients away from inbox checks and into attacker-controlled voice channels.
A reported extortion crew called Helix illustrates how voice phishing, device-code abuse, and MFA weak spots can turn identity trust into a path toward SharePoint data.
A freshly described phishing service shows how cloud-account theft is becoming a packaged identity operation, blending relay tactics, OAuth abuse, and AI-assisted lures.