A July 2026 disruption did not end the threat around Kratos - it appears to have pushed its methods into fresh Microsoft 365 phishing campaigns.
A malvertising campaign is using Google Ads and a fake Claude Code installer to reach macOS users, showing how cybercrime now leans on trust instead of obvious exploits.
A realistic attack exercise can reveal a company’s weakest point long before criminals do: how people decide when the clock is ticking.
The disruption of Kratos may have removed one criminal service, but the deeper problem is the reusable playbook behind modern Microsoft 365 account-takeover campaigns.
A discount on annual privacy-removal plans draws attention to a bigger question: how much can broker opt-outs really shrink the data trail behind unwanted calls and social engineering?
A reported social-engineering intrusion used fake IT contact, Microsoft Teams, and Quick Assist to reach employee computers before the GoGRPC backdoor was installed, with ransomware ties still unconfirmed.
Italian SMEs and public offices are facing a quieter but harder problem: protecting sensitive communications as smartphones, cloud services, and collaboration apps pull them beyond traditional boundaries.