The disruption of Kratos may have removed one criminal service, but the deeper problem is the reusable playbook behind modern Microsoft 365 account-takeover campaigns.
QR-code phishing is growing fast because it moves the scam out of text filters and into the scan step, where a personal phone may become the attacker’s real launchpad.
A guilty plea tied to a Snapchat phishing case shows how account takeover can turn routine social engineering into intimate privacy loss.
More than 13,000 Chick-fil-A customer accounts were caught in a credential-stuffing campaign, a reminder that the weakest link in many consumer platforms is often the login box itself.
A confirmed incident affecting Chick-fil-A One accounts shows how credential stuffing can turn ordinary password reuse into a serious account-security and payment-risk problem.
Credential-sharing habits make password-based checkout brittle, and the shift to passkeys changes the risk model for Click to Pay without making identity security automatic.
Microsoft has set passkeys to become the default authentication method for Entra ID in September 2026, a change that shifts the security conversation from passwords to enrollment, recovery, and policy design.
A vishing-led campaign is abusing the trust users place in passkey onboarding, showing that phishing resistance can still be undermined at the enrollment step.
As password replay loses value in well-implemented passkey environments, account takeover pressure is migrating toward verification, recovery, and fallback paths that still decide who gets in.
A NordPass discount may be the headline hook, but the deeper story is the shift from reusable passwords to phishing-resistant authentication that can shrink the value of stolen credentials.
Passkeys are pushing authentication away from reusable secrets, while Click to Pay and emerging agent-led commerce are turning payments into a tighter trust problem with new security choke points.
A reported UNC1151 phishing push aimed at Gmail and a Ukrainian email portal shows how credential theft now leans on trusted identity services rather than loud malware.
A small, targeted campaign against AWS users shows how cloned console pages and live interception can make typed MFA codes part of the attack, not the defense.
A phishing operation attributed to Ghostwriter, also tracked as UNC1151, shows how attackers can turn a normal sign-in flow into a credential-grab that reaches beyond the password field.
A reported UNC1151 Ghostwriter campaign puts a familiar weak point back under the microscope: code-based 2FA can still be trapped by a convincing fake login flow.
A Lapsus$-attributed claim tied to github.com is unverified, but it highlights why developer platforms are prized for secrets, access tokens, and account control.
A phishing campaign is using Browser-in-the-Browser styling to target Microsoft 365 credentials, turning ordinary sign-in habits into the attacker’s main entry point.
Active Sessions and Lockdown Mode are being expanded, turning ChatGPT into a tighter-controlled workspace where visibility and restriction matter as much as convenience.
A reported phishing technique puts the spotlight on the recovery layer behind Google Password Manager, where convenience features can become high-value targets.
Tycoon 2FA is a reminder that identity attacks do not need to break passwords if they can relay a live login and harvest the session behind it.