A reported phishing-as-a-service kit is said to abuse Microsoft’s device-code flow, showing how cloud identity abuse can outlast a simple password theft.
A Telegram-linked phishing service shows how identity theft now borrows the mechanics of SaaS, combining device-code abuse, token persistence, and AI-written lures.
A panel-driven phishing operation is using fake security calls to pressure Microsoft 365 users into registering a new passkey, showing how identity attacks can target the enrollment process instead of the login itself.
A vishing campaign is steering Microsoft 365 users toward counterfeit Microsoft Entra ID login pages, showing how social engineering now targets the identity layer itself.
A freshly described phishing service shows how cloud-account theft is becoming a packaged identity operation, blending relay tactics, OAuth abuse, and AI-assisted lures.
A reported phishing-as-a-service kit blends AiTM relays, device-code abuse, and AI-written lures, showing how identity attacks are being packaged for reuse.
A vishing-led campaign is abusing the trust users place in passkey onboarding, showing that phishing resistance can still be undermined at the enrollment step.
A recently reported extortion operation shows how voice phishing, device-code login abuse, and rushed MFA enrollment can turn Microsoft 365 identity controls into a pathway for data theft.
A ghost-phishing campaign is reportedly hiding malicious pages until they decrypt inside the browser, a trick that can leave traditional email and URL checks staring at an empty frame.
A late-June phishing run against Microsoft 365 shows how attackers are industrializing a legitimate sign-in method, turning trusted authentication into a reusable identity-abuse chain.
A phishing kit called EvilTokens shows how attackers can abuse a legitimate OAuth path to collect valid Microsoft 365 tokens without stealing a password.
Two separate techniques show how attackers are leaning on user trust - one through a promoted macOS lure, the other through browser-based Microsoft 365 token abuse.
A Microsoft 365 phishing panel linked to the EvilTokens ecosystem shows how criminal operators are turning login abuse, token handling, and persistence into a reusable service.
ConsentFix and ClickFix show how a fake prompt and an OAuth flow can turn Microsoft 365 identity controls into a fast-moving token theft problem.
A phishing kit tied to Microsoft 365 targeting shows how attackers can lean on legitimate cloud login flows, trusted collaboration branding, and edge-hosted delivery to turn identity into the attack surface.
A React-based phishing-as-a-service panel reportedly built for Microsoft 365 abuse points to a quieter threat: industrialized token handling, not just stolen passwords.
A two-week burst of automated sign-in attempts shows how password spraying can strain cloud defenses even when the full extent of account impact is still unclear.
A massive credential campaign against Microsoft 365 shows how distributed password spraying can turn identity controls into the real front line of cloud defense.
A two-week wave of password spraying against Microsoft 365 shows how weak credentials and permissive sign-in controls can turn identity into the softest layer of cloud security.
A phishing-as-a-service kit tied to OAuth 2.0 shows why modern account attacks can succeed without ever stealing a password.