A reported phishing-as-a-service kit is said to abuse Microsoft’s device-code flow, showing how cloud identity abuse can outlast a simple password theft.
A Telegram-linked phishing service shows how identity theft now borrows the mechanics of SaaS, combining device-code abuse, token persistence, and AI-written lures.
A panel-driven phishing operation is using fake security calls to pressure Microsoft 365 users into registering a new passkey, showing how identity attacks can target the enrollment process instead of the login itself.
A vishing campaign is steering Microsoft 365 users toward counterfeit Microsoft Entra ID login pages, showing how social engineering now targets the identity layer itself.
Proton Pass is discounting its Family plan, and the offer is a reminder that the strongest security tools still depend on how people use them.
A discount may be the headline hook, but the technical story is the shift from malware blocking to detecting phishing, fake websites, and synthetic media before users act.
A callback-phishing lure uses fake account sign-in alerts to pull targets off the inbox and into a live voice scam, where trust is easier to exploit and harder to automate away.
A callback-phishing campaign uses fake sign-in warnings to push recipients away from inbox checks and into attacker-controlled voice channels.
A reported extortion crew called Helix illustrates how voice phishing, device-code abuse, and MFA weak spots can turn identity trust into a path toward SharePoint data.
A freshly described phishing service shows how cloud-account theft is becoming a packaged identity operation, blending relay tactics, OAuth abuse, and AI-assisted lures.
A reported phishing-as-a-service kit blends AiTM relays, device-code abuse, and AI-written lures, showing how identity attacks are being packaged for reuse.
A reported Microsoft Entra-themed scam shows why attackers are now targeting the moment a user adds a new sign-in method, not just the login page.
A fake support conversation, paired with targeted email pressure, shows how trusted collaboration tools can be used to sell a malicious download without any confirmed exploit in the platform itself.
A vishing-led campaign is abusing the trust users place in passkey onboarding, showing that phishing resistance can still be undermined at the enrollment step.
A ghost-phishing campaign is reportedly hiding malicious pages until they decrypt inside the browser, a trick that can leave traditional email and URL checks staring at an empty frame.
AI is making impersonation calls harder to spot, pushing support teams to treat onboarding and recovery as high-risk security events, not routine admin.
A published discussion on women’s online safety is a reminder that digital risk is not limited to malware: the everyday architecture of the internet can shape who feels safe enough to participate.
A webinar promotion about email security points to a larger problem: inbox controls help, but phishing now lives across identity, authentication, and user trust layers.
A sharp rise in ClickFix detections shows how browser lures, fake errors, and trust-themed prompts are turning ordinary users into the execution path.
A phishing lure impersonating India’s tax authority reportedly used fake government branding and a six-step delivery path to reach in-memory RAT-style payloads.