Misconfigured Server Exposes Three Evilginx Phishing Operations Targeting Microsoft 365
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing…
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing…
Evilginx is an open-source adversary-in-the-middle (AiTM) phishing framework used to bypass multi-factor authentication by proxying live login sessions. It has been forked…
A sophisticated threat actor tracked as O-UNC-066 by Okta is targeting organizations across multiple sectors with a voice-based phishing (vishing) scheme that…
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
Cybersecurity researchers at Huntress have uncovered a massive, ongoing automated password spray attack targeting Microsoft's Azure command-line interface (CLI). The campaign, active…