BigBear 2.0 Phishing: What to Do After Microsoft 365 MFA
BigBear 2.0 phishing can steal Microsoft 365 sessions after MFA. What to…
Dropbox Lenovo ID Breach: Check Account and File Access
Dropbox says about 5,000 accounts were accessed through Lenovo ID. Check your…
iAuthFlow v2 Adds a Rogue Google Passkey That Survives Reset
iAuthFlow v2 can add an attacker-controlled Google passkey after a relayed phishing…
.vu Phishing Surge Uses 1,660 Domains to Steal Accounts
A .vu phishing operation used 1,660 short-lived domains and AiTM login relays.…
CaptiveCrunch Hotel Wi-Fi: Fake Logins and Malware Updates
Hotel Wi-Fi can deliver fake Microsoft logins or malware updates. Check what…
Fake Microsoft 365 Passkey Setup: How the O-UNC-066 Vishing Attack Works
Okta says O-UNC-066/Pink is using phone calls and fake Entra passkey enrollment…
SonicWall CVE-2024-12802: MFA Bypass Still Exposes SSL-VPNs
SonicWall CVE-2024-12802 can leave SSL-VPN MFA bypassable when firmware is patched but…
Device Code Phishing: Microsoft Login Trap and Token Theft
Device code phishing uses a real Microsoft login page to authorize an…
Microsoft AiTM Phishing Targeted 35,000 Users
Microsoft says a code-of-conduct phishing campaign targeted 35,000 users with PDF lures,…
Crypto Recovery Scams: Can Stolen Crypto Be Recovered?
Learn how crypto recovery scams work, which recovery claims are fake, what…
Malware Protection: Benefits and Cleanup Steps
Malware protection can block risky files, detect hidden threats, clean leftovers, and…
W3LL Targets Microsoft 365 Accounts with Sophisticated Phishing Kit
In the ever-evolving landscape of cyber threats, crooks continually find new and…
