Phishing Campaigns Exploit Passkeys to Compromise Microsoft Cloud Accounts

Microsoft has reported two significant phishing campaigns targeting cloud accounts, utilizing advanced social engineering techniques and passkey-themed tactics.

Microsoft has reported two significant phishing campaigns targeting cloud accounts, utilizing advanced social engineering techniques and passkey-themed tactics.

A security flaw in Brevo's login system allowed phishing emails to target 347,000 Trezor subscribers, raising concerns about data security across multiple crypto platforms.

A recent Microsoft report reveals that attackers are employing ASCII smuggling, typically associated with AI prompt injections, in phishing emails to evade detection.

A recent phishing campaign has deployed invisible Unicode characters to evade email security measures, targeting financial keywords and affecting numerous users.

A series of cybersecurity threats have emerged, highlighting vulnerabilities in various systems and the tactics employed by threat actors.

Recent research highlights a shift in phishing tactics targeting the insurance sector, moving from credential harvesting to real-time account hijacking.

A new phishing kit linked to North Korean threat actors is exploiting Zoom and Microsoft Teams to target cryptocurrency users, utilizing social engineering tactics to deliver malware.

Danish e-commerce platform Miinto has disclosed a data breach affecting customer order information, prompting warnings about potential phishing attacks.

This week’s cybersecurity landscape reveals multiple vulnerabilities affecting various systems, including a significant flaw in Apple's Hide My Email service and a new ransomware phishing campaign targeting small businesses.

The EvilTokens phishing kit has evolved, enabling attackers to bypass multi-factor authentication and gain unauthorized access to Microsoft 365 applications, according to Cisco Talos.