Phishing
Curated coverage and analysis in this editorial area.

APT29 Hits Hotel Wi-Fi: Steals M365 Credentials with Malware
Microsoft attributes the CaptiveCrunch campaign to Storm-2945, a Midnight Blizzard sub-group, which compromises hotel captive portals…

Valve: Steam Hardware Shipping Data Exposed in CEVA Logistics Attack
Valve notified European Steam hardware customers on August 7, 2026 that their shipping data was compromised in a cyberattack on logist…

The Microsoft 365 Account Takeover That Leaves No Trace
Proofpoint tracks active campaigns since September 2025 that abuse Microsoft's OAuth 2.0 device authorization grant flow. MFA is bypas…

Pirated 'The Odyssey' Downloads Hide Lumma Stealer: Windows Users Tricked by Fake Video Files
Cybercriminals are recycling a proven attack pattern to distribute Lumma Stealer through fake pirated copies of Christopher Nolan's Th…

CaptiveCrunch: Midnight Blizzard Turns Hotel Wi-Fi into an APT Delivery Vector
Microsoft Threat Intelligence has exposed CaptiveCrunch, a Storm-2945 campaign that weaponizes hotel captive portals to deliver the Co…

Kodak Confirms 'Limited' Breach, but ShinyHunters Claims 2.2 Million Records
Kodak acknowledged unauthorized access to a 'limited amount' of corporate data on June 18, 2026, but did not verify the 2.2 million re…

Greatness PhaaS Bypasses M365 MFA by Abusing Whitelists
The Greatness Phishing-as-a-Service platform has evolved beyond credential theft to advanced adversary-in-the-middle and device-code p…

Authorities Dismantle Kratos Phishing Kit, but the Code Lives On With 1,800 Customers
German and U.S. law enforcement seized over 200 servers and took down the Kratos phishing-as-a-service platform on July 21, 2026, whil…

PNLD Data Breach: UK Police Contacts Published on Dark Web July 26
The Police National Legal Database confirms the exfiltration of names, organizations, and work emails of officers, government staff, a…

TokenLover and YaksaLover: The PhaaS Kits That Measure Persistence With a 'Password Change Survival Rate'
Italy's ACN details two Phishing-as-a-Service toolkits that abuse the Device Code Flow and NGC keys to achieve persistence that surviv…

Midnight Blizzard Turns Hotel Wi-Fi Into a Trap for Corporate Travelers
Storm-2945, a Midnight Blizzard sub-cluster, compromises captive portal networks worldwide to deliver the CornFlake RAT and steal Micr…

Hotel DNS Attacks: Corporate VPNs Aren't Enough to Protect Microsoft 365
ReliaQuest has documented an active campaign since June 2026 that compromises hotel Wi-Fi gateways to redirect Microsoft 365 logins to…