Phishing
Curated coverage and analysis in this editorial area.

Russia Exploits Zimbra Zero-Day: Patching Alone Won't Evict the Spies
A zero-click XSS flaw in Zimbra Collaboration Suite let a Russian espionage group harvest emails, 2FA codes, and persistent app passwo…

Misconfigured Server Exposes Three Evilginx Operations Targeting Microsoft 365
A phishing server with directory listing enabled exposed complete M365 phishing toolkits, two distinct MFA bypass techniques, and evid…

Joint Operation Dismantles Kratos: The AiTM Phishing Kit That Bypasses MFA
German, U.S., and Indonesian authorities have taken down over 200 servers powering the Kratos phishing kit. The code survives among ro…

Wind Tre Fined €1.7M: Social Engineering Beats Firewalls
Italy's data protection authority fined Wind Tre €1,715,600 for two breaches caused by phone-based social engineering at retail stores…

Google Sues 'Outsider Enterprise': Gemini Weaponized as PhaaS Engine
Google has filed a civil lawsuit against a China-based cybercrime network that abused Gemini to generate phishing code at scale. The c…

Device Code Phishing: Legitimate Authentication Becomes the Weapon to Breach M365
Device code phishing exploits Microsoft's legitimate OAuth flow to bypass MFA. Low-cost PhaaS kits like DEBULL and ARToken have indust…

LastPass Suffers New Breach via Klue: Vaults Safe, Personal Data Exposed
LastPass disclosed an indirect data breach through vendor Klue. Password vaults remain secure, but personal data including names, emai…

German Police Dismantle Kratos, the Kit That Turned AiTM Phishing Into a Franchise
German, U.S., and Indonesian authorities dismantled the Kratos phishing-as-a-service platform, seizing over 200 servers and arresting…

Microsoft Uncovers OAuth Abuse: Vishing and Supply Chain Attacks Target SaaS
Microsoft has documented ShinyHunters-linked campaigns abusing trusted OAuth relationships in Salesforce through vishing and third-par…

Chinese-Linked Cluster Exploits Roundcube to Spy on Strategic Research in North America
Proofpoint has identified UNK_MassTraction, a suspected Chinese cluster, exploiting two Roundcube N-day vulnerabilities to compromise…

AssuranceAmerica: 7 Million Driver's Licenses Exposed, No Credit Monitoring Offered
A single compromised employee account opened access to nearly 7 million driver's license numbers. AssuranceAmerica is not offering cre…

Verified X Ads Spread Mac Malware and Steal Microsoft 365 Accounts
Active campaigns exploit X's blue verification badge to distribute Mac malware via ClickFix and steal Microsoft 365 OAuth tokens using…