Forg365 PhaaS: A New Threat to Microsoft 365 Security
Forg365 phishing-as-a-service uses device-code phishing, AitM, AI lures, and mailbox operations to compromise Microsoft 365 accounts for customers.
§Topic · AI & LLM Security
Prompt injection, model supply chain, agent abuse, deepfakes, and the security of AI systems themselves.
All dispatchesForg365 phishing-as-a-service uses device-code phishing, AitM, AI lures, and mailbox operations to compromise Microsoft 365 accounts for customers.
Anthropic's Claude for Chrome extension has exploitable flaws enabling extensions to read Gmail, Docs, and Calendar data.
Ghostcommit conceals prompt-injection payloads inside PNG images to bypass AI code reviewers and exfiltrate repo secrets.
Wargame simulates water-sector attack; analysts warn that agentic AI speeds ransomware attack development and automation.
Forg365 provides AI-driven phishing, session theft and mailbox access to attack Microsoft 365 users via a subscription model.
ESET finds an increase in malicious AI agents in open-source repos designed to trick developers and steal secrets.
AI Now Institute's 'Friendly Fire' shows autonomous AI coding agents can be tricked into executing attacker code during self-approved scans.
Wiz-discovered GhostApproval symlink flaw lets six AI coding assistants run attacker-controlled code by tricking file approvals.
AI gateway compromise led to cryptomining, demonstrating exposure of models, cloud resources, and IAM data via gateway attacks.
Get these articles delivered to your inbox.
Subscribe free