Phishing Scheme Bypasses Microsoft 365 MFA to Redirect Vendor Payments
PremiumPhishing allowed attackers to bypass Microsoft 365 MFA, hijack a finance mailbox, and redirect vendor payments.
§Topic · Identity, Access & Credentials
Credential theft, infostealers, session hijacking, MFA bypass, SSO and Active Directory attacks.
All dispatchesFlashpoint reports infostealers exfiltrated 1.7 billion credentials in the first half of 2026, fueling account takeover risk.
TWINLOOT Python implant uses SharePoint and Teams to host C2, steal credentials, and pivot inside Microsoft tenant environments.
Active exploitation of MLflow SSRF (CVE-2026-64849) leads to cloud credential and secret theft from ML deployments.
New macOS infostealer steals keychain and browser data via ClickFix and supports remote interactive browser control.
Compromised Azure/Entra credentials exfiltrated employee directories from major corporations, data now offered for sale.
Malicious LiteLLM PyPI releases contained credential-stealing code that may have exposed secrets for 2,100+ organizations.
Critical Adobe Commerce vulnerability was targeted and exploited shortly after disclosure, risking customer account takeover.
Malware running in a signed Windows session can quietly use Windows Hello for Business keys to authenticate to Entra ID and persist.
Campaign published nearly 800 malicious npm packages delivering a cross-platform RAT and infostealer for Windows, macOS and Linux.
CSS bomb technique manipulates webmail UI to spy on user activity and capture passwords and tokens without JavaScript.
Greatness PhaaS adds device-code phishing and AiTM capabilities to bypass MFA and capture OAuth tokens for account takeover.
Mini Shai-Hulud/npm campaign compromises popular packages, indicating coordinated supply-chain poisoning activity.
Get these articles delivered to your inbox.
Subscribe free