Open-Source Phishing Kits Exploit Microsoft 365 Authentication
PremiumOpen-source AiTM phishing kits proxy live Microsoft 365 auth sessions, capturing tokens and bypassing MFA protections.
§Topic · Identity, Access & Credentials
Credential theft, infostealers, session hijacking, MFA bypass, SSO and Active Directory attacks.
All dispatchesOpen-source AiTM phishing kits proxy live Microsoft 365 auth sessions, capturing tokens and bypassing MFA protections.
Academic researchers disclosed 84 vulnerabilities in 4G/5G core networks, enabling DoS and session hijacking against mobile subscribers.
Wiz documents CaptiveCrunch AiTM campaign by Storm-2945/Midnight Blizzard targeting hospitality captive portals to harvest credentials.
Numerous internet-exposed remote hardware management controllers are vulnerable to offline password cracking and takeover attempts.
Microsoft patched a high-severity Certighost AD Certificate Services flaw that enables privilege escalation and domain compromise.
Researchers found 24,650 internet-exposed BMC/IPMI interfaces disclosing password-derived hashes before login, enabling offline cracking.
Insurance-targeted phishing now triggers immediate real-time account hijacking rather than delayed credential theft for timely money transfer fraud.
Russian state-linked actors exploited a Zimbra zero-day to steal emails and bypass MFA, prompting urgent patching and mitigations.
Directory listing on misconfigured server exposed three Evilginx phishing operations that bypass MFA to target Microsoft 365 users.
Novel OAuth client ID spoofing enables attackers to validate stolen Microsoft Entra credentials and enumerate accounts while evading telemetry.
Jalisco and OmegaLord phishing kits target Microsoft 365, using MFA-evasion techniques to steal credentials and session tokens.
Rise in deceptive QR-code scams leading to credential theft, fraudulent payments and account takeover attempts.
Malicious jscrambler npm v8.14.0 runs a preinstall hook that drops a cross-platform Rust infostealer during package install.
Critical Dell BIOS weakness (CVE-2026-40639) allows instant admin-password recovery from SPI flash, risking device takeover and firmware abuse.
Get these articles delivered to your inbox.
Subscribe free