Microsoft 365 Phishing Platform Forg365
A new phishing-as-a-service operation called Forg365 uses AI to target Microsoft 365 accounts, combining adversary-in-the-middle and device code methods with AI-assisted lure generation.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
A new phishing-as-a-service operation called Forg365 uses AI to target Microsoft 365 accounts, combining adversary-in-the-middle and device code methods with AI-assisted lure generation.
A contributor to OpenMandriva Linux attempted to sabotage the project by wiping GitHub repositories and pushing an empty package that could have damaged users' systems.
Google's Chrome 150 update patches 27 vulnerabilities, including two critical-severity flaws, with most discovered by Google, resulting in lower bug bounty rewards.
The National Security Agency has rebranded its elite hacking division as Tailored Access Operations, a name that recalls the agency's history of offensive cyber operations, in a move to improve its response to evolving digital threats.
A cybersecurity startup offering millions for zero-day exploits is run by convicted felons with a history of fake intelligence companies and fraud.
Cyberattacks increase by 40% during summer months due to reduced IT staffing, making it essential for organizations to implement automation and monitoring to maintain strong protection.
A threat actor is targeting Microsoft 365 users with voice-based fake security requests to enroll a new Entra passkey, with the goal of stealing credentials and multi-factor authentication codes.
The European Commission has unveiled a cyber plan to reduce reliance on foreign AI systems, aiming to make frontier AI safe and accessible for European cybersecurity.
The newly established AI cybersecurity clearinghouse must address the gap between fast vulnerability discovery and slow patching to be effective.