Microsoft has identified a cyberthreat campaign called "CaptiveCrunch" targeting travelers through compromised hotel WiFi networks, potentially linked to Russian actors…
Read More »device code phishing
A new threat group called Helix uses voice phishing, device code phishing, and MFA abuse to compromise SharePoint environments for…
Read More »The financial sector warns that generative AI has made deepfake identity attacks cheap and routine, urging stronger policy countermeasures. Major…
Read More »A massive 37.5x surge in device code phishing attacks has occurred this year, exploiting a legitimate OAuth feature designed for…
Read More »A new phishing-as-a-service toolkit called EvilTokens is enabling a surge in sophisticated device code phishing attacks against Microsoft 365 accounts,…
Read More »A new wave of attacks combines device code phishing with voice phishing (vishing) to compromise Microsoft Entra accounts, exploiting the…
Read More »




