An exposed Python HTTP server instance with directory listing enabled revealed an attacker’s phishing toolkit and enabled the discovery of a total of three Evilginx campaigns targeting Microsoft 365.
Threat actors O-UNC-066 use social engineering and a controlled phishing kit to gain access to Microsoft 365 accounts via Entra Passkey enrollment and subsequently conduct data extortion attacks.
Forg365 democratizes phishing attacks on Microsoft 365 through an AI-powered service model that combines AiTM techniques with automated lure generation.
Ghost phishing techniques hide malicious pages in encryption until they are decoded in the browser, thereby circumventing traditional email security controls.
Three out of four mobile fraud attempts in Germany are social-engineering attacks that exploit psychological pressure situations rather than technical exploits.
Traditional email filters fail against modern attacks that abuse legitimate identities; behavioral AI can provide remedies through anomaly detection and automation.
Large language models regularly hallucinate non-existent web addresses that attackers preemptively register and abuse with phishing pages; Palo Alto Networks Unit 42 documents the “Phantom Squatting” phenomenon for the first time in practice.
Attacks on popular AI brands exploit rapid employee trust in new productivity tools and create a governance blind spot in browser extension management.
Modern attack techniques allow compromise from phishing email to system takeover in approximately five minutes, with multi-factor authentication bypassed through session hijacking.