DeepSeek was deployed by an attacker through the Hermes Agent Framework to autonomously compromise internet-facing systems without requiring further operator involvement.
Attackers can use OAuth client ID spoofing to enumerate Microsoft Entra user accounts and validate credentials without classic sign-in attempts being logged.
Threat actors O-UNC-066 use social engineering and a controlled phishing kit to gain access to Microsoft 365 accounts via Entra Passkey enrollment and subsequently conduct…
Microsoft removed a steganography-based adware network (StegoAd) consisting of 119 extensions that had been active since at least 2021 and concealed malware payloads in images…
Threat actors are abusing ChatGPT share links to host fake OpenAI outage pages that redirect users to download malware disguised as a ChatGPT desktop application,…