Passkey-themed phishing attacks lead to Microsoft 365 data theft
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks ...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
83 articles found
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks ...
Attackers are using passkey-themed social engineering to trick employees into giving them access to their Microsoft accounts. Microsoft Security Research sai...
Attackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into hand...
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence,...
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specop...
A cryptocurrency-stealing campaign that abuses Google Sheets and the Google Visualization API as a covert command-and-control channel, delivering obfuscated ...
StreamRAT, a newly identified Android banking trojan distributed through fake free-TV streaming advertisements on Meta and TikTok. The campaign, tracked as “...
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain...
Breeze Comet gains initial access through password spraying and social engineering tactics, impersonating IT support to trick victims into installing Remote ...
The ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts. The post...
A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stea...
Google Workspace breaches can begin with social engineering or forgotten third-party integrations rather than sophisticated exploits. This webinar examines r...
OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: The network simultaneously conducted multiple types of ...
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronge...
A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has ...
ReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systems
Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief w...
The attack involved threat actors calling employees and attempting to trick them into accessing a fake ReliaQuest single sign-on (SSO) page hosted on a looka...
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of t...
ReliaQuest has reported a targeted social engineering attack in which threat actors impersonated company security personnel, used a spoofed domain, and succe...