Microsoft Discloses AI-Assisted Invoice Fraud and Passkey Phishing Campaigns
Microsoft has disclosed details of two active campaigns targeting enterprise cloud environments through AI-assisted executive impersonation and passkey-themed social engineering. The attacks leverage third-party email delivery infrastructure to bypass…
Mirage2FA Phishing Campaign Compromises 4,500 Microsoft 365 Accounts
August 25, 2026 The Mirage2FA phishing campaign has compromised an estimated 4,500 organizations across the United States and European Union by abusing legitimate Microsoft 365 login flows and bypassing traditional two-factor authentication.…
SafePal Data Breach Crypto Wallet Customers Exposed
August 17, 2026 Cryptocurrency hardware wallet provider SafePal disclosed a data breach that exposed customer order information for approximately 39,798 users. The incident involves an authorization flaw in the company’s order-tracking system, and…
Zimbra CVE: Russian Spies Exploit Zero-Click XSS
July 23, 2026 A Russian state-sponsored advanced persistent threat group known as Laundry Bear (also called Void Blizzard) has been silently reading Western mailboxes by exploiting a stored cross-site scripting vulnerability in Zimbra Collaboration…
FBI Dismantles Outsider Enterprise AI Phishing Ring: $1.9B in Losses
June 14, 2026 The FBI, working alongside Google and Black Lotus Labs, has dismantled a massive China-based phishing-as-a-service operation called Outsider Enterprise. This AI-powered cybercrime ring operated thousands of fake websites and sent millions…