Microsoft Discloses AI-Assisted Invoice Fraud and Passkey Phishing Campaigns
Microsoft has disclosed details of two active campaigns targeting enterprise cloud environments through AI-assisted executive impersonation and passkey-themed social engineering. The attacks leverage third-party email delivery infrastructure to bypass…
Mirage2FA Phishing Campaign Compromises 4,500 Microsoft 365 Accounts
August 25, 2026 The Mirage2FA phishing campaign has compromised an estimated 4,500 organizations across the United States and European Union by abusing legitimate Microsoft 365 login flows and bypassing traditional two-factor authentication.…
SafePal Data Breach Crypto Wallet Customers Exposed
August 17, 2026 Cryptocurrency hardware wallet provider SafePal disclosed a data breach that exposed customer order information for approximately 39,798 users. The incident involves an authorization flaw in the company’s order-tracking system, and…
Zimbra CVE: Russian Spies Exploit Zero-Click XSS
July 23, 2026 A Russian state-sponsored advanced persistent threat group known as Laundry Bear (also called Void Blizzard) has been silently reading Western mailboxes by exploiting a stored cross-site scripting vulnerability in Zimbra Collaboration…