threat-intel When “Hi, This Is IT” Comes Through Microsoft Teams This report details a tactic employed by threat actors, primarily Cloaked Ursa (APT29), to compromise organizations by impersonating IT departments within Microsoft Teams. The attackers leverage trusted communication cha… Palo Alto Unit 42 · Jun 8, 2026 High microsoft teamssocial engineeringmfa
threat-intel FBI-Flagged Phishing Kit Kali365 Expands Its Reach The Kali365 phishing-as-a-service platform, initially focused on compromising Microsoft 365 accounts via MFA bypass, has significantly expanded its capabilities and target list. It now actively targets platforms like AWS… Dark Reading · Jun 2, 2026 High USRUphishingdevice-codemfa
threat-intel Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts Hackers exploited Meta’s AI support bot on Instagram to gain unauthorized access to accounts, including those belonging to the Obama White House and the U.S. Space Force. The tactic involved tricking the bot into resetti… Krebs on Security · Jun 1, 2026 High IRaichatbotsocial engineering
phishing FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required The FBI has issued a warning about Kali365, a phishing-as-a-service kit that allows attackers to compromise Microsoft 365 accounts without needing passwords, even when MFA is enabled. This kit leverages device code flow,… Graham Cluley · May 26, 2026 High USCAGBmfadevice-code-flowphishing
threat-intel MFA Prompt Bombing: Why Your Second Factor Isn't Saving You This article details a new attack technique called ‘MFA prompt bombing,’ where attackers repeatedly trigger multi-factor authentication prompts to trick users into approving access. The attack leverages push-based MFA sy… The Hacker News · May 26, 2026 High USmfapush-mfaprompt bombing
phishing FBI warns of Kali365 phishing service targeting Microsoft 365 accounts The FBI has issued a warning about Kali365, a phishing-as-a-service (PhaaS) platform, being used to target Microsoft 365 accounts. This platform leverages device code authentication to bypass multi-factor authentication… BleepingComputer · May 25, 2026 High USphishingoauthmfa
phishing FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks The FBI has issued a warning about Kali365, a Telegram-based phishing-as-a-service platform, following its use in April attacks targeting Microsoft 365 accounts. This service lowers the barrier to entry for cybercriminal… The Record · May 22, 2026 High USphishingoauthmfa
threat-intel Hackers bypass SonicWall VPN MFA due to incomplete patching Hackers exploited a vulnerability (CVE-2024-12802) in SonicWall Gen6 SSL-VPN appliances to bypass multi-factor authentication and deploy ransomware tools. The attackers gained access to networks within 30-60 minutes, lev… BleepingComputer · May 20, 2026 High CVE-2024-12802USvpnmfacredential theft
threat-intel Identity Alone Isn't Enough: Why Device Security Has to Share the Load This article highlights the limitations of relying solely on identity verification in modern cybersecurity, arguing that it’s no longer sufficient against sophisticated attacks leveraging AI and phishing. The piece empha… BleepingComputer · May 20, 2026 High USzero trustmfadevice posture
threat-intel Fixing the password problem is as easy as 123456 This article highlights a persistent problem in cybersecurity: the widespread use of easily guessable passwords, particularly ‘123456’ and variations. Despite industry advice and password policies, numerous websites, inc… WeLiveSecurity · May 7, 2026 High password_securityweak_passwordsdata_breach
threat-intel Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition A 19-year-old teenager, identified as "Bouquet," has been arrested in Finland and faces US extradition charges for allegedly being a member of the Scattered Spider cybercrime group. The investigation revealed the group’s… Graham Cluley · May 4, 2026 High USGBFIsocial engineeringphishingmfa
threat-intel Great responsibility, without great power This article from Cisco Talos discusses the importance of empathy and understanding in cybersecurity, particularly in recognizing and responding to attacker behavior. It highlights five critical priorities for defenders… Cisco Talos · Apr 30, 2026 High CVE-2026-42208identityanomalythreat-hunting
threat-intel Five defender priorities from the Talos Year in Review This Cisco Talos report, part of their Year in Review, highlights five key priorities for cybersecurity defenders in the current threat landscape. The report emphasizes the increasing ease of attack due to readily availa… Cisco Talos · Apr 28, 2026 High USidentityvulnerabilityanomaly detection