Identity and Access Management

Cybersecurity
Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts
The Greatness phishing-as-a-service platform has expanded to device-code and AiTM phishing, with attacks spoofing RingCentral to target Microsoft 365 users.
Cybersecurity
Unit 42 Details Pass-ta-key Attacks on Google-Synced Passkeys
Unit 42 reveals three Pass-ta-key attacks that let malware hijack Google-synced passkeys on Windows by abusing Chrome's TPM trust and cloud authenticator flows.
Cybersecurity
ShinyHunters Claims Brinks Home Breach of Up to 4.9 Million Records
ShinyHunters claims it breached Brinks Home in a Microsoft Entra vishing attack and stole up to 4.9 million Salesforce records and 3.8 million support chats.
Cybersecurity
Health-ISAC Warns Healthcare Sector of Rising ShinyHunters Attacks
Health-ISAC warned of increased ShinyHunters attacks on healthcare using vishing to compromise SSO accounts and steal data from connected cloud platforms.
CVE Vulnerability Alerts
Check Point SmartConsole Auth Bypass PoC Elevates Active Exploit Risk
Rapid7 released a public PoC for CVE-2026-16232, a CVSS 9.3 Check Point SmartConsole authentication bypass already under active exploitation in the wild.
Cybersecurity
Jalisco and OmegaLord PhaaS Kits Beat M365 MFA Using OAuth Tricks
ReliaQuest disclosed Jalisco, which regenerates OAuth tokens in real time to beat Microsoft's 15-minute window, and OmegaLord, which harvests MFA phone numbers.
Cybersecurity
Open Server Exposes Three Concurrent Evilginx M365 Operations
French security firm Lexfo discovered three Evilginx M365 phishing campaigns after attackers left a Python HTTP server with directory listing exposed.
Cybersecurity
Helix Group Uses Vishing and Device Code Flow to Steal SharePoint Data
New threat group Helix chains vishing with Microsoft's OAuth Device Code Flow to harvest M365 tokens and exfiltrate SharePoint data for corporate extortion.
Application Security
WriteOut Flaw Let Attackers Hijack Any Writer AI Enterprise Account
Sand Security found a one-click session isolation flaw in Writer AI letting attackers access any enterprise tenant's private models, credentials, and documents.
Cybersecurity
Fake Job Interview Phishing Hits Marketing Pros Across 30 Brand Lures
Attackers posing as 30-plus major brand recruiters use fake job interviews to steal Google credentials from marketing professionals who manage ad platforms.