
Fake IT Help Desk Calls Target Microsoft 365 Executives
Vishing campaign targets directors and VPs with fake IT help desk calls, using adversary-in-the-middle token theft and residential proxies.

Vishing campaign targets directors and VPs with fake IT help desk calls, using adversary-in-the-middle token theft and residential proxies.

TantoSec released a PoC exploit chaining Telerik UI padding oracle to unauthenticated RCE two months after Progress Software shipped a

Elastic Security Labs found four REVSTEALER persistence modules that remain after the stealer deletes itself, disabling Defender to run a

WatchTowr researchers observed attackers exploiting CVE-2026-82329 to mint admin tokens on JFrog Artifactory instances days after August 28 disclosure.

U.S. and South Korean intelligence agencies warn Gunra ransomware exploits Fortinet firewall flaws alongside a previously undocumented MFA bypass technique.

PortSwigger researcher Gareth Heyes showed email-borne CSS attacks that capture passwords and steal tokens in Outlook, Gmail, Yahoo, and other

Researcher James Arnott disclosed severe flaws in the Connective eID extension exposing PINs, enabling forged signatures, and allowing drive-by code

Arctic Wolf documented an AitM phishing campaign hijacking Microsoft 365 accounts to collect payroll and finance emails across North America

Connor Riley Moucka pleaded guilty in Seattle federal court to intrusions into 165 Snowflake customers that exposed records of more

The Greatness phishing-as-a-service platform has expanded to device-code and AiTM phishing, with attacks spoofing RingCentral to target Microsoft 365 users.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.