
ShinyHunters Breach Data Fuels $2,000 Bitcoin Sextortion Wave
Attackers are sending $2,000 Bitcoin sextortion emails that cite specific ShinyHunters-breached companies to make false surveillance threats appear credible.

Attackers are sending $2,000 Bitcoin sextortion emails that cite specific ShinyHunters-breached companies to make false surveillance threats appear credible.

ANY.RUN disclosed PhantomEnigma, a campaign that hijacked 20-plus Brazilian gov.br domains to distribute malware via police-themed phishing emails that pass

Spanish National Police and Europol dismantled a €140 million BEC and investment fraud ring, arresting four suspects across Spain, Portugal,

ReliaQuest disclosed Jalisco, which regenerates OAuth tokens in real time to beat Microsoft’s 15-minute window, and OmegaLord, which harvests MFA

French security firm Lexfo discovered three Evilginx M365 phishing campaigns after attackers left a Python HTTP server with directory listing

Elastic Security Labs found REF6045 deploying SCMBANKER, an AI-written PowerShell toolkit that lets operators control Mexican banking sessions live and

New threat group Helix chains vishing with Microsoft’s OAuth Device Code Flow to harvest M365 tokens and exfiltrate SharePoint data

Forg365 is a new phishing-as-a-service platform combining AiTM session hijacking and Device Code Flow abuse with AI-generated lures for mass

China-nexus Operation DragonReturn deploys DcRAT via a cloned Indian tax utility, targeting tax professionals and accountants during India’s filing season.

Unit 42 exposed an active campaign using fake Microsoft Teams IT support calls to install EtherRAT, a Node.js RAT whose
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.