Phishing

Application Security
Microsoft Seizes 50 EvilTokens Phishing Sites, UK Arrests 2
Microsoft announced court-authorized takedown of EvilTokens phishing service on September 22, seizing 50 sites. UK police arrested 2 suspects. 12,000 inboxes compromised.
Application Security
SideCopy Expands India Targeting to Academic Institutions
SideCopy threat actor expanded targeting from Indian government to academic institutions using spear-phishing with ReverseRAT and mshta.exe abuse, per Trellix research.
Application Security
Fake LastPass Authenticator Uses Signed Driver to Disable EDR
Fake LastPass Authenticator installer distributed via GitHub installs Microsoft-signed kernel driver to disable antivirus and EDR before deploying password stealer.
Application Security
Attackers Use BYOD Weaknesses to Access M365 via Graph API
Threat actors exploit BYOD gaps through vishing to gain M365 access, then use Microsoft Graph API to enumerate corporate structure and identify targets for extortion ...
Cybersecurity
Ohio Man Sentenced to 15 Years for AI-Generated Sextortion
Federal prosecutors secured a 15-year prison sentence for an Ohio man who created deepfake pornographic videos to extort victims in sextortion campaign.
Application Security
Mathspace Breach Exposes Data of Over 1 Million Students and Staff
Attackers breached Mathspace's Metabase internal reporting system, stealing data from more than 1 million students, staff, and parents at the math platform.
Application Security
Nightmare Eclipse Drops Zero-Days for CrowdStrike, Nvidia, Avast
Security researcher Nightmare Eclipse publicly released proof-of-concept zero-day exploits for CrowdStrike, Nvidia, and Avast that escalate to System privileges.
Application Security
BigBear Phishing Service Bypassed MFA at 258 Organizations
BigBear 2.0 phishing-as-a-service framework stole over 5,000 Microsoft 365 credentials from 258 organizations using adversary-in-the-middle attacks.
Application Security
Trezor Data Breach Impact Reaches 81,000 Customers
Trezor updated breach impact to 81,000 total customers after a third-party logistics provider ShipMonk was compromised in August 2026.
Application Security
Fake IT Help Desk Calls Target Microsoft 365 Executives
Vishing campaign targets directors and VPs with fake IT help desk calls, using adversary-in-the-middle token theft and residential proxies.