A criminal AI service called MessiahGPT is being marketed on BreachForums as an uncensored platform for creating ransomware, phishing kits, stealers, crypters, rootkits, and social-engineering content.
Trellix researchers describe it as part of a growing underground market that turns offensive...
Three distinct Phishing-as-a-Service (PhaaS) platforms, Sneaky 2FA, EvilTokens, and EvilProxy, are actively targeting US organizations to steal Microsoft 365 (M365) credentials and session tokens, effectively neutralizing standard multi-factor authentication (MFA) protections.
Each kit uses a fundamentally different technical approach: Adversary-in-the-Middle (AiTM) session...
AI-generated phishing campaigns are rapidly evolving beyond traditional malware delivery, shifting the battleground directly into the web browser where attackers can hijack active sessions, bypass multi-factor authentication (MFA), and evade conventional endpoint security controls.
This emerging threat model is forcing...
Authorities dismantled Kratos, a major phishing-as-a-service operation behind around 15,000 monthly phishing campaigns, shutting down a global infrastructure used for large-scale credential theft.
The operation involved collaboration between German law enforcement agencies and authorities in the United States and Indonesia....
Forg365 is a phishing-as-a-service platform that targets Microsoft accounts, combining AI-powered phishing, session theft, and post-compromise mailbox access in a single operator panel
The platform is reportedly distributed through Telegram, where criminals can access a 30-day trial, pay about per...
A $12 domain, 72 hours of patience, and your finance team's credentials — why authentication tells you who sent the email, never where the link goes, and how detection at the click closes the gap your gateway can't see.
A...
The FBI has issued a new cybersecurity warning about a rapidly emerging phishing-as-a-service (PhaaS) platform named Kali365, which is actively targeting Microsoft 365 users to steal access tokens and bypass multi-factor authentication (MFA).
Kali365 is being distributed primarily through Telegram...
Threat actors are rapidly shifting their intrusion tradecraft toward high-speed, SaaS-centric attacks that completely bypass traditional endpoint security.
Since October 2025, security researchers have tracked two distinct adversaries, identified as CORDIAL SPIDER and SNARKY SPIDER, conducting aggressive data theft...
A sophisticated cybercriminal operation dubbed "AccountDumpling" has compromised approximately 30,000 Facebook accounts worldwide.
Discovered by Guardio Labs, this Vietnamese-linked campaign abuses Google's AppSheet platform to bypass traditional email security filters.
By routing fully authenticated phishing lures through legitimate channels,...
A multi-vector phishing campaign using compromised WordPress sites to steal login credentials from Microsoft Teams and Xfinity users. By hijacking these trusted sites, attackers can bypass security filters and trick victims into disclosing sensitive information.
The threat actors are not...