Identity & access
-
Researchers redraw North Korea’s cyber structure
Sekoia and Kudelski Security have divided the old Lazarus umbrella into six operational clusters spanning espionage, financial operations, cryptocurrency theft, and fraudulent IT-worker activity.
-
BigBear steals Microsoft 365 sessions at scale
CloudSEK says a phishing-as-a-service operation has used adversary-in-the-middle infrastructure to collect Microsoft 365 credentials and authenticated-session cookies across hundreds of organisations.
-
Teams impersonation moves beyond email fraud
Belgian authorities and Microsoft are warning about Microsoft Teams impersonation attacks that turn trusted collaboration workflows into routes for payment fraud and remote enterprise compromise.
-
NetScaler bypass draws exploitation attempts
Exploit attempts against a critical NetScaler authentication bypass are being observed after public proof-of-concept code appeared, increasing pressure on operators still running vulnerable appliances.
-
Police reveal route into Odido breach
Dutch investigators say an attacker impersonated Odido’s IT department, captured an employee’s credentials and verification code, and gained access to data belonging to more than six million customers.
-
Knight Office steals Microsoft 365 sessions
Huntress has documented a Microsoft 365 phishing kit that steals authenticated sessions and can establish persistence through unauthorised Entra device registration.
-
Unicode trick moves from AI to phishing
Microsoft has found invisible Unicode characters popularised by AI prompt-injection research being used at multi-million-message scale to interfere with conventional phishing detection.
-
Kali365 abuses Microsoft authentication for account access
Kali365 phishing campaigns are abusing legitimate Microsoft authentication processes to obtain sessions and tokens, reducing the value of familiar warning signs around fake login pages and password theft.
-
Pegasus found on Serbian protest activist’s iPhone
Citizen Lab has forensically confirmed Pegasus spyware on a Serbian student activist’s iPhone after an iMessage zero-click attack, while the identity of the operator remains unknown.
-
Lenovo identity flaw exposed Dropbox accounts
A weakness in Lenovo ID email verification allowed attackers to create fraudulent identities and use the federated login relationship to access associated Dropbox accounts without the victims’ passwords.










