LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
security

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff

zeroday.news ·

Photo: KK IN HK (Public domain) via Wikimedia Commons

Threat hunters have reported a new threat cluster actively targeting executive staff within organizations, leveraging social engineering and technical exploits to compromise Microsoft 365 and other SaaS platforms. The attacks involve fake IT help desk calls, a technique known as vishing, combined with adversary-in-the-middle (AitM) token theft and the use of residential proxies for illicit sign-ins. The primary targets identified are high-level personnel, including directors and vice presidents.

The attack chain typically begins with a vishing call to an executive, impersonating IT support. The goal of this initial social engineering phase is often to trick the victim into performing an action that facilitates the subsequent technical compromise. This could involve directing them to a malicious website or convincing them to provide authentication details under the guise of troubleshooting.

Following the social engineering component, the attackers employ adversary-in-the-middle (AitM) techniques to steal authentication tokens. AitM attacks intercept communication between a user and a legitimate service, allowing the attacker to capture session cookies or other tokens that prove a user's authenticated status. With a stolen token, the attacker can bypass multi-factor authentication (MFA) and gain unauthorized access to the victim's accounts without needing their password.

Once access is gained, the threat actors utilize residential proxies for sign-ins. Residential proxies route network traffic through legitimate residential IP addresses, making the malicious sign-in attempts appear to originate from a trusted or less suspicious location. This tactic helps attackers evade detection mechanisms that flag logins from unusual or known malicious IP ranges, making it harder for security teams to identify the compromise in real-time.

The ultimate objectives of this threat cluster are data theft and extortion. After gaining access to executive Microsoft 365 accounts, attackers can exfiltrate sensitive corporate data, including emails, documents, and other files stored within the SaaS environment. This stolen data is then likely used as leverage in extortion schemes, threatening public release or sale if a ransom is not paid.

Mitigation for such attacks typically involves a multi-layered approach. Organizations are advised to implement robust security awareness training, specifically educating employees, especially executives, about vishing tactics and the importance of verifying IT support requests through official channels. Technical controls should include strong multi-factor authentication (MFA) that is resistant to token theft, such as FIDO2-based security keys, and continuous monitoring of sign-in logs for anomalous activity, including the use of residential proxies or unusual access patterns. Endpoint detection and response (EDR) solutions can also help detect and prevent the execution of malicious scripts or access to phishing sites.

This incident highlights the evolving sophistication of threat actors who combine social engineering with advanced technical exploits to target high-value individuals within organizations. The focus on executives underscores the understanding that compromising such accounts can yield significant access to sensitive information and critical business operations, making them prime targets for data theft and extortion campaigns.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.