Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. "The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,

Cybersecurity researchers have reported an active and widespread email-driven phishing campaign targeting Microsoft 365 accounts. This campaign leverages adversary-in-the-middle (AitM) techniques to compromise accounts, with the ultimate goal of identifying key personnel involved in financial workflows and exfiltrating related email communications. The observed activity indicates a focused effort to gain access to sensitive financial and payroll information within targeted organizations.
The core mechanism of this attack involves AitM phishing. In such a scenario, attackers position themselves between a user and a legitimate login page, effectively proxying the authentication process. This allows them to intercept credentials, including multi-factor authentication (MFA) tokens or session cookies, as they are exchanged. By capturing these elements, the attackers can then bypass MFA and establish their own authenticated session, thereby hijacking the legitimate user's account.
A notable characteristic of this particular campaign is its use of residential proxies. Attackers are routing their malicious sign-in attempts through these proxies, which makes the traffic appear to originate from ordinary consumer internet service provider (ISP) connections. This tactic helps to mask the true origin of the attacks and can make it more difficult for security systems to distinguish malicious login attempts from legitimate user activity, potentially allowing the attackers to evade detection mechanisms that flag unusual IP addresses or geographic locations.
Once an account is compromised, the attackers focus on reconnaissance within the victim's Microsoft 365 environment. Their objective is to identify individuals involved in payroll and finance operations. This often involves searching mailboxes for keywords, sender addresses, or specific types of attachments commonly associated with financial transactions, invoices, or payroll processing. The subsequent collection of related emails suggests an intent to either directly exfiltrate sensitive data or to prepare for further attacks, such as business email compromise (BEC) scams.
Microsoft 365 environments are frequently targeted due to their widespread adoption in business operations and the sensitive data they often contain, including email, documents, and collaboration tools. Organizations utilizing Microsoft 365 are advised to implement robust security measures. These typically include strong multi-factor authentication for all users, regular security awareness training to educate employees about phishing threats, and the deployment of advanced threat protection solutions that can detect and block sophisticated phishing attempts, including those employing AitM techniques.
Mitigation strategies for this class of attack generally involve a multi-layered approach. Beyond MFA and user education, organizations should ensure that email security gateways are configured to detect and quarantine phishing emails, especially those attempting to direct users to malicious login pages. Monitoring for unusual login patterns, such as logins from previously unseen IP addresses or rapid consecutive logins from different geographical locations, can also help identify compromised accounts. Furthermore, regular audits of mailbox rules and forwarding settings can detect unauthorized changes made by attackers to maintain persistence or exfiltrate data.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.