Scammers abusing a real Microsoft account-alert sender are part of a wider pattern: attackers are turning legitimate SaaS notification workflows into authenticated phishing infrastructure.
Read more:TechCrunchAbnormal AI
By PhishPond Desk
Arctic Wolf's June 2 follow-up describes the Kali365 operator expanding well beyond Microsoft 365: Okta SSO, Xerox DocuShare, AWS-style endpoints, and a Russian-language cluster including MAX Messenger account takeover via real SMS OTPs. Proofpoint's research places the kit inside a broader cluster of AI-generated device-code lookalikes.
Read more:Arctic Wolf LabsProofpoint
By PhishPond Desk
Socket attributes a coordinated supply-chain campaign called TrapDoor to roughly thirty-four packages across npm, PyPI, and Crates.io, with ecosystem-specific execution paths and a new twist: planted .cursorrules and CLAUDE.md files designed to influence the developer's AI coding assistant.
Read more:SocketThe Hacker News
By PhishPond Desk
An FBI-flagged phishing-as-a-service kit rents Microsoft 365 token theft for $250 a month, packaging device-code and OAuth abuse into a point-and-click dashboard that defeats MFA without a fake login page.
Read more:FBI IC3Malwarebytes
By PhishPond Desk
Abuse of legitimate email services such as Amazon SES shows why authentication pass results are not the same thing as sender trust.
Read more:BleepingComputerMicrosoft Security Blog
By PhishPond Desk
A newly reported kit packages templates, domain setup, anti-analysis controls, session monitoring, and AI-assisted drafting into one operator console.
Read more:BleepingComputerVaronis
By PhishPond Desk
SVG attachments became one of 2024 and 2025's fastest-growing phishing payload formats. The reason isn't novelty - it is that SVG sits in a parsing gap most secure email gateways inherit.
Read more:Sophos NewsCisco Talos
By PhishPond Desk
New phishing kits are pivoting from simple password theft to real-time token capture and replay workflows targeting modern MFA deployments.
Read more:The Hacker NewsThe Hacker News
By PhishPond Desk
Reverse-proxy phishing kits commoditized session-token theft over the last two years. The kit market now resembles SaaS, and that has implications for how defenders track operators.
Read more:Microsoft Threat IntelligenceSekoia
By PhishPond Desk
A longitudinal study tracks how lookalike domains and cloned login flows are assembled and rotated across finance-themed phishing clusters.
Read more:The Hacker News
By PhishPond Desk
Attackers continue to abuse trusted domains with weak redirect controls to improve lure trust and reduce user suspicion.
Read more:Microsoft Security Blog
By PhishPond Desk