authentication

The Silent “Storm”: New Infostealer Hijacks Sessions, Decrypts Server-Side

A new infostealer named Storm, emerging in early 2026, steals browser credentials, session cookies, crypto wallets, and more by sending encrypted data to attackers' servers for decryption instead of decrypting locally, evading endpoint security detection. Storm automates session hijacking by restoring authenticated sessions remotely, enabling attackers to access SaaS platforms and cloud environments without triggering password alerts, and it is sold via tiered subscriptions on cybercrime forums.

https://www.bleepingcomputer.com/news/security/the-silent-storm-new-infostealer-hijacks-sessions-decrypts-server-side/

New VENOM Phishing Attacks Steal Senior Executives’ Microsoft Logins

Threat actors using a new phishing-as-a-service platform called VENOM have been targeting Microsoft logins of senior executives since at least last November. The attacks impersonate Microsoft SharePoint notifications with highly personalized emails and QR codes leading victims to sophisticated credential-harvesting pages that bypass traditional protections like MFA, highlighting the need for stronger authentication measures such as FIDO2 and stricter access policies.

https://www.bleepingcomputer.com/news/security/new-venom-phishing-attacks-steal-senior-executives-microsoft-logins/

New Alert: Hackers Hijack Corporate M365 Accounts With OAuth Device Codes

A recent surge in phishing attacks abuses Microsoft's OAuth Device Code flow, allowing hackers to hijack corporate Microsoft 365 accounts without stealing passwords by tricking victims into authenticating on legitimate Microsoft login pages. This token-based technique is difficult to detect with traditional tools and enables attackers to access sensitive corporate data, but solutions like ANY.RUN’s SSL decryption and interactive sandbox analysis provide earlier visibility and help security teams respond faster to these sophisticated threats.

https://cyberpress.org/new-alert-hackers-hijack-corporate-m365-accounts-with-oauth-device-codes/

Inside Tycoon2FA: How a Leading AiTM Phishing Kit Operated at Scale

The article analyzes Tycoon2FA, a phishing-as-a-service platform that enabled large-scale adversary-in-the-middle (AiTM) attacks capable of bypassing multifactor authentication. It explains how the service intercepted login credentials and session cookies through proxy phishing pages that mimicked services such as Microsoft 365 and Gmail. The platform included evasion techniques and user-friendly infrastructure, enabling less-skilled attackers to run campaigns that reached hundreds of thousands of organizations each month. The article concludes with guidance on layered defenses, including improved authentication methods, phishing detection, and coordinated disruption efforts. 

https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/

New AirSnitch Attack Bypasses Wi-Fi Encryption in Homes, Offices, and Enterprises

New research reveals a series of attacks, named AirSnitch, that bypass Wi-Fi encryption and client isolation, allowing attackers to intercept and manipulate data between connected clients. The attacks exploit vulnerabilities in the lowest levels of the network stack, specifically targeting the interaction between Layers 1 and 2. AirSnitch enables bidirectional man-in-the-middle attacks, potentially compromising sensitive data and enabling advanced cyberattacks.

https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/

Identity Verification Systems Are Struggling With Synthetic Fraud

Identity verification systems face issues with synthetic fraud as fake and expired IDs appear in transactions, especially in fast onboarding and remote transactions. Intellicheck's analysis of nearly 100 million transactions shows a 97.85% average verification success rate, concealing significant industry differences. Key fraud sources include expired credentials and synthetic identities, exacerbated by AI capabilities. Industries like alcohol retail and online-only banks exhibit the highest failure rates. Organizations are encouraged to focus on identity verification metrics to preempt fraud. The need for advanced, multi-layered verification technologies is emphasized as traditional methods fail to counteract evolving fraud tactics.

https://www.helpnetsecurity.com/2026/02/23/analysis-identity-verification-fraud-report/

Hackers Target Microsoft Entra Accounts in Device Code Vishing Attacks

Hackers are targeting Microsoft Entra accounts using device code phishing and voice vishing, compromising accounts through legitimate Microsoft OAuth flows without needing traditional phishing methods. This allows attackers to gain valid authentication tokens and access victims' accounts, enabling corporate data theft. The ShinyHunters gang is suspected to be behind these attacks, with recommendations for organizations to monitor OAuth apps, revoke suspicious consents, and consider disabling device code flows when unnecessary.

https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/

CyberheistNews Vol 16 #07 Uncovering the Sophisticated Phishing Campaign Bypassing M365 MFA

Phishing campaign bypassing M365 MFA detected, compromising accounts by exploiting OAuth 2.0 flows. Attackers trick users into authenticating on legitimate Microsoft domains, stealing access tokens for persistent access to data. Key sectors targeted include tech, manufacturing, and finance. Immediate mitigation requires auditing OAuth apps and reviewing email logs. Additionally, there’s discussion on automation in incident response, AI-driven email security, and the evolution of romance scams using deepfake technology. New voice phishing kits enable real-time control over attacks, raising concerns over email security gaps in organizations.

https://blog.knowbe4.com/cyberheistnews-vol-16-07-uncovering-the-sophisticated-phishing-campaign-bypassing-m365-mfa

Massive Credential Leak Exposes 149 Million Stolen Logins for Gmail, Facebook, Netflix and More

Massive leak of 149 million stolen logins (including for Gmail, Facebook, Netflix) poses significant customer trust risks, revealing cybersecurity failures. Exposed data includes sensitive credentials linked to major services. This incident highlights the need for improved security measures and customer education on malware risks, as credential theft becomes industrialized. Brands must prioritize trust and proactive responses to protect customer experience amidst rising cyber threats.

https://www.cxtoday.com/security-privacy-compliance/massive-credential-leak-exposes-149-million-stolen-logins-for-gmail-facebook-netflix-and-more/

Nearly 800,000 Telnet Servers Exposed to Remote Attacks

Nearly 800,000 Telnet servers are vulnerable to remote attacks exploiting an authentication bypass flaw (CVE-2026-24061) in GNU InetUtils. This flaw allows attackers to gain root access without proper authentication. The vulnerability affects versions 1.9.3 to 2.7, with a patch available in version 2.8. Cybersecurity firm GreyNoise reports that limited exploit attempts have already begun following the vulnerability's disclosure. Admins are advised to disable Telnet services or block TCP port 23 if they cannot upgrade immediately.

https://www.bleepingcomputer.com/news/security/nearly-800-000-telnet-servers-exposed-to-remote-attacks/

Hackers Exploit Critical Telnetd Auth Bypass Flaw to Get Root

Hackers are exploiting a critical 11-year-old vulnerability in the GNU InetUtils telnetd server, allowing remote authentication bypass to gain root access. The flaw involves unsanitized environment variable handling, enabling attackers to set the USER variable to gain unauthorized access. Affected versions include 1.9.3 to 2.7, with a patch available in version 2.8. Despite the risk, many legacy systems still use Telnet, particularly in industrial sectors. Recent exploit activity was detected, but real-world impact appears limited. Immediate patching or mitigations are advised.

https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-telnetd-auth-bypass-flaw-to-get-root/

Inside GoBruteforcer: AI-Generated Server Defaults, Weak Passwords, and Crypto-Focused Campaigns

GoBruteforcer is a modular botnet that brute-forces passwords on Linux servers, targeting FTP, MySQL, and PostgreSQL services, exploiting AI-generated defaults and weak credentials. Over 50,000 servers may be affected. Its campaigns focus on cryptocurrency databases, utilizing common usernames and weak passwords derived from AI-generated configurations. The botnet operates through a two-part system: an IRC bot for command control and a bruteforcer for password attacks. Its success is bolstered by widespread internet exposure and legacy software vulnerabilities, particularly with misconfigured services like XAMPP. The botnet dynamically updates and expands its reach while targeting specific sectors, including crypto-related services, revealing significant risks in server security.

https://research.checkpoint.com/2026/inside-gobruteforcer-ai-generated-server-defaults-weak-passwords-and-crypto-focused-campaigns/

27 Malicious Npm Packages Used as Phishing Infrastructure to Steal Login Credentials

27 malicious npm packages were discovered in a phishing campaign targeting U.S. and allied organizations, primarily in sales and commercial sectors. The campaign utilized these packages to host phishing infrastructure, mimicking document-sharing portals and Microsoft sign-in pages, to steal login credentials from their targets. Attackers embedded client-side scripts to avoid detection and included checks to filter out bots. Notably, the campaign hard-coded specific email addresses of individuals in targeted firms, raising concerns about the source of this information. To mitigate risks, strong dependency verification, logging unusual CDN requests, enforcing phishing-resistant multi-factor authentication, and monitoring for suspicious activities are recommended.

https://thehackernews.com/2025/12/27-malicious-npm-packages-used-as.html

State-linked and Criminal Hackers Use Device Code Phishing Against M365 Users

State-linked hackers exploit device code phishing to target Microsoft 365 users, using techniques that impersonate legitimate access workflows. Groups from Russia and China lead recent attacks, employing tools like SquarePhish2 and Graphish phishing kits. This method involves users entering a device code, granting hackers access to their accounts. Cybersecurity firm Proofpoint notes the increased use of this tactic for attacks on various sectors, including government and education.

https://www.cybersecuritydive.com/news/state-linked-criminal-hackers-device-code-phishing-m365/808396/

Yep, Passkeys Still Have Problems

Passkeys still face significant issues in 2025, including vendor lock-in and usability challenges across different ecosystems. Users should engage with Credential Managers like Bitwarden, avoid relying solely on platform managers (Apple, Google, Microsoft), and consider Yubikeys for important accounts. The introduction of the FIDO Credential Exchange Specification offers some hope for transitioning between providers, but day-to-day usability remains problematic. Active user education on how Passkeys work and the benefits of robust Credential Managers is crucial to overcoming barriers to adoption. Miscommunication and forced options by service providers exacerbate user confusion and trust issues. Ultimately, a focus on user control and education is imperative to safely navigate the evolving landscape of digital security.

https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-still-have-problems/

Scroll to Top