Tag: Microsoft 365 Security
Cybersecurity Threat Advisory: Forg365 targets M365 accounts
Cybersecurity Threat Advisory: Forg365 targets M365 accounts
A new phishing-as-a-service (PhaaS) platform, Forg365, is being distributed through Telegram, lowering the barrier to Microsoft 365 account compromise by automating AI-assisted phishing lures and exploiting device code and adversary-in-the-middle (AiTM) authentication flows. What is the threat? Forg365 provides operators...
Cybersecurity Threat Advisory: EvilTokens targets Microsoft 365
Cybersecurity Threat Advisory: EvilTokens targets Microsoft 365
Recent research describes a phishing kit called EvilTokens. It is actively targeting organizations in the U.S. and Europe, especially those in finance and other high-value sectors. Barracuda recommends deploying browser-aware phishing analysis and strengthening Microsoft 365 OAuth and device-code controls....
