Tag: Microsoft 365 Security

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: EvilTokens targets Microsoft 365

Cybersecurity Threat Advisory: EvilTokens targets Microsoft 365

Recent research describes a phishing kit called EvilTokens. It is actively targeting organizations in the U.S. and Europe, especially those in finance and other high-value sectors. Barracuda recommends deploying browser-aware phishing analysis and strengthening Microsoft 365 OAuth and device-code controls....

/ July 8, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: LSHIY password spray campaign

Cybersecurity Threat Advisory: LSHIY password spray campaign

This Cybersecurity Threat Advisory covers a large-scale password and token spray campaign targeting Microsoft Azure CLI authentication flows. Researchers linked the campaign to activity originating from the IPv6 range 2a0a:d683::/32. The range is associated with LSHIY LLC / AS32167. Researchers...

/ July 8, 2026