❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdaySecurity/Privacy

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

By: Dissent
7 September 2026 at 13:24
Bill Toulas reports: A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. Researchers at cybersecurity company CloudSEK gained administrator access to the control panel and found that the service managed 42 VPS nodes, all configured to target Microsoft 365 as...

Source

Copilot is one app β€” and other changes

7 September 2026 at 03:43
MICROSOFT 365 By Peter Deegan Microsoft is finally fixing a mess of its own making by merging two Copilot apps into one. Less obvious are other changes happening at the same time: reducing Microsoft’s costs and nudging more people toward paid AI services. Just so you’re not caught unawares, let’s go through the Copilot app […]

Push off Passkeys

1 September 2026 at 03:45
ISSUE 23.35.1 β€’ 2026-09-01 By Susan Bradley Defer the Passkeys mandate for 365. Today, Microsoft begins its official effort to move Microsoft 365 customers from traditional authentication to what it calls β€œphishing-resistant” methods. This means Windows Hello, passkeys, or similar multifactor authentication (MFA) methods that are more secure. For consumers using 365, this will probably […]

Windows 10 and Office

27 July 2026 at 03:43
MICROSOFT 365 By Peter Deegan Microsoft recently extended the Windows 10 ESU plan until October 2027. What you might not realize is that neither Microsoft 365 updates nor Office updates are part of the ESU offering. Office 2021 support ends in mere months. Microsoft’s original plan was to offer the Windows 10 Extended Security Updates […]

This phishing kit looks more like BEC-as-a-service

1 July 2026 at 06:00

Toolkits to wage phishing campaigns are a now-venerable instrument for cybercriminals, but researchers recently turned up details on something like a full-fledged β€œbusiness email compromise-as-a-service” platform.

Cisco Talos said Wednesday that it had found an operator panel dubbed ARToken, which shares infrastructure and other things in common with, and as an affiliate to, the EvilTokens phishing-as-a-service operation built to bypass multi-factor authentication and compromise Microsoft 365 accounts. EvilTokens has reportedly seen a dramatic increase in its phishing attacks β€” by 1,380% early this year compared to the same period last year β€” with an assist from artificial intelligence integration.

ARToken is notable, though, for the capabilities that go beyond what’s been made public about EvilTokens so far by companies like Sekoia and Microsoft itself, such as inbox rule manipulation and shared access links.

β€œThese features indicate the platform is more mature than a simple device code phishing kit β€” it is a complete BEC operations environment,” wrote Michael Kelley, security research engineer at Cisco Talos, in a blog post, referring to business email compromise scams that involve sending fake emails to solicit fraudulent payments.

Kelley told CyberScoop that β€œwe’ve seen some offerings that touch on this capability, but this definitely seems more fleshed out and polished than previous instances.”

ARToken is also notable for its evasive capabilities, with a seven-layer anti-analysis system, the post states.

The research provides further details on what ARToken’s actual phishing lures look like in practice. They are targeted, rather than scattershot and opportunistic, as one lure the firm examined shows.

β€œThe messages spoof an accounts-payable contact at a legitimate Wisconsin contractor, addressed to an accounts-payable recipient at a U.S. life sciences company β€” abusing a real vendor relationship rather than inventing a sender,” Kelley wrote. β€œThe lure theme is an outstanding-invoice inquiry (β€˜the following invoices appear to still be outstanding… advise when this will be processed’), the kind of message accounts-payable staff are conditioned to act on.”

Kelley told CyberScoop that Cisco Talos doesn’t yet have a full sense of the breadth of the activity, nor who is making use of the capability.

β€œWe’ve seen the public sector targeted but it’s unlikely to be the only one,” he said.

The post This phishing kit looks more like BEC-as-a-service appeared first on CyberScoop.

Better spreadsheets with sensible AI

29 June 2026 at 03:45
ISSUE 23.26 β€’ 2026-06-29 MICROSOFT 365 By Peter Deegan Give AI a chance to help you with any Excel or spreadsheet app. AI can greatly speed up your time spent working on a workbook β€” rom explaining functions and improving formulas to making a full sheet from your description. Any version of Excel, including perpetual […]

Spoofing Microsoft 365 Like It’s 1995

Steve Borosh // Why Phishing? Those of us on the offensive side of security often find ourselves in the position to test our clients’ resilience to phishing attacks. According to […]

The post Spoofing Microsoft 365 Like It’s 1995 appeared first on Black Hills Information Security, Inc..

❌
❌