⤷ Title: Payroll Pirates in the North: Microsoft Unmasks ‘Storm-2755’ and the Theft of Canadian Salaries
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:11:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM Attack #Canada Cyber Threat #cybersecurity #HR Security #MFA Bypass #Microsoft DART #Payroll Fraud #phishing #SEO Poisoning #Storm_2755 #Workday Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:11:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM Attack #Canada Cyber Threat #cybersecurity #HR Security #MFA Bypass #Microsoft DART #Payroll Fraud #phishing #SEO Poisoning #Storm_2755 #Workday Security
Daily CyberSecurity
Payroll Pirates in the North: Microsoft Unmasks 'Storm-2755' and the Theft of Canadian Salaries
Microsoft DART uncovers Storm-2755, a "payroll pirate" using AiTM traps and SEO poisoning to steal salaries. Protect your organization from this MFA bypass.
⤷ Title: JUMPSEC Unmasks Iranian ‘Muddy Water’ Using Russian ‘CastleRAT’ Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 02:05:45 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #browser hijacking #CastleRAT #ChainShell #cyber_espionage #Ethereum C2 #HVNC #Iranian APT #JUMPSEC #Malware_as_a_Service #MFA Bypass #Muddy Water
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 02:05:45 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #browser hijacking #CastleRAT #ChainShell #cyber_espionage #Ethereum C2 #HVNC #Iranian APT #JUMPSEC #Malware_as_a_Service #MFA Bypass #Muddy Water
Daily CyberSecurity
JUMPSEC Unmasks Iranian 'Muddy Water' Using Russian 'CastleRAT' Malware
Iranian state actor Muddy Water adopts CastleRAT and ChainShell to hijack browsers and bypass MFA invisibly. A professional-grade shift in APT strategy.
⤷ Title: FBI and Indonesian Authorities Dismantle Prolific “W3LL” Phishing Empire
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 04:25:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime Takedown #FBI Atlanta #Indonesian National Police #MaaS #Malware_as_a_Service #MFA Bypass #Phishing_as_a_Service #Session Hijacking #W3LL Phishing Kit #W3LLSTORE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 04:25:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime Takedown #FBI Atlanta #Indonesian National Police #MaaS #Malware_as_a_Service #MFA Bypass #Phishing_as_a_Service #Session Hijacking #W3LL Phishing Kit #W3LLSTORE
Daily CyberSecurity
FBI and Indonesian Authorities Dismantle Prolific "W3LL" Phishing Empire
The FBI and Indonesia dismantle W3LL, a $20M phishing kit that bypassed MFA and hijacked live sessions. Learn about the takedown of this MaaS powerhouse.
⤷ Title: JanelaRAT Uses Fake Windows Updates to Empty LATAM Bank Accounts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 08:35:42 +0000
════════════════════════
⌗ Tags: #Malware #Banking Trojan #Brazil #DLL Sideloading #infosec #JanelaRAT #kaspersky #LATAM Cybercrime #Malware Analysis #Mexico #MFA Bypass #Session Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 08:35:42 +0000
════════════════════════
⌗ Tags: #Malware #Banking Trojan #Brazil #DLL Sideloading #infosec #JanelaRAT #kaspersky #LATAM Cybercrime #Malware Analysis #Mexico #MFA Bypass #Session Hijacking
Daily CyberSecurity
JanelaRAT Uses Fake Windows Updates to Empty LATAM Bank Accounts
JanelaRAT targets banking users in Brazil and Mexico using window monitoring and fake updates. Learn how this 2026 threat bypasses MFA to hijack sessions.
⤷ Title: MFA in 2026: Why Hackers Still Slip Through
════════════════════════
𐀪 Author: Cybersectoworld
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 13:46:45 GMT
════════════════════════
⌗ Tags: #social_engineering #cybersecurity #cyber_security_awareness #infosec #mfa
════════════════════════
𐀪 Author: Cybersectoworld
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 13:46:45 GMT
════════════════════════
⌗ Tags: #social_engineering #cybersecurity #cyber_security_awareness #infosec #mfa
Medium
MFA in 2026: Why Hackers Still Slip Through
Multi‑Factor Authentication (MFA) has been widely adopted as the frontline defense against account compromise. Users were assured that by…
⤷ Title: Unmasking the Phoenix System’s Rogue BTS Smishing Empire
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 May 2026 08:29:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Group_IB #infosec #Live_Phishing #MFA Bypass #Mouse System #OTP Interception #Phishing_as_a_Service #Phoenix System #Rogue BTS #smishing #Telegram fraud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 May 2026 08:29:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Group_IB #infosec #Live_Phishing #MFA Bypass #Mouse System #OTP Interception #Phishing_as_a_Service #Phoenix System #Rogue BTS #smishing #Telegram fraud
Daily CyberSecurity
Unmasking the Phoenix System’s Rogue BTS Smishing Empire
Group-IB unmasks the Phoenix System: a PhaaS platform using rogue cell towers and live-dashboards to bypass MFA across 2,500+ domains. Read the full report.
⤷ Title: OpenAI Introduces Advanced Account Security to Safeguard AI Identities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 09:14:10 +0000
════════════════════════
⌗ Tags: #Technology #Advanced Account Security #AI Privacy #ChatGPT #cybersecurity #infosec #MFA #OpenAI #Passkeys #Phishing Resistance #Trusted Access for Cyber #Yubico
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 09:14:10 +0000
════════════════════════
⌗ Tags: #Technology #Advanced Account Security #AI Privacy #ChatGPT #cybersecurity #infosec #MFA #OpenAI #Passkeys #Phishing Resistance #Trusted Access for Cyber #Yubico
Daily CyberSecurity
OpenAI Introduces Advanced Account Security to Safeguard AI Identities
OpenAI launches Advanced Account Security for high-risk users. Features include mandatory passkeys, disabled SMS recovery, and automatic training exclusion.
⤷ Title: The Compliance Trap: How a 13,000-Org Phishing Wave Bypasses MFA via AiTM Proxying
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 09:00:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #Cloudflare CAPTCHA #Credential Theft #cybersecurity #FIDO2 #infosec #MFA Bypass #Microsoft Defender #Paubox Hijacking #phishing #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 09:00:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #Cloudflare CAPTCHA #Credential Theft #cybersecurity #FIDO2 #infosec #MFA Bypass #Microsoft Defender #Paubox Hijacking #phishing #threat intelligence
Daily CyberSecurity
The Compliance Trap: How a 13,000-Org Phishing Wave Bypasses MFA via AiTM Proxying
Microsoft warns of a massive AiTM phishing campaign targeting 13,000+ orgs. Using fake disciplinary lures, attackers bypass MFA to hijack active sessions.
⤷ Title: Interceptor | TryHackMe | Walkthrough
════════════════════════
𐀪 Author: Sornphut
════════════════════════
ⴵ Time: Wed, 06 May 2026 19:06:21 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme_writeup #mfa #command_injection #tryhackme
════════════════════════
𐀪 Author: Sornphut
════════════════════════
ⴵ Time: Wed, 06 May 2026 19:06:21 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme_writeup #mfa #command_injection #tryhackme
Medium
Interceptor | TryHackMe | Walkthrough
What is the flag value after logging in as admin?
⤷ Title: AI “Vibe Coding” Fuels a Phishing Free-For-All: How EvilTokens Bypasses Microsoft 365 MFA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:11:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Conditional Access #Cyber Security #Device Code Phishing #EvilTokens #infosec #MFA Bypass #Microsoft 365 #PhaaS #Phishing_as_a_Service #Proofpoint #Vibe Coding
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:11:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Conditional Access #Cyber Security #Device Code Phishing #EvilTokens #infosec #MFA Bypass #Microsoft 365 #PhaaS #Phishing_as_a_Service #Proofpoint #Vibe Coding
Daily CyberSecurity
AI "Vibe Coding" Fuels a Phishing Free-For-All: How EvilTokens Bypasses Microsoft 365 MFA
AI "vibe coding" and the EvilTokens PhaaS platform are supercharging device code phishing to bypass Microsoft 365 MFA. Secure your network today!