FBI and multiple security sources warn that the new Kali365 Phishing-as-a-Service (PhaaS) kit is enabling large-scale token-theft attacks against Microsoft 365 users.
According to the...
A sophisticated automated campaign dubbed Megalodon executed one of the largest GitHub supply chain attacks on record, pushing 5,718 malicious commits to 5,561 repositories in just...
The threat actor group TeamPCP, which operates the prolific Mini Shai-Hulud supply chain campaign, has successfully compromised Microsoft's official Python client for the Durable Task workflow...
Microsoft's Digital Crimes Unit (DCU) has dismantled the infrastructure of Fox Tempest, a financially motivated threat actor that operated a sophisticated malware-signing-as-a-service (MSaaS) platform, enabling...