Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News


thehackernews.com > 2026 > 09 > attackers-use-passkey-phishing-to.html

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

1+ day, 5+ hour ago   (734+ words) Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. Evidence indicates that the operators behind the campaign…...


thehackernews.com > 2026 > 09 > microsoft-365-attackers-use-help-desk.html

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

6+ day, 23+ hour ago   (360+ words) The activity, which mainly singles out directors, vice presidents, and other executive staff, is being tracked by Arctic Wolf under the moniker PREY-0058, adding it shares significant tradecraft similarities with a data extortion group that Google-owned Mandiant calls UNC6671. It also…...


thehackernews.com > 2026 > 08 > key-reasons-why-identity-fabric-matters.html

Key Reasons Why Identity Fabric Matters in 2026

2+ week, 3+ day ago   (1098+ words) The guidance here focuses on enterprise hybrid and multi-cloud environments; smaller single-directory deployments may not require the full scope described. An Identity Fabric is not a single product but an architectural approach that connects identity providers, governance systems, applications, and…...


thehackernews.com > 2026 > 08 > novacookies-campaigns-abuse-genuine.html

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

2+ week, 5+ day ago   (857+ words) Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News ahead of…...


thehackernews.com > 2026 > 08 > mirage2fa-surge-hits-4500-us-and-eu.html

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

2+ week, 6+ day ago   (496+ words) Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most…...