Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SC Media
scworld.com > news > bigbear-2-0-phishing-campaign-compromises-mfa-protected-microsoft-accounts

BigBear 2.0 phishing campaign compromises MFA-protected Microsoft accounts

3+ day, 23+ hour ago   (143+ words) SC Media BigBear 2.0 phishing campaign compromises MFA-protected Microsoft accounts Attackers used VPS to match victim’s geolocation Laura French has been a staff reporter for SC Media since 2023. Laura writes daily news stories, contributes to feature stories, covers industry events and…...

eSecurity Planet
esecurityplanet.com > cybersecurity > news-bigbear-2-0-microsoft-365-mfa-bypass

BigBear 2.0 Bypasses Microsoft 365 MFA at 258 Firms

4+ day, 8+ hour ago   (580+ words) BigBear 2.0 bypassed Microsoft 365 MFA at 258 organizations by stealing session cookies. Learn how the phishing service works and how to respond. CloudSEK discovered BigBear 2.0 in June 2026 after gaining access to the operation’s administrative panel. The panel contained 5,137 records associated with 461 targeted…...

@KnowBe4
blog.knowbe4.com > greatness-phishing-kit-can-now-launch-sophisticated-attacks

Greatness Phishing Kit Can Now Launch Sophisticated Attacks

4+ day, 11+ hour ago   (154+ words) Researchers at ZeroBEC are tracking a phishing platform called “Greatness” that’s been significantly upgraded since it surfaced in 2023. “Since its initial discovery, the platform has evolved significantly,” the researchers write. “It now supports adversary-in-the-middle (AiTM) credential and token theft, device…...

theregister
theregister.com > security > 09/08/2026 > bigbear-phishing-crew-nets-thousands-of-microsoft-365-credentials > 5294944

BigBear phishing crew nets thousands of Microsoft 365 credentials

4+ day, 13+ hour ago   (625+ words) A Microsoft 365 phishing operation targeting hundreds of organizations captured thousands of passwords and session cookies, including hundreds of authenticated sessions that could be hijacked to bypass MFA, according to researchers who accessed the crooks' own admin panel. Security researchers at…...

TechNadu
technadu.com > bigbear-2-0-phishing-service-targets-microsoft-365-accounts-worldwide > 635921

BigBear 2.0 Phishing Service Targets Microsoft 365 Accounts Worldwide

4+ day, 15+ hour ago   (289+ words) CloudSEK's TRIAD team has uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service (PhaaS) operation targeting Microsoft 365 accounts worldwide. First identified in June 2026, CloudSEK attributes the campaign to a threat actor using the alias "General Boss," who operates a multi-user panel leased to…...

CSO Online
csoonline.com > article > 4219606 > bigbear-2-0-phishing-campaign-hijacks-microsoft-365-sessions-after-mfa.html

BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA

4+ day, 16+ hour ago   (700+ words) A phishing-as-a-service operation targeting Microsoft 365 users has harvested thousands of session cookies that could be used to hijack authenticated sessions after victims complete multifactor authentication, CloudSEK said. The cybersecurity firm said in a report that it uncovered the operation, known…...

Cyber Security News
cyberpress.org > bigbear-2-0-bypasses-mfa

BigBear 2.0 Phishing Campaign Hijacks Microsoft 365 Sessions to Bypass MFA

4+ day, 21+ hour ago   (391+ words) First identified in June 2026, the operation targeted Microsoft 365 users and was reportedly still active during the investigation. Researchers gained administrative access to the campaign’s management panel and found it had controlled 42 virtual private server nodes during its lifecycle. Most of…...

BleepingComputer
bleepingcomputer.com > news > security > bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

5+ day, 11+ hour ago   (517+ words) Dropbox accounts breached through Lenovo email verification flaw Microsoft: KB5120998 mouse reset bug affects only non-English PCs BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations Mathspace discloses data breach affecting over 1 million people Trezor data breach impact now reaches 81,000 customers Block…...

Infosecurity Magazine
infosecurity-magazine.com-magazine.com

Outsider Phishing Kit Survives Takedown With 700 New Pages

1+ week, 2+ day ago   (405+ words) A phishing-as-a-service (PaaS) operation has continued generating new campaigns despite a coordinated takedown effort, with more than 700 new phishing pages identified within a month of the disruption. Group-IB said its researchers had tracked the Outsider Phishing Kit, operated by a…...

@securitymag
securitymagazine.com > articles > 102527-a-look-inside-the-phishing-service-attacking-organizations

A Look Inside the Phishing Service Attacking Organizations

2+ week, 3+ day ago   (175+ words) Security Magazine Research from Island dives into a subscription phishing service known as NovaCookies. For around $320 per month, this service packages real-time Microsoft 365 session theft. The research examined artifacts from the campaign, discovering hundreds of organizations targeted, with nearly 90% associated…...