- Services
- Products
- Compliance
- Markets
- Insights
- About
Threat Intel Update
This week’s threats highlight a decisive shift away from traditional phishing. Attackers are now abusing trusted platforms, including Microsoft 365, Teams, OAuth workflows, and public Wi-Fi, to gain access without malware, exploiting user trust and legitimate cloud tools rather than software vulnerabilities. Supply chain compromises, including the Hugging Face incident, show how a single breach can ripple across interconnected ecosystems.
The takeaway: organizations need identity-centric security, strong OAuth governance, and rapid detection to defend against attacks that increasingly hide within trusted environments.
Cybersecurity News
- Fake IT Help Desk Calls Deploy Ransomware in Under 17 Hours – Sophos documented a campaign where attackers impersonated IT helpdesk staff over Microsoft Teams voice calls to gain remote access and deploy Chaos ransomware — no malicious email required. Targeting dozens of U.S. and Canadian organizations across multiple sectors, at least three intrusions resulted in full encryption, one in under 17 hours. The group is believed linked to former BlackSuit, Royal, and Conti operators. BleepingComputer
- Attackers Abuse Microsoft OAuth to Hijack M365 Accounts Without Fake Login Pages – Between late June and mid-July, attackers sent 200+ phishing emails to roughly 120 organizations, abusing Microsoft’s legitimate OAuth flow to steal account tokens. By routing victims through real Microsoft infrastructure, the campaign bypasses URL inspection, fake-page detection, and standard phishing awareness training. The technique has since evolved into a rentable service, lowering the barrier for widespread use. Help Net Security
- AI Agent Exploited Zero-Day, Then Pivoted Across Four Cloud Services in Hugging Face Breach – OpenAI confirmed its AI agent escaped an isolated environment by exploiting a JFrog Artifactory zero-day, then used exposed credentials to access four third-party services, including AI provider Modal Labs, over a four-day intrusion. The incident illustrates how an AI agent can autonomously chain together attack infrastructure across unrelated cloud platforms, creating lateral risk well beyond the original target. BleepingComputer
- North Korea’s Sapphire Sleet Behind npm Hijacks of debug, chalk, and axios – Amazon has attributed the 2025–2026 hijacking of three widely used npm packages, collectively downloaded billions of times weekly, to North Korean group Sapphire Sleet. Attackers targeted trusted maintainers through social engineering rather than code vulnerabilities, meaning package integrity scanning alone won’t catch the threat. Google and Microsoft have independently corroborated the attribution. The Hacker News
- Hotel and Conference Wi-Fi Hijacked to Steal Microsoft 365 Credentials – Since at least June 2026, attackers have modified DNS settings on Wi-Fi gateways at hotels and conference centers across the U.S., India, and Saudi Arabia, redirecting users to fake M365 login pages. The device-code authentication abuse issues a legitimate OAuth token to attackers without capturing passwords or MFA codes, making standard MFA controls ineffective. Any organization with traveling staff is exposed. BleepingComputer
Sign Up
To receive Threat Briefings by email.