The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Professional Training
Breach intelligence, attack campaigns, and threat reports targeting the Professional Training sector.
Explore Other Sectors
Professional Training Threat Reports
Inside Real Google Workspace Breaches: OAuth Social Engineering Attack Analysis
Multiple Google Workspace environments have been compromised through sophisticated social engineering campaigns combined with malicious OAuth applications. Attackers bypassed traditional credential-based security by convincing users to authorize malicious applications, granting direct access to corporate Google Workspace data and services. These incidents demonstrate how threat actors exploit user trust and application authorization mechanisms rather than relying on stolen passwords or software vulnerabilities, resulting in significant data exposure and lateral movement across connected applications. These attacks highlight the growing trend of identity-centric compromise vectors as organizations increasingly adopt cloud-first strategies. With OAuth-based attacks rising 300% in 2026 and social engineering remaining the top initial access vector, enterprises face mounting pressure to implement zero-trust controls that verify application legitimacy and user intent beyond simple authentication.
1 day ago
Kill Chain
How Microsoft's EvilTokens Takedown Exposed the Rise of AI-Powered Cybercrime
In September 2026, Microsoft and industry partners disrupted EvilTokens, a sophisticated AI-powered phishing-as-a-service platform that compromised over 12,000 Microsoft customer email accounts across 10,000+ organizations globally. Operating from February 2026, the platform served approximately 1,000 cybercriminals who paid $1,500 initiation fees and $500 monthly subscriptions for access to advanced tools that bypassed multi-factor authentication through session token theft. The service featured an AI chatbot that analyzed victim inboxes to identify trusted relationships and financial exploitation opportunities, generating at least $1.1 million in revenue and facilitating $1.7 million in documented fraud losses before takedown operations seized 50 websites and disabled 175 domains. This incident highlights the concerning evolution of cybercrime-as-a-service models that leverage artificial intelligence to democratize sophisticated attack techniques, significantly lowering barriers to entry for financially motivated threat actors and enabling unprecedented scale of business email compromise campaigns.
2 days ago
Kill Chain
How Malicious OAuth Applications Breach Google Workspace Environments
OAuth application abuse has emerged as a sophisticated attack vector targeting Google Workspace environments, bypassing traditional authentication controls through social engineering tactics. Attackers manipulate users into authorizing malicious OAuth applications, granting persistent access to organizational data without requiring password theft or exploitation of software vulnerabilities. These attacks exploit the trust relationship between users and legitimate-appearing applications, allowing threat actors to access sensitive information based on the permissions granted during the authorization process. The incidents demonstrate how attackers can achieve significant organizational compromise through user manipulation rather than technical exploitation. This attack method represents a growing trend in identity-focused threats as organizations increasingly adopt cloud-based collaboration platforms and third-party integrations, making OAuth abuse a critical concern for modern enterprise security.
1 week ago
Kill Chain
When Employee Passwords Appear in Infostealer Logs: A Critical Security Response Framework
A growing cybersecurity challenge has emerged where employee corporate credentials are increasingly appearing in infostealer malware logs, with approximately 46% originating from unmanaged personal devices. These logs contain not just passwords but authenticated session cookies that can bypass multi-factor authentication, creating immediate access risks. Research indicates that exposure involving credentials for major SaaS and cloud services is growing 29% annually, with roughly 90% of logs now circulating through Telegram channels where they're accessible to initial access brokers and ransomware affiliates. This threat represents the convergence of several critical cybersecurity trends: the rise of hybrid work environments, increased reliance on SaaS applications, and the evolution of credential theft from simple password harvesting to comprehensive session hijacking. Organizations must now treat infostealer monitoring as an essential component of identity security programs.
2 weeks ago
Kill Chain
Spring Ring Campaign: How Vishing Attacks Weaponized Microsoft Teams in 2026
Between January and April 2026, the "Spring Ring" threat operation targeted over 150 Microsoft Teams users across 10+ organizations using sophisticated voice phishing (vishing) attacks. Attackers impersonated internal IT support staff through Teams chats, then conducted voice calls to trick employees into installing remote access tools or executing malware. The most advanced variant employed NTLM relay attacks targeting domain controllers for full infrastructure compromise, demonstrating a significant evolution from traditional email phishing to real-time social engineering through trusted collaboration platforms. This incident reflects the accelerating shift toward platform-native attacks as threat actors exploit the inherent trust users place in enterprise collaboration tools. With vishing attacks doubling in the first half of 2026 according to CrowdStrike data, organizations face an urgent need to reassess security controls around identity verification and SaaS platform governance as traditional perimeter defenses prove inadequate against socially-engineered compromise vectors.
3 weeks ago
Kill Chain
Russian Cybercriminal Extradited for Massive Excel Malware Campaign
Russian national Searzhudin Tamirlanovich Aktulaev, 40, has been charged by the U.S. Department of Justice for orchestrating a sophisticated malware campaign between 2016 and 2017. Aktulaev created approximately 255 fake accounts on a freelance platform and distributed malware-laced Excel attachments to roughly 80,000 users. The attack leveraged social engineering tactics within trusted business communications to deliver malicious payloads, potentially compromising thousands of victims' systems and data. Aktulaev was arrested in Cyprus in May 2025 and extradited to the United States on August 28, 2026. This case highlights the persistent threat of nation-state actors exploiting trusted platforms and file formats for malware distribution, particularly as cybercriminals increasingly target business communication channels and use legitimate services as attack vectors in 2026's evolving threat landscape.
3 weeks ago
Kill Chain
ClickFix Attackers Exploit Polygon Blockchain in Campaign Against 31 Organizations
In September 2026, a sophisticated ClickFix campaign compromised at least 31 organizations across e-commerce, professional services, and retail logistics sectors. The attackers employed EtherHiding techniques, abusing the Polygon blockchain as a dynamic command-and-control infrastructure to evade traditional detection methods. Unlike typical ClickFix campaigns that deploy infostealers, this operation functioned as an initial access broker (IAB), installing persistent backdoors that survive reboots and communicate with C2 servers updated via blockchain transactions costing fractions of cents. This incident represents a concerning evolution in cybercriminal tactics, demonstrating how threat actors are weaponizing blockchain technology for resilient C2 infrastructure. The campaign's dual-victim approach, targeting both website owners through mass exploitation and end-users through social engineering, highlights the growing sophistication of modern cyber attacks and the need for comprehensive defense strategies addressing both technical vulnerabilities and human factors.
3 weeks ago
Kill Chain
Anthropic Claude Users Targeted in Multi-Platform Infostealer Campaign
In August 2026, Anthropic detected unauthorized access to Claude AI accounts after threat actors used multiple infostealer malware variants including Vidar, Lumma, StealC, RedLine, Acreed, and Atomic Stealer to harvest user session cookies and authentication tokens. The attackers bypassed multifactor authentication by stealing active browser sessions rather than credentials, allowing them to consume users' Claude usage quotas and access saved payment information. Anthropic responded by forcibly signing out affected users, removing payment methods, and refunding unauthorized charges. This incident exemplifies the growing shift from credential-based attacks to session hijacking, as organizations strengthen password policies and MFA adoption. The attack highlights emerging threats against AI platforms and the need for enhanced session management controls in cloud-native applications.
3 weeks ago
Kill Chain
The AI Revolution in Cyber Reconnaissance: Why Everyone Is Now a Target
Artificial intelligence is fundamentally transforming the cybercrime landscape by democratizing sophisticated Open Source Intelligence (OSINT) reconnaissance capabilities. Previously, comprehensive target profiling required specialized skills and significant time investment, limiting such attacks to high-value targets. AI-powered tools now enable threat actors with minimal technical expertise to rapidly collect, correlate, and weaponize publicly available information from social media, professional networks, and web sources at machine speed, dramatically lowering the barrier to entry for personalized social engineering attacks and fraud schemes. This capability shift represents a critical inflection point in cyber threat evolution, as AI enables scalable personalization of attacks previously reserved for advanced persistent threat groups. The convergence of readily available AI tools with abundant personal data creates unprecedented risk exposure for individuals and organizations alike.
3 weeks ago
Kill Chain
Forcepoint Exposes Critical AI Vulnerability: Hidden Prompts Manipulate Email Summarizers
In August 2026, Forcepoint X-Labs researchers demonstrated how attackers can manipulate AI-powered email summarizers through hidden HTML prompt injections. The proof-of-concept study showed that malicious instructions embedded in invisible text can cause AI assistants like Claude Haiku 4.5 to generate false summaries, altering critical information such as invoice amounts and meeting dates. The attack succeeded in all 10 test runs, with recipients receiving no indication that the AI-generated summaries contained corrupted data. This research validates OWASP's consistent ranking of prompt injection as the top risk for LLM applications since 2023. This incident highlights the growing urgency around AI security as organizations increasingly deploy autonomous AI agents with expanded capabilities beyond simple summarization, including email sending and meeting scheduling functions that could amplify attack impact.
4 weeks ago
Kill Chain
WordlistLoader and SynkLoader Campaigns Exploit ClickFix and Microsoft Teams for Credential Theft
In August 2026, cybersecurity researchers identified two new malware families - WordlistLoader and SynkLoader - being used to deliver sophisticated payloads and potentially sell access to ransomware groups. WordlistLoader delivers Amatera Stealer through ClearFake campaigns using ClickFix social engineering techniques that trick victims into executing malicious commands disguised as CAPTCHA verification. The malware uses advanced evasion techniques including EtherHiding blockchain storage and WebDAV-based delivery, while SynkLoader is distributed via Microsoft Teams phishing campaigns to capture Windows credentials through fake lock screens. This incident highlights the evolving sophistication of infostealer campaigns that increasingly abuse legitimate infrastructure like CDNs, cloud storage, and collaboration platforms. The use of blockchain-based payload storage and hardware-breakpoint ETW bypasses demonstrates how threat actors are adapting to modern security controls, making traditional signature-based detection less effective.
1 month ago
Kill Chain
SynkLoader Malware Exploits Microsoft Teams Trust in 2026 Campaign
In July 2026, cybercriminals launched a sophisticated phishing campaign using Microsoft Teams to distribute a new malware family called SynkLoader. Attackers impersonated IT help desk personnel to trick victims into installing a fake 'PowerShell Cleaner' executable hosted on Microsoft Azure. The multi-language malware combines Python, PowerShell, C#, and C++ components to establish persistence, steal credentials through a convincing fake Windows lock screen, and create backdoor access for potential ransomware operations. The campaign demonstrates the growing abuse of trusted collaboration platforms and sophisticated social engineering tactics that bypass traditional email security measures. This incident highlights the evolving threat landscape where attackers increasingly target remote work infrastructure and exploit user trust in corporate communication tools, making traditional perimeter security insufficient against modern attack vectors.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports