โŒ

Reading view

There are new articles available, click to refresh the page.

The Ghost in the Machine: How a Multi-Stage Phishing Campaign Evades Security to Steal Microsoft 365 Credentials

Lead Analysts: Jeewan Singh Jalal, Prabhakaran Ravichandhiran and Anand Bodke

Since November 3, 2025, KnowBe4 Threat Labs has been monitoring a highly sophisticated, multi-stage phishing operation that is actively targeting organizations to steal employeesโ€™ Microsoft 365 credentials. The campaign has been engineered to bypass traditional email security defenses, such as secure email gateways (SEGs),ย  and multi-factor authentication (MFA) tools.

Scammers Are Exploiting the Holiday Shopping Season

Users should be particularly wary of holiday-themed scams over the next few weeks, according to researchers at Malwarebytes.

โ€œMobile-first shopping has become second nature, and during the holidays, itโ€™s faster and more frantic than ever,โ€ Malwarebytes says. โ€œFifty-five percent of people get a scam text message weekly, while 27% are targeted daily.

Blurred Chats, Bigger Risks

Think about your digital spaces. Youโ€™ve got your corporate email, which we all treat a bit like a high-security bank vault. We approach it with caution, we're suspicious of unfamiliar senders, and weโ€™re primed to spot a dodgy attachment. Then, you have WhatsApp. Thatโ€™s the digital equivalent of your living room. Itโ€™s comfy, familiar, and filled with people you (mostly) trust. Our guard is down.

โŒ