ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
BigBear 2.0, a phishing-as-a-service framework, bypassed multi-factor authentication at 258 organizations and stole 5,137 Microsoft 365 credentials. CloudSEK researchers accessed the control panel, finding 42 VPS nodes and an Evilginx2-based adversary-in-the-middle framework that intercepts passwords and session cookies. The operation remains active, with credentials exfiltrated to at least five affiliate operators via Telegram.
Tap to vote and see what everyone thinks.
Summary by ByteBrief