Find notable cyber news and cases, enriched with sources, timelines, and signals.

AI-driven phishing and public-facing application exploitation rise across Microsoft telemetry incidents

Trend
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

Microsoft Digital Defense Report 2026 shows AI is speeding attacks up and shifting initial access patterns across observed incidents, increasing defender pressure. Phishing rose from 7% of incidents in 2025 to 23% in 2026, while public-facing application exploitation also climbed. The same period saw post-compromise activity such as credential discovery, data exfiltration, and lateral movement compress from days to minutes.

Related Happenings

Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026

Trend
H score30 First: 28.07.2026 16:00 Last: 28.07.2026 16:00 Sources 1

About this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...

Kali365 Microsoft 365 device-code phishing campaign

Campaign
H score46 First: 25.05.2026 15:45 Last: 25.05.2026 15:45 Sources 1

About this happening: A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...

Latest development: 05.08.2026 14:43

Kali365 uses device-code phishing to target US organizations, presenting lures that impersonate SharePoint, OneDrive, or DocuSign before redirecting victims to Microsoft's legitimate device login portal for attacker-provided codes; successful approvals can yield access and refresh tokens with continued access to Microsoft 365 email, documents, and cloud resources, and ANY.RUN telemetry records more than 80 public sessions linked to the campaign each week.

EvilTokens Microsoft 365 consent phishing campaign

Campaign
H score39 First: 19.05.2026 14:30 Last: 19.05.2026 14:30 Sources 1

About this happening: The EvilTokens campaign is a Microsoft 365 device-code phishing PhaaS that began in February 2026 and abused microsoft.com/devicelogin to steal authentication...

Latest development: 22.09.2026 18:00

Microsoft coordinated with Health-ISAC, law enforcement, and SpyCloud to seize active EvilTokens infrastructure, disrupting the phishing service after it compromised more than 12,000 Microsoft accounts across over 10,000 organizations. The Metropolitan Police Service also arrested two suspected EvilTokens administrators in the U.K. after executing warrants at addresses in Canary Wharf and Nine Elms.

Code of conduct-themed Microsoft AiTM phishing campaign

Campaign
H score53 First: 05.05.2026 09:35 Last: 05.05.2026 09:35 Sources 1

About this happening: A large-scale phishing campaign used code of conduct-themed lures and legitimate email services to push victims to attacker-controlled domains and steal authentication t...

Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations

Threat Actor Meta
H score82 First: 05.03.2026 08:51 Last: 05.03.2026 08:51 Sources 1

About this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...

Latest development: 17.05.2026 17:43

eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.

Timeline

  1. 02.10.2026 17:15 2 articles · 2h ago

    AI-driven phishing and public-facing application exploitation rise across Microsoft telemetry incidents

    Initial Disclosure

    By 2026, observed attacks had shifted toward AI-assisted entry and faster post-compromise movement, with phishing and public-facing application exploitation both rising sharply. The earliest attack stages changed the most, reducing the time defenders have to detect and contain compromise.

    Show sources