Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cybersecurity professionals report persistent password reliance and rising AI-driven phishing and deepfake targeting

Trend
First reported
Last updated
Happening score
H score 39
1 unique sources, 1 articles

Summary

Hide ▲

Survey data from 2,000 cybersecurity professionals shows persistent reliance on usernames and passwords alongside a rise in AI-driven phishing and deepfake impersonation, increasing compromise risk across organizations. 44% said their organization faced at least one AI-driven phishing attack in the past year, and 43% reported suspicious deepfake-style impersonations aimed at executives or clients. The pattern shows a widening gap between awareness of stronger authentication and the controls actually in use.

Related Happenings

TA419 AI policy impersonation phishing campaign

Campaign
H score36 First: 01.10.2026 17:00 Last: 01.10.2026 17:00 Sources 1

About this happening: TA419 is a China-nexus espionage campaign that used credential phishing against AI policy experts at U.S. think tanks, universities, and legal sector organizatio...

Kali365 Microsoft 365 device-code phishing campaign

Campaign
H score46 First: 25.05.2026 15:45 Last: 25.05.2026 15:45 Sources 1

About this happening: A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...

Latest development: 05.08.2026 14:43

Kali365 uses device-code phishing to target US organizations, presenting lures that impersonate SharePoint, OneDrive, or DocuSign before redirecting victims to Microsoft's legitimate device login portal for attacker-provided codes; successful approvals can yield access and refresh tokens with continued access to Microsoft 365 email, documents, and cloud resources, and ANY.RUN telemetry records more than 80 public sessions linked to the campaign each week.

Healthcare breach trend shifts toward AI-assisted social engineering in 2025

Trend
H score39 First: 22.05.2026 16:17 Last: 22.05.2026 16:17 Sources 1

About this happening: Healthcare organizations faced a sharp rise in social engineering and pretexting in 2025, making identity abuse a dominant breach pattern. Verizon Business’ 2026...

Healthcare phishing defense guidance for VPN MFA and continuous training

Defensive Guidance
H score16 First: 22.05.2026 16:17 Last: 22.05.2026 16:17 Sources 1

About this happening: Healthcare defenders were urged to treat phishing as a top priority, which matters because social engineering is a direct path to credential abuse in clinical environments...

Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations

Threat Actor Meta
H score82 First: 05.03.2026 08:51 Last: 05.03.2026 08:51 Sources 1

About this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...

Latest development: 17.05.2026 17:43

eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.

Timeline

  1. 07.10.2026 13:15 2 articles · 1h ago

    Survey finds cybersecurity professionals still rely on passwords as AI-driven phishing rises

    Initial Disclosure

    A Yubico and Okta survey published on October 7 found that many cybersecurity professionals still use usernames and passwords for personal and work accounts, while hardware-backed passkeys remain far less common than password-based methods. The findings also show fragmented authentication across internal applications, incomplete MFA coverage, and continued use of one-time mobile passcodes and SMS-based authentication, alongside reported growth in AI-driven phishing and deepfake impersonation targeting organizations, executives, and clients.

    Show sources