Skip to content

Sam's News — email-security — 2026-08-10

TL;DR

Security

Payroll Pirates AiTM phishing campaign hijacks Microsoft 365 sessions

Threat actors deployed a widespread phishing campaign called 'Payroll Pirates' using account-in-the-middle techniques to compromise Microsoft 365 accounts and extract payroll and HR emails using residential proxies and the Microsoft Graph API to bypass multi-factor authentication.

  • Campaign targets Microsoft 365 credentials via AiTM phishing
  • Attackers use residential proxies to conceal payroll email collection
  • Microsoft Graph API leveraged to search and extract HR communications
  • Targets healthcare, education, and manufacturing sectors
  • Session tokens harvested to bypass multi-factor authentication

Sources: Arctic Wolf Web Search, The Hacker News Web Search, CyberSecurityNews RSS

Cisco Email Threat Defense achieves FedRAMP High certification

Cisco's Email Threat Defense service obtains FedRAMP Class D (High) certification for government use.

Sources: Cisco Blogs RSS