Sam's News — email-security — 2026-08-11¶
Email Security¶
8 Widespread AitM Phishing Campaign Hijacks Microsoft 365 Accounts to Steal Payroll Data¶
Cybersecurity researchers have identified an active, large-scale phishing campaign using adversary-in-the-middle (AitM) techniques to compromise Microsoft 365 accounts across multiple sectors. The attackers use voicemail-themed emails and residential proxies to capture credentials and MFA codes, then harvest payroll and finance-related emails from compromised accounts.
- Hundreds of organizations targeted across healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe
- Campaign uses six-stage redirection chain through Google, Google Meet, Google Ads, and Amazon S3 to bypass email filters
- Attackers employ residential proxies to mask malicious sign-ins as ordinary consumer traffic and maintain compromised sessions every ~8 hours
- Activity shares tactical overlaps with Microsoft-tracked Payroll Pirate (Storm-2755) and Storm-2657 threat clusters dating to early 2025
- Phishing pages fingerprint victim browsers and systems, capturing OS, browser, timezone, and WebDriver status before redirecting to AitM infrastructure
Sources: The Hacker News AI Web Searched
Security¶
6.5 New phishing attack exploits SSL/TLS certificates to target premium brand customers via WhatsApp¶
Attackers are exploiting SSL/TLS certificate legitimacy to launch phishing campaigns targeting customers of high-value brands via WhatsApp.
Sources: CyberSecurityNews RSS