Sam's News โ email-security โ 2026-09-08¶
Security¶
8 BigBear 2.0 phishing campaign bypasses Microsoft 365 MFA via session cookie theft¶
The BigBear 2.0 phishing campaign uses Evilginx2 to bypass Microsoft 365 multi-factor authentication by stealing session cookies.
Sources: CyberSecurityNews RSS, Computerworld RSS, Infosecurity Magazine RSS
8 Phishing campaign targets 99% of US military bases amid US-Iran tensions¶
A widespread phishing campaign has targeted nearly all US military bases during escalating US-Iran tensions.
Sources: The Defense Post RSS
7 Microsoft 365 Users Targeted by Dual Threat Campaign: Fake IT Calls and Phishing¶
Microsoft 365 users globally are being attacked through coordinated phishing emails and fraudulent IT support calls.
Sources: TechRadar RSS
6.5 NordVPN uncovers global phishing campaign impersonating 75+ brands targeting corporate accounts¶
NordVPN researchers discovered a coordinated phishing operation impersonating over 75 major brands to compromise business email accounts.
Sources: Cybernews RSS
6.5 Trezor Customers Targeted by Phishing Following Shipping Partner Data Breach¶
Cryptocurrency hardware wallet company Trezor's customers receive phishing calls and mail after a breach at a shipping partner exposed their information.
Sources: helpnetsecurity.com RSS
6 Microsoft warns of phishing attacks exploiting hidden text within document formatting¶
Microsoft identified a phishing campaign using concealed text embedded within document Word formatting to evade detection.
Sources: hi-Tech.ua RSS Update to: Microsoft Discovers ASCII Smuggling Used in Phishing Campaign
4.5 Proofpoint appoints new Chief Legal Officer and Chief People Officer¶
Cybersecurity firm Proofpoint announced the appointment of a Chief Legal Officer and Chief People Officer to strengthen its executive leadership.
Sources: Proofpoint โ Threat Insight RSS