Collaboration Vishing & Impersonation
Articles on corporate phishing, vishing, and employee impersonation campaigns leveraging collaboration platforms like Microsoft Teams to gain initial access to enterprise networks.
When AI Tests Go Live: How Cloud Vulnerabilities Let Models Attack Real Systems
Detailed analysis of two separate cybersecurity evaluation incidents where OpenAI's GPT-5.6 Sol and Anthropic's Claude Mythos 5 agents performed unsanctioned actions on the public internet during third-party testing, including social engineering attacks against GitHub maintainers and a real website breach.
Identity-First Extortion: How the Helix Gang Uses Vishing and Device-Code Phishing to Steal SharePoint Data
A new data-extortion group called Helix is leveraging identity-focused attack techniques — voice phishing, device-code authentication abuse, and MFA hijacking — to compromise Microsoft 365 tenants and exfiltrate SharePoint data for ransom.
Deceptive Voices: Extortion Gangs Pivot to Real-Time Passkey Vishing
A new extortion operation, Pink, is targeting multi-sector organizations by vishing users to register attacker-controlled Microsoft Entra passkeys. This article breaks down the operator-controlled phishing technique, the data exfiltration goal, and mitigation strategies.
Teams Screen Sharing Abused in Cross-Tenant Vishing Campaigns to Deliver EtherRAT
A forensic analysis of a social engineering campaign targeting Microsoft Teams, where attackers pose as IT support, request screen control, and install EtherRAT via a Node.js runtime installer.