Greatness PhaaS adds device code phishing to bypass MFA and steal OAuth tokens alongside AiTM and consent abuse.
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts.
The platform has been active since at least mid-2022, targeting Microsoft 365 users in the United States, Canada, the UK, Australia, and South Africa.
It evolved over the years and now targets multiple platforms, including Microsoft 365, iCloud, Yahoo, and Google Workspace.
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories.
Xcode is the official software development kit (SDK) for creating, testing, and publishing software for all Apple’s platforms.
After months of inactivity, XCSSET has resurfaced with an updated version, v40, that features enhanced evasion techniques and introduces two new components, researchers have found.
Artificial intelligence, quantum computing and nanotechnology are converging to reshape innovation — and organizations that understand how to harness them could gain a competitive edge.
That’s according to Chuck Brooks, president of Brooks Consulting International and one of Executive Mosaic’s GovCon Experts, in a recent piece exploring how the technologies are transforming research and development while accelerating advances in healthcare, cybersecurity, defense and other industries.
Brooks highlights AI’s role in accelerating R&D, nanotechnology’s potential in wearables and sensors, and quantum computing’s ability to solve complex problems beyond the reach of classical computers.
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments.
One of the packages in question is “lib-mtop,” an unscoped package with the same name as a private Alibaba package under the “@ali” scope. Although the npm package was first published sometime in November 2023 with no functionality, three new versions (v1.0.1, v1.0.2, and v1.0.3) were uploaded earlier this March and April.
It’s currently not clear if this was the result of a maintainer account takeover or the project developer opting to go rogue. Regardless of how the malicious changes were pushed, the newly added changes feature a loader that’s designed to fetch a remote JavaScript payload using curl and then execute it.
INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1,000 series VPN appliances.
In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per statistics listed on Ransomware. Live, the group has claimed 885 victims to date, with the most recent victim listed on August 2, 2026.
The attacks are suspected to involve the exploitation of CVE-2026–15409 and CVE-2026–15410, which could be chained to facilitate arbitrary command execution and take over susceptible devices. Fixes for the vulnerability pair were released by SonicWall in mid-July 2026.
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29.
The activity was previously disclosed in a report from cybersecurity company ReliaQuest, which detailed how the attacker changed DNS settings on Wi-Fi devices to steal Microsoft 365 accounts.
Besides attributing the campaign to Russian hackers tracked as Storm-2945 — a sub-cluster of Midnight Blizzard, Microsoft identified two malware families called CornFlake and ChocoShell with capabilities for persistent access, credential theft, surveillance, and data exfiltration.
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager’s synced passkeys to take over accounts, bypass user verification, and extract passkey private keys.
Passkeys are a passwordless authentication method that uses cryptographic keys stored on a user’s device to sign in to online accounts.
They are considered safer than passwords because they cannot be guessed, reused, or easily stolen through phishing, while also allowing users to authenticate with a PIN or biometrics, such as a fingerprint or facial recognition.
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.
SOCRadar’s Threat Research Unit says DOUBLECUP has operated since early June 2026, providing customers with licenses and a Go-based Windows tool for creating malicious campaigns and generating the code operators add to their websites.
The service handles much of the infrastructure required to conduct the attacks, including hosting the steganographic PNG images, managing session and signal endpoints, providing encryption keys, and automatically rebuilding payloads.