CloudSEK took administrator access to the panel and counted 5,137 stolen records coming off 42 VPS nodes into five leasing affiliates' Telegram bots, with the phishing pages dark for three weeks while the panel itself stays reachable.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 60%
- Investor
- Investor 10%
Reality
- Evidence55
- Adoption30
- Hype gap+25
- Incentives40
- Confidence60
The FBI says a subscription kit sold on Telegram harvests Microsoft 365 OAuth tokens through device code lures. The mitigation it recommends is a tenant-wide block, and somebody has to decide the exceptions.
Publishers:fbi.gov
Reality
- Evidence65
- Adoption35
- Hype gap−10
- Incentives25
- Confidence60
Microsoft's researchers describe a device code phishing campaign that minted fresh codes the moment a target clicked, defeating the expiry that used to hold these attacks down. The flow it abuses is only needed by hardware that cannot show a login page.
Reality
- Evidence55
- Adoption45
- Hype gap+20
- Incentives65
- Confidence60
Fast Company's roundup of four working email scams includes three that never show a link worth hovering over, which leaves both the awareness module and the mobile device policy answering a question users no longer face.
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+25
- Incentives25
- Confidence50
Google's threat intel group ties UNC6293, UNC7005 and UNC5976 to attacks on OAuth consent, app passwords, device codes and WhatsApp linking. The login succeeds; the token leaves anyway.
Reality
- Evidence64
- Adoption58
- Hype gap+14
- Incentives57
- Confidence55
Okta Threat Intelligence says as-a-service phishing kits now let a caller change what the target sees in real time, synced to genuine MFA prompts. Push and OTP were not built to survive that.
Publishers:okta.com
Reality
- Evidence46
- Adoption28
- Hype gap+22
- Incentives78
- Confidence44