
EvilTokens: device-code phishing and more than 12,000 compromised inboxes
Microsoft details a platform abusing device-code sign-in and using AI to tailor lures and analyse compromised mailboxes.
Read the analysisSECURCHECK · CYBER NEWS
Impersonated messages, malicious links and independent checks.
A sourced overview of tax, education and training incidents, with a clear distinction between confirmed exposure and claims.

Microsoft details a platform abusing device-code sign-in and using AI to tailor lures and analyse compromised mailboxes.
Read the analysis
Brevo says a SAML SSO scoping flaw exposed access to 138 customer accounts, six used to send phishing. What the supply-chain risk means.
Read the analysis
Following an incident at email provider Brevo, Trezor reports 347,149 exported addresses and a malicious email requesting wallet recovery words.
Read the analysis
Sansec's February investigation into a compromised PrestaShop store shows a fake card form before the real checkout; AI can speed up localisation of deceptive overlays.
Read the analysisWe distinguish confirmed facts from claims and update articles when primary sources publish new information. These reports are not a real-time incident feed.