logo

Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace

ID: ea31bd31-0967-5d3c-9151-2172eee5b77b

STIX ID: report--ea31bd31-0967-5d3c-9151-2172eee5b77b

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Dhivya

...
...

Since October 2025, researchers have tracked two adversary groups (CORDIAL SPIDER and SNARKY SPIDER) conducting high-speed data theft from trusted SaaS environments by using vishing to deliver AiTM SSO phishing, stealing session tokens, manipulating MFA, and rapidly exfiltrating sensitive documents via anonymization services; these campaigns emphasize IdP abuse and visibility gaps in SaaS security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.