Don’t trust that app!
ID: f80e4596-b83e-5085-a72f-657028d58b2b
STIX ID: report--f80e4596-b83e-5085-a72f-657028d58b2b
Feed Name: The CyberWire
Threat Score
Proofpoint researchers uncovered active campaigns in 2025 where threat actors used fake Microsoft OAuth applications and Tycoon attacker-in-the-middle phishing kits to impersonate services (Adobe, DocuSign, SharePoint), capture credentials, bypass MFA, and harvest session cookies; nearly 3,000 Microsoft 365 accounts across 900 environments were targeted. The report recommends Microsoft security changes, strengthened email/cloud/web defenses, and user education to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
