AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

15:03 · July 13, 2026 · Hacker News AI Section

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts. Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing

Summary

A new phishing-as-a-service platform called Forg365 targets Microsoft 365 accounts through device-code flows and adversary-in-the-middle interception. Operators subscribe via Telegram for $400 per month or $3,800 annually and receive access to a control panel at logfriend[.]com that handles lure generation, campaign delivery, token storage, and post-compromise mailbox management. The service combines legitimate delivery channels such as Amazon SES and Twilio SendGrid with SVG-based redirects and antibot logic that serves benign content when a VPN is detected.

Device-code phishing presents a Microsoft-branded verification page that initiates a genuine authentication-broker session; once the victim completes the flow, the resulting token authorizes an attacker-controlled session. Adversary-in-the-middle capabilities rely on route tokens and session cookies to classify traffic and maintain persistence. A companion Chromium extension, ForgCookie, automatically refreshes single-sign-on cookies for Microsoft services, extending access beyond initial token capture.

The platform also supplies AI-assisted tools for crafting initial lures and for drafting replies to specific email threads once an account is compromised. Keyword monitoring inside captured mailboxes further automates follow-on activity. These features mirror earlier kits such as Kali365 and Sneaky 2FA, illustrating the continued industrialization of phishing operations that bundle infrastructure, evasion, and post-exploitation under a single subscription.

Defensive measures include disabling device-code authentication where it is not required, reviewing mailbox artifacts after any device-code sign-in events, auditing mail-flow rules, and removing legacy forwarding aliases that no longer map to active users. One observed campaign succeeded because an outdated pre-acquisition namespace still forwarded mail into an active inbox, bypassing external filters without visible indicators to the recipient.

Why it matters

This article highlights the weaponization of AI by cybercriminals to scale and enhance phishing attacks against widely used enterprise platforms like Microsoft 365. It provides actionable threat intelligence and mitigation strategies crucial for Dutch security professionals defending corporate networks against AI-augmented threats.

More in this beat
Forg365identity-governanceincident-response-playbooksmicrosoftMicrosoft 365phishingthreat-and-vulnerability-updates
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

19:46 · June 30, 2026

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

This article is highly relevant for security and privacy professionals as it exposes a novel attack vector against AI agents that bypasses traditional security alarms. Understanding this vulnerability is crucial for Dutch enterprises to secure their AI deployments and prevent data breaches that could violate GDPR.

Relevance 90 · Audience 95

AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload

15:19 · June 8, 2026

AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload

This article is highly relevant for security professionals as it highlights a critical, AI-driven threat vector that directly impacts SOC efficiency and enterprise security. Dutch organizations must adapt their defensive strategies to handle the increased volume and sophistication of AI-generated phishing attacks.

Relevance 85 · Audience 95

Phishing 3.0: The Fight Moves to Agent Versus Agent

13:30 · August 19, 2026

Phishing 3.0: The Fight Moves to Agent Versus Agent

This article is highly relevant for security professionals as it highlights the emerging threat of AI-driven phishing agents. Dutch enterprises must adapt their cybersecurity strategies to counter AI-generated attacks, making this crucial for maintaining robust organizational security.

Relevance 85 · Audience 95

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

18:47 · August 11, 2026

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

This article demonstrates the practical application of AI agents in discovering complex vulnerability chains in widely used enterprise software. It provides crucial insights into how AI is accelerating offensive security capabilities, which Dutch enterprises must understand to defend against increasingly sophisticated cyberattacks.

Relevance 85 · Audience 95

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

13:30 · August 6, 2026

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

Directly addresses AI security risks from prompt injection and memory poisoning with actionable guidance for professionals. Applicable to Dutch/EU teams using commercial AI tools, aligning with GDPR and AI Act compliance needs. Provides concrete detection patterns and policy recommendations.

Relevance 85 · Audience 90

Mythos Asks the Right Question. It Doesn't Answer It.

14:15 · July 29, 2026

Mythos Asks the Right Question. It Doesn't Answer It.

It highlights how AI accelerates offensive security capabilities, necessitating a shift to dynamic, context-aware vulnerability management. Security professionals in the Netherlands can apply these architectural insights to defend against AI-driven threats.

Relevance 75 · Audience 90

IBM and Red Hat Move Project Lightwell to Commercial Launch, Warning AI Security Risks are a “Wake Up Call” for CX Leaders

18:23 · July 13, 2026

IBM and Red Hat Move Project Lightwell to Commercial Launch, Warning AI Security Risks are a “Wake Up Call” for CX Leaders

This article is highly relevant for security professionals as it highlights a critical shift in the threat landscape where AI accelerates both attacks and remediation. It offers actionable insights into managing technical debt and introduces a major new enterprise tool for securing open-source dependencies, which is vital for Dutch organizations deploying AI.

Relevance 85 · Audience 95

Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

13:02 · July 13, 2026

Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

This article is highly relevant for security professionals as it demonstrates how threat actors are actively using LLMs to generate aggressive reconnaissance scripts and accelerate cloud attacks. It highlights that while AI may not create novel zero-days, it significantly lowers the barrier to entry and increases the speed of intrusions, requiring enterprises to adapt their detection and response strategies.

Relevance 85 · Audience 95