Find notable cyber news and cases, enriched with sources, timelines, and signals.

Forg365-ForgCookie alliance reshapes ransomware ecosystem operations

Threat Actor Meta
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk for organizations that rely on Microsoft identity services. The platform also pairs phishing with AI-assisted lure generation and a browser extension that helps keep access to compromised accounts. That combination lowers the cost of running custom phishing infrastructure and extends attacker persistence after the initial login theft.

Related Happenings

Kratos ecosystem shift changes threat-actor operations

Threat Actor Meta
H score39 First: 22.07.2026 02:07 Last: 22.07.2026 02:07 Sources 1

About this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...

LastPass and Bitwarden users targeted by fake-security-notice phishing campaign

Campaign
H score31 First: 14.07.2026 18:31 Last: 14.07.2026 18:31 Sources 1

About this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...

Jalisco and OmegaLord Microsoft 365 phishing kits

Malware Activity
H score27 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...

Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord

Campaign
H score37 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...

ShinyHunters-linked Salesforce intrusion campaign

Campaign
H score45 First: 14.07.2026 09:19 Last: 14.07.2026 09:19 Sources 1

About this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...

Timeline

  1. 09.07.2026 17:39 2 articles · 13d ago

    Forg365 targets Microsoft 365 accounts with AiTM and device-code phishing

    Initial Disclosure

    Forg365 is a phishing-as-a-service platform that targets Microsoft 365 accounts with adversary-in-the-middle and device-code phishing, AI-assisted lure generation, and the ForgCookie browser extension for refreshing Microsoft SSO cookies to keep access to compromised Microsoft services. The platform dashboard supports campaign creation, phishing-link management, OAuth app and SMTP profile configuration, token and cookie management, AI-generated phishing email content, and mailbox keyword monitoring.

    Show sources