Skip to main content
Security Products

Microsoft links passkey-themed phishing to ShinyHunters and Helix extortion crews

Microsoft links passkey-themed phishing to ShinyHunters and Helix extortion crews Image: Primary
Microsoft says threat actors tied to the ShinyHunters, Helix and other extortion gangs have used passkey- and single sign-on-themed social engineering since May 2026 to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. Attackers research targets, then call or message employees while impersonating IT help desks and urge urgent passkey, MFA or SSO updates. Microsoft says the lures do not enroll a passkey; they push victims to adversary-in-the-middle phishing sites or device-code authentication flows that capture credentials and session tokens. Microsoft attributes the activity to groups it tracks as Storm-3121 and Storm-3032, overlapping with Google's UNC6671 cluster.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Science
AI Science

NASA and IBM release open lunar foundation model on Hugging Face

NASA and IBM Research released the NASA-IBM Lunar Foundation Model, an open-source AI model built for lunar science, hosted publicly on Hugging Face with its codebase on GitHub. NASA said the model was trained primarily on 17 yea...

Security Policy
Security Policy

Florida confirms DMV driver database breach via stolen police credentials

The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. The agency said it learned of the bre...

Security
Security

Wiz reports Artifactory flaw chain exploited to plant Rust backdoor

Wiz says multiple threat actors chained two JFrog Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, against self-hosted servers between August 15 and September 8, 2026, obtaining an internal anonymous-user JWT and ex...

Security Infrastructure
Security Infrastructure

GitLab patches maximum-severity file-read flaw as probes hit exposed servers

GitLab released patches for a maximum-severity path traversal flaw in its repository commits API that lets an unauthenticated attacker read arbitrary files from a GitLab server under certain conditions, the company said. The vuln...