Tag Signal

Microsoft Warns of Russian-Linked Hackers Using ‘Device Code Phishing’ to Compromise Accounts

February 14, 2025
Enterprise Security / Cyber Attack

Microsoft has highlighted a new threat group known as Storm-2372, linked to a series of cyberattacks that have targeted multiple sectors since August 2024. The attacks focus on government entities, NGOs, IT services, defense, telecommunications, healthcare, higher education, and the energy sector across Europe, North America, Africa, and the Middle East.

Evaluated with medium confidence to align with Russian interests, the threat actors utilize messaging platforms such as WhatsApp, Signal, and Microsoft Teams. They impersonate notable figures relevant to their targets to gain trust. The attacks employ a phishing method known as ‘device code phishing,’ which deceives users into logging into productivity applications, allowing the actors to capture the login tokens for malicious use.

Microsoft Warns of Russian-Linked Cyber Attack Group Utilizing ‘Device Code Phishing’ Tactics February 14, 2025 Enterprise Security / Cyber Attack Microsoft has issued an urgent advisory regarding a rising threat actor, designated as Storm-2372, which is reportedly linked to Russian cyber interests. Since August 2024, this group has launched a…

Read More

Microsoft Warns of Russian-Linked Hackers Using ‘Device Code Phishing’ to Compromise Accounts

February 14, 2025
Enterprise Security / Cyber Attack

Microsoft has highlighted a new threat group known as Storm-2372, linked to a series of cyberattacks that have targeted multiple sectors since August 2024. The attacks focus on government entities, NGOs, IT services, defense, telecommunications, healthcare, higher education, and the energy sector across Europe, North America, Africa, and the Middle East.

Evaluated with medium confidence to align with Russian interests, the threat actors utilize messaging platforms such as WhatsApp, Signal, and Microsoft Teams. They impersonate notable figures relevant to their targets to gain trust. The attacks employ a phishing method known as ‘device code phishing,’ which deceives users into logging into productivity applications, allowing the actors to capture the login tokens for malicious use.

AI Rubio Hoax Sheds Light on Vulnerabilities in White House Security

Artificial Intelligence & Machine Learning, Fraud Management & Cybercrime, Next-Generation Technologies & Secure Development Impersonation Hoax Exposes Security Vulnerabilities Regarding U.S. Officials Chris Riotta (@chrisriotta) • July 9, 2025 U.S. Secretary of State Marco Rubio at a press conference in Guatemala, February 5, 2025. (Image: Daniel Hernandez-Salazar/Shutterstock) A recent attempt…

Read MoreAI Rubio Hoax Sheds Light on Vulnerabilities in White House Security

College Student Expected to Plead Guilty in PowerSchool Hacking Case

Cybercrime, Data Breach Notification, Data Security Teenager Charged With Stealing K-12 Student and Faculty Data, $3 Million Extortion Mathew J. Schwartz (euroinfosec) • May 26, 2025 Image: Shutterstock A college student has been charged with extorting PowerSchool, a platform for K-12 student information systems, after allegedly stealing sensitive data from…

Read MoreCollege Student Expected to Plead Guilty in PowerSchool Hacking Case

Signal Claims Microsoft Leaves No Alternative as It Blocks Windows Recall

In recent developments surrounding Microsoft’s Recall feature, concerns have emerged regarding its potential risks to user privacy. When enabled, Recall indexes a wide array of content, including Zoom meetings, emails, personal photos, medical information, and notably, conversations on Signal. This indexing occurs not only for the user but also for…

Read MoreSignal Claims Microsoft Leaves No Alternative as It Blocks Windows Recall

DDoSecrets Incorporates 410GB of TeleMessage Breach Data into Its Index

On May 4, 2025, TeleMessage, an Israeli firm specializing in modified encrypted messaging applications such as Signal, experienced a significant data breach. This incident led to the exposure of sensitive archived messages, contact information of government officials, and backend login credentials. The breach was executed by an unidentified hacker who…

Read MoreDDoSecrets Incorporates 410GB of TeleMessage Breach Data into Its Index