#Proofpoint
6 stories taggedProofpoint.

Four Million Fake App IDs, One Blind Spot: How Hackers Are Slipping Past Microsoft Login Defences
Two criminal campaigns sent over four million spoofed application identities at Microsoft's sign-in system and barely triggered an alert. Here is what happened, who is at risk, and what security teams can do.

Fake COLDCARD 'Security Audit' Emails Push Remote Access Tool After $88M Bitcoin Theft
A phishing campaign impersonates the hardware wallet maker, tricks owners into installing ScreenConnect, and hands attackers full control of the victim's PC.

Russian hackers used an Outlook Web Access flaw to plant hidden backdoor in mailboxes
Proofpoint says Laundry Bear, tracked as TA488, exploited a zero-day in Microsoft's webmail to install OWAReaper, a stealthy tool that survives password resets and credential rotations.

Cruciferra: The Malware-Hiding Service Fuelling Attacks on Indian Taxpayers
A China-linked group is paying for a tool called Cruciferra to smuggle remote-access malware onto Windows machines, with fake income tax emails as the entry point.

China-linked hackers hit university email servers to spy on physics and defence researchers
Proofpoint says a group it calls UNK_MassTraction is chaining two Roundcube flaws at U.S. and Canadian universities to steal logins and plant backdoors.

TA558 Is Back, Targeting Hotels and Airlines With Fake Booking Emails
A criminal group that has quietly stolen travel-industry data since 2018 has dramatically ramped up its fake-reservation campaigns, now using compressed file tricks to sneak spying software onto victims' computers.