Curated Cyber Threat Intelligence
Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports
Filtered Reports
2 / 2 results
highperson_alertThreat Actorperson_alertThreat Actor
EvilTokens Ghost Phishing Campaign Targets US and European Businesses
EvilTokens is a campaign leveraging "ghost phishing" techniques to target business entities across the United States and Europe. The campaign's primary motivation appears to be credential theft and unauthorized access to Microsoft 365 environments, w…
Microsoft11:00 UTC
highperson_alertThreat Actorperson_alertThreat Actor
EvilTokens Affiliate ARToken Exposes M365 Phishing-as-a-Service Platform
EvilTokens is a threat actor operating a phishing-as-a-service (PhaaS) ecosystem targeting Microsoft 365 credentials. The group utilizes an affiliate model, with ARToken identified as one operational affiliate platform.
Microsoft12:12 UTC