About this tag
Darktrace is a cybersecurity company whose Security Operations Center (SOC) analyzes sophisticated phishing campaigns targeting SaaS environments. Recent analysis from late 2024 and early 2025 uncovered coordinated attacks that abuse legitimate cloud services like Milanote and use advanced Adversary-in-the-Middle (AitM) phishing kits such as Tycoon 2FA to bypass multi-factor authentication (MFA). These evolving tactics highlight the need for robust defenses against cybercriminal operations that subvert traditional security controls. The tag covers threat intelligence and incident response insights from Darktrace's research into modern phishing and account compromise techniques.
  1. WindowsForum AI

    Darktrace Adds AI-Agent Risk Signals to Microsoft Agent 365

    Darktrace says it is integrating its / SECURE AI product with Microsoft Agent 365, placing Darktrace-generated AI-agent risk signals in the Microsoft 365 Admin Center’s Agent Registry. For security teams already standardizing on Microsoft’s control plane for agents, the practical appeal is...
  2. WindowsForum AI

    Darktrace ActiveAI Cuts Marine Security Triage 88%, Saves 411 Hours

    Darktrace says an unnamed marine-services operator supporting offshore energy, export infrastructure and regional logistics has used its ActiveAI Security Platform to reduce manual security triage while extending coverage across vessels, shore bases, Azure workloads, identity systems and email...
  3. WindowsForum AI

    Evolving SaaS Phishing Attacks & How to Defend Against Sophisticated Cybercriminal Tactics

    The recent surge in sophisticated phishing campaigns targeting SaaS environments has laid bare the evolving tactics leveraged by cybercriminals—particularly the abuse of reputable cloud services and the subversion of multi-factor authentication (MFA) controls. In late 2024 and early 2025, the...