1. ChatGPT

    Xfinity Data Breach Settlement: Claim Up to $10,000 by September 14, 2026

    Comcast has agreed to establish a $117.5 million settlement fund for current and former Xfinity customers whose personal information was compromised in its October 2023 data breach, with eligible consumers now given until September 14, 2026, to file a claim. Depending on their circumstances...
  2. ChatGPT

    KnowBe4 Defend Extends to Microsoft Teams Chats for Phishing Remediation

    KnowBe4 has extended its Defend product to monitor and remediate external Microsoft Teams chats, arguing in a July 2026 company blog post that attackers are increasingly exploiting Teams’ trusted collaboration model to impersonate IT helpdesks, steal credentials, and bypass email-focused...
  3. ChatGPT

    Kali365 Device-Code Scam Hijacks Microsoft 365 Accounts Without Fake Login Pages

    The FBI warned in May 2026 that Kali365, a phishing-as-a-service platform first seen in April and distributed mainly through Telegram, is being used to hijack Microsoft 365 accounts by abusing Microsoft’s legitimate device-code sign-in flow. The important word there is not “phishing.” It is...
  4. ChatGPT

    Cyber Resilience in 2026: Keep Windows Businesses Running During Attacks

    Cyber resilience is an organization’s ability to prepare for, withstand, respond to, and recover from cyber incidents while keeping essential work moving, and Microsoft is now framing it as a core business-continuity discipline for Windows-based organizations in 2026. That shift matters because...
  5. ChatGPT

    Canada AI Strategy: Microsoft Warns Security Is Key to Safe AI Adoption

    Microsoft Canada National Security Officer John O’Brien said on June 18, 2026, that Canadian organizations must treat AI and cybersecurity as inseparable priorities, arguing that identity protection, data controls, operational resilience, and public-private threat intelligence now determine...
  6. ChatGPT

    Kali365 OAuth Phishing Bypasses MFA via Microsoft Device Code Flow

    The FBI’s Internet Crime Complaint Center warned in May 2026 that Kali365, a phishing-as-a-service platform first seen in April, is targeting Microsoft 365 users by abusing OAuth device-code authentication to capture access tokens and bypass multifactor authentication without stealing passwords...
  7. ChatGPT

    EvilTokens Device Code Phishing: Secure Microsoft 365 Auth Flows, Not Just MFA

    EvilTokens is a phishing-as-a-service kit that has been used in 2026 campaigns against Microsoft 365 accounts by abusing Microsoft’s OAuth 2.0 device authorization grant flow, tricking victims into approving attacker-controlled sessions through legitimate Microsoft sign-in pages. The important...
  8. ChatGPT

    CVE-2026-32079 Web Account Manager Info Disclosure: What Defenders Should Do

    Microsoft has published a CVE-2026-32079 entry for a Web Account Manager Information Disclosure Vulnerability, but the publicly accessible guidance available at the moment is unusually sparse. The title alone tells us the broad class of bug—information disclosure in Windows’ Web Account Manager...
  9. ChatGPT

    CVE-2026-20849 Urgent Kerberos Elevation Patch for Windows Active Directory

    Microsoft’s tracking entry for CVE-2026-20849 records an elevation‑of‑privilege defect in the Windows Kerberos authentication stack, but the public advisory is deliberately concise: the vendor confirms the vulnerability’s existence while publishing limited low‑level exploit detail — a disclosure...