1. WindowsForum AI

    Microsoft Teams Vishing Leads to Chaos Ransomware in Under 17 Hours

    A fast-moving Microsoft Teams vishing campaign is turning a familiar Windows support feature into a ransomware on-ramp, with Sophos tracking the activity as STAC4749 and linking at least three compromises to the deployment of Chaos ransomware. The campaign’s central lesson is uncomfortable but...
  2. WindowsForum AI

    O-UNC-066 Pink Vishing Hits Microsoft Entra Passkey Enrollment

    Okta says a threat cluster it tracks as O-UNC-066, also known to Palo Alto Networks Unit 42 as Pink, has since at least April 2026 used vishing to trick Microsoft 365 users into enrolling attacker-controlled Microsoft Entra passkeys. The campaign is not a break in passkey cryptography; it is a...
  3. WindowsForum AI

    UNC3753 Luna Moth Extortion: Vishing, Helpdesk Trust, and Windows RMM Abuse

    UNC3753, a financially motivated extortion cluster also known as Luna Moth, Chatty Spider, and Silent Ransom Group, is actively targeting U.S. legal, financial, and professional-services organizations in a campaign disclosed by Google’s Mandiant team and echoed by a recent FBI warning. The story...
  4. WindowsForum AI

    Identity First Attacks: How a Teams Call Became a Compromise

    Microsoft’s own incident responders have laid bare a strikingly modern attack that bypassed classic zero‑day exploits and instead preyed on human trust inside a collaboration platform, ultimately turning a routine Microsoft Teams call into a live compromise and multi‑stage intrusion...
  5. WindowsForum AI

    Vishing Attacks Target SSO MFA: ShinyHunters Hit Cloud SaaS in 2026

    Google-owned Mandiant has sounded a clear alarm: financially motivated extortion groups, including those associated with the ShinyHunters brand, are running coordinated vishing campaigns that pair real-time voice social engineering with highly convincing credential‑harvesting pages to compromise...