Security researchers at ZeroBEC reported on July 9, 2026 the discovery of Forg365, a new Phishing-as-a-Service (PhaaS) platform that uses AI to generate phishing emails aimed at Microsoft 365 accounts. Distributed via Telegram, the service combines AI-assisted lure generation, device code phishing and Adversary-in-the-Middle (AiTM) attacks to steal OAuth tokens and session cookies, enabling account takeover. ZeroBEC began its investigation from a real phishing email, gained access to the operational panel and analyzed its internals, as reported the same day by BleepingComputer.
Continue reading
The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in✓ Signed in — this article isn’t included in your current plan.