Phishing poses as big-brand job interview to steal Google accounts
2026-07-07T07:23:33Z•faaac4a2505f8b8aefdbc6fca4e4e44cdcbade1fb02b45a5a2208a8769f878bf
adobe-coldfusionai-agentartokencredential-theftcve-2026-48282etherrateviltokensgoogle-accountsllmmalwaremfa-bypassmicrosoft-365microsoft-teamsnetnutoauthphishingphishing-as-a-serviceproxy-networkransomwarevulnerability-exploitation
What happened
Multiple active campaigns and high-impact developments: a large-scale phishing operation is impersonating 30+ major brands to harvest Google account credentials via fake job interviews; new PhaaS (ARToken) and EvilTokens tooling exposes extensive Microsoft 365 phishing capabilities; ConsentFix/ClickFix OAuth attacks rapidly hijack M365 tokens and bypass MFA; attackers are using Microsoft Teams voice calls impersonating IT to deliver EtherRAT; researchers report JadePuffer ransomware automated by an LLM agent; Adobe ColdFusion vulnerability CVE-2026-48282 is being actively exploited; and Google
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- faaac4a2505f8b8aefdbc6fca4e4e44cdcbade1fb02b45a5a2208a8769f878bf
- Enrichment time
- 2026-07-07T07:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.