Phishing poses as big-brand job interview to steal Google accounts

2026-07-07T07:23:33Zfaaac4a2505f8b8aefdbc6fca4e4e44cdcbade1fb02b45a5a2208a8769f878bf
adobe-coldfusionai-agentartokencredential-theftcve-2026-48282etherrateviltokensgoogle-accountsllmmalwaremfa-bypassmicrosoft-365microsoft-teamsnetnutoauthphishingphishing-as-a-serviceproxy-networkransomwarevulnerability-exploitation

What happened

Multiple active campaigns and high-impact developments: a large-scale phishing operation is impersonating 30+ major brands to harvest Google account credentials via fake job interviews; new PhaaS (ARToken) and EvilTokens tooling exposes extensive Microsoft 365 phishing capabilities; ConsentFix/ClickFix OAuth attacks rapidly hijack M365 tokens and bypass MFA; attackers are using Microsoft Teams voice calls impersonating IT to deliver EtherRAT; researchers report JadePuffer ransomware automated by an LLM agent; Adobe ColdFusion vulnerability CVE-2026-48282 is being actively exploited; and Google

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
faaac4a2505f8b8aefdbc6fca4e4e44cdcbade1fb02b45a5a2208a8769f878bf
Enrichment time
2026-07-07T07:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.