New EvilTokens Attack Exposes Browser Visibility Gap in Enterprise SOCs
2026-06-30T20:51:39Z•d90a908f503a24fc917d1684540aec318d2fbdd588fb9e397f5bbce0c0cb1d8e
EvilTokensSOC-detectionVoidriftaccount-takeoverbrowser-visibility-gapdonation-scammalicious-domainsmalware-distributionphishingphishing-luresthird-party-risktoken-theft
What happened
The feed highlights multiple active threats and security trends: an "EvilTokens" phishing technique that conceals takeover indicators until malicious code runs in the browser, creating visibility gaps for enterprise SOCs and increasing account takeover risk; a personalized FIFA World Cup 2026 T-shirt phishing campaign used to distribute Voidrift malware via trusted-looking emails and sites; and a surge of newly-registered domains exploiting a Venezuela earthquake to facilitate donation scams. Other items cover third-party/agent identity security, secure office software guidance, and WhatsApp's
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- d90a908f503a24fc917d1684540aec318d2fbdd588fb9e397f5bbce0c0cb1d8e
- Enrichment time
- 2026-06-30T20:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.