New EvilTokens Attack Exposes Browser Visibility Gap in Enterprise SOCs

2026-06-30T20:51:39Zd90a908f503a24fc917d1684540aec318d2fbdd588fb9e397f5bbce0c0cb1d8e
EvilTokensSOC-detectionVoidriftaccount-takeoverbrowser-visibility-gapdonation-scammalicious-domainsmalware-distributionphishingphishing-luresthird-party-risktoken-theft

What happened

The feed highlights multiple active threats and security trends: an "EvilTokens" phishing technique that conceals takeover indicators until malicious code runs in the browser, creating visibility gaps for enterprise SOCs and increasing account takeover risk; a personalized FIFA World Cup 2026 T-shirt phishing campaign used to distribute Voidrift malware via trusted-looking emails and sites; and a surge of newly-registered domains exploiting a Venezuela earthquake to facilitate donation scams. Other items cover third-party/agent identity security, secure office software guidance, and WhatsApp's

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
d90a908f503a24fc917d1684540aec318d2fbdd588fb9e397f5bbce0c0cb1d8e
Enrichment time
2026-06-30T20:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.