ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

Threat roundup covers Teams abuse, phishing and account theft

The Hacker News compiled a ThreatsDay edition on Teams-based intrusion campaigns, ransomware claims, phishing kits, malicious downloads, AI security warnings and a Dropbox disclosure affecting about 5,000 accounts.

The Hacker News

The roundup opened with Microsoft's warning about a human-run intrusion campaign that used Teams links outside the victim's own organisation to pose as IT or help desk staff. Microsoft said the attackers then used remote access tools and PowerShell to install additional code, collect information and move through internal systems.

Palo Alto Networks Unit 42 said a separate operation targeted more than 150 employees at at least 10 companies between January and April 2026. Sophos said The Gentlemen ransomware had claimed 683 victims by the end of July 2026, while Group-IB said the Outsider phishing kit kept producing new pages after legal action against its operators.

ZeroBEC said BlueKit was being used to target chief executives in financial groups, and iZOOlogic described a tax-notice lure that carried a signed executable alongside an unsigned library. Intezer said a counterfeit privacy-browser download turned attacker instructions into mouse and keyboard input, and the FBI was investigating Nexus, which claimed more than 153 million driving licence scans.

The article also said more than 100 companies, including Anthropic, Google and OpenAI, had signed an open letter on AI security. It ended with Dropbox's disclosure that about 5,000 accounts were accessed last month through Lenovo ID-linked accounts that did not have two-factor authentication enabled.

Named in this story

Companies

Microsoft
warned about a campaign abusing Teams collaboration
Sophos
reported victim counts for The Gentlemen ransomware
Group-IB
said the Outsider kit kept producing phishing pages after takedowns
iZOOlogic
described a tax-notice lure carrying hidden payloads
Intezer
detailed a counterfeit privacy-browser campaign
Dropbox
disclosed access to about 5,000 accounts
Lenovo
was linked to the affected Dropbox accounts
Clerk
was said to have addressed an llms.txt issue
Anthropic
was among the signatories to the AI security letter
Google
was among the signatories to the AI security letter
OpenAI
was among the signatories to the AI security letter

Organisations

Palo Alto Networks Unit 42
described a separate Teams-based social engineering campaign
ZeroBEC
disclosed details of the BlueKit phishing service
Prince of Persia
was the Iranian hacking group whose infrastructure was analysed

Governments and agencies

FBI
was investigating the Nexus ID theft service

Products and systems

Microsoft Teams
was used for impersonation and contact with targets
The Gentlemen
was a ransomware operation tracked as Gold Sherwood
Outsider
was a phishing-as-a-service platform
BlueKit
was used to target chief executives for credential theft
Nexus
claimed to sell more than 153 million driving licence scans

How the source tells it

The piece used a breathless, alarm-forward newsletter register, with urgency and vendor-led amplification running through the whole roundup.

  • alarm the opening turns ordinary interactions into threat vectors and frames the collection around hidden danger
  • urgency the copy pushes the bulletin as a recurring must-follow update and stresses the pace of new threats
  • hype broad claims about AI attacks becoming faster, broader and more capable are presented without measurement
  • vendor boosterism multiple companies’ own characterisations of their findings are repeated as if settled fact
  • speculation presented as fact future-facing predictions and worst-case outcomes are stated with certainty rather than as forecasts