Cybersecurity
Threat roundup covers Teams abuse, phishing and account theft
The Hacker News compiled a ThreatsDay edition on Teams-based intrusion campaigns, ransomware claims, phishing kits, malicious downloads, AI security warnings and a Dropbox disclosure affecting about 5,000 accounts.
- The article was a roundup of separate cyber incidents and security research items.
- Microsoft warned that attackers were using external Microsoft Teams collaboration to impersonate IT or help desk staff and gain interactive access.
- Sophos said The Gentlemen ransomware, which it tracks as Gold Sherwood, had claimed 683 victims by the end of July 2026, including 169 in July.
- The FBI was investigating Nexus, which claimed more than 153 million driving licence scans, and Dropbox said about 5,000 accounts were accessed through Lenovo ID-linked accounts without two-factor authentication.
- The article also said more than 100 companies had signed an open letter calling for stronger AI security.
The roundup opened with Microsoft's warning about a human-run intrusion campaign that used Teams links outside the victim's own organisation to pose as IT or help desk staff. Microsoft said the attackers then used remote access tools and PowerShell to install additional code, collect information and move through internal systems.
Palo Alto Networks Unit 42 said a separate operation targeted more than 150 employees at at least 10 companies between January and April 2026. Sophos said The Gentlemen ransomware had claimed 683 victims by the end of July 2026, while Group-IB said the Outsider phishing kit kept producing new pages after legal action against its operators.
ZeroBEC said BlueKit was being used to target chief executives in financial groups, and iZOOlogic described a tax-notice lure that carried a signed executable alongside an unsigned library. Intezer said a counterfeit privacy-browser download turned attacker instructions into mouse and keyboard input, and the FBI was investigating Nexus, which claimed more than 153 million driving licence scans.
The article also said more than 100 companies, including Anthropic, Google and OpenAI, had signed an open letter on AI security. It ended with Dropbox's disclosure that about 5,000 accounts were accessed last month through Lenovo ID-linked accounts that did not have two-factor authentication enabled.
Named in this story
Companies
- Microsoft
- warned about a campaign abusing Teams collaboration
- Sophos
- reported victim counts for The Gentlemen ransomware
- Group-IB
- said the Outsider kit kept producing phishing pages after takedowns
- iZOOlogic
- described a tax-notice lure carrying hidden payloads
- Intezer
- detailed a counterfeit privacy-browser campaign
- Dropbox
- disclosed access to about 5,000 accounts
- Lenovo
- was linked to the affected Dropbox accounts
- Clerk
- was said to have addressed an llms.txt issue
- Anthropic
- was among the signatories to the AI security letter
- was among the signatories to the AI security letter
- OpenAI
- was among the signatories to the AI security letter
Organisations
- Palo Alto Networks Unit 42
- described a separate Teams-based social engineering campaign
- ZeroBEC
- disclosed details of the BlueKit phishing service
- Prince of Persia
- was the Iranian hacking group whose infrastructure was analysed
Governments and agencies
- FBI
- was investigating the Nexus ID theft service
Products and systems
- Microsoft Teams
- was used for impersonation and contact with targets
- The Gentlemen
- was a ransomware operation tracked as Gold Sherwood
- Outsider
- was a phishing-as-a-service platform
- BlueKit
- was used to target chief executives for credential theft
- Nexus
- claimed to sell more than 153 million driving licence scans
How the source tells it
The piece used a breathless, alarm-forward newsletter register, with urgency and vendor-led amplification running through the whole roundup.
- alarm the opening turns ordinary interactions into threat vectors and frames the collection around hidden danger
- urgency the copy pushes the bulletin as a recurring must-follow update and stresses the pace of new threats
- hype broad claims about AI attacks becoming faster, broader and more capable are presented without measurement
- vendor boosterism multiple companies’ own characterisations of their findings are repeated as if settled fact
- speculation presented as fact future-facing predictions and worst-case outcomes are stated with certainty rather than as forecasts