Inside Mirage2FA — Reverse-Engineering
Inside Mirage2FA — Reverse-Engineering a Two-Year M365 Phishing Operation Adverse Trace OSINT · 2026-06-29 · TLP:CLEAR Campaign: AT-IR-2026-MIRAGE2FA · Activity: Jun 2024
· Artificial?
Inside Mirage2FA — Reverse-Engineering a Two-Year M365 Phishing Operation Adverse Trace OSINT · 2026-06-29 · TLP:CLEAR Campaign: AT-IR-2026-MIRAGE2FA · Activity: Jun 2024
Bluekit and the AI Impersonators: A Phishing Kit Hunt That Uncovered a Fraud Empire 26 June 2026 · FindEvil — dAIffed / Adverse Trace · Case Refs: BLUEKIT-PHA-2026-
Original inspiration for this from https://abnormal.ai/blog/eviltokens-oauth-device-codes-bec-operations EvilTokens Is Still Live: Three Months On, the PhaaS Platform Has
Let me get the bias out of the way first, because it shapes everything that follows. I don't hold much weight in threat intel.
So I started down the path of building an automated DFIR pipeline. As mentioned previously, SANS announced an AI Hackathon, and my original idea was to
Or: how I spent twelve hours building a workaround for a flag that already existed I run a four-node DGX Spark cluster for local DFIR
SANS recently announced their first hackathon for autonomous incident response — open to the community, build something that uses AI to figure out what the bad guys
I benchmarked 11 LLMs on a 69-scenario tool-calling test suite. Intel/Qwen3.6-35B-A3B-int4-AutoRound delivered the best overall result: a perfect
On 19 April 2026, Vercel disclosed a security incident. Within 48 hours, the public attack chain had resolved into something more interesting than the initial "
DORA came into force in January 2025. Financial entities across the EU are supposed to be compliant. Most aren't — at least not fully — and
So I have gotten into running my own local llm for privacy reasons, and like to use it to assist with incident response tasks and collecting
Separating the jailbreak hype from the genuine security story Today a GitHub repository appeared claiming to be a "freed" build of Anthropic's