Threats Tagged 'saas platforms'
View all threats tagged with 'saas platforms'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'saas platforms'
Click on any threat for detailed analysis and mitigation recommendations
A widespread IT impersonation and voice-phishing campaign designated PREY-0058 is actively targeting Microsoft 365 and SaaS platforms. Threat actors impersonate IT helpdesk staff via phone or text to trick executives and senior personnel into divulging credentials through adversary-in-the-middle phishing portals. After bypassing multi-factor authentication, attackers conduct rapid automated data exfiltration across email, file storage, and cloud repositories without deploying ransomware. The operation relies heavily on NodeMaven residential proxy infrastructure to blend with legitimate traffic. Extortion demands are delivered via TOX messaging within hours of compromise, typically with 72-hour deadlines and threats of public data exposure. The campaign exhibits tradecraft overlapping with UNC6671 and involves multiple extortionware brands including BlackFile, Redact, Pink, and Helix. Join the discussion | AlienVault OTX General | 09/10/2026, 13:26:22 UTC Added: 09/10/2026, 14:07:16 UTC |
A threat campaign linked to the Scattered Lapsus$ Hunters group is targeting Zendesk users through over 40 typosquatted domains impersonating Zendesk and various organizations. These domains host phishing pages to harvest credentials. Attackers also submit fraudulent tickets to Zendesk portals to infect support staff with remote access trojans (RATs). This campaign follows similar attacks on other SaaS platforms like Salesforce, with Discord reportedly breached via its Zendesk support system. The attack leverages phishing, typosquatting, and social engineering to compromise customer service environments. Organizations are advised to implement strong authentication, monitor for typosquatted domains, and secure Zendesk chat to mitigate risks. The threat poses a medium severity risk due to its potential to compromise sensitive support operations and enable persistent access. No CVSS score is available, but the attack's impact on confidentiality and integrity, combined with ease of exploitation, warrants a medium severity rating. Join the discussion | AlienVault OTX General | 11/27/2025, 14:13:07 UTC Added: 11/27/2025, 18:38:55 UTC |
Showing 1 to 2 of 2 results