This roundup shows how attackers are using normal-looking actions like Teams chats, file-sharing prompts, trusted software, and OAuth consent to gain access without obvious alarms. It also highlights active threats including The Gentlemen ransomware, Outsider phishing-as-a-service, Nexus ID theft, RevStealer, BlueKit, CRPx0, and abuse tied to Lenovo ID, Dropbox, Faronics Deploy, and Clerk. #MicrosoftTeams #TheGentlemen #Outsider #Nexus #RevStealer #BlueKit #CRPx0 #LenovoID #Dropbox #FaronicsDeploy #Clerk
Keypoints
- Microsoft warned of attackers using Teams to impersonate IT staff and gain remote access.
- Spring Ring used vishing and Teams accounts to target employees across multiple companies.
- The Gentlemen ransomware operation combined privilege escalation, data theft, and defense evasion.
- Outsider phishing kits kept spreading through SMS and Telegram despite takedown efforts.
- Misconfigurations, legacy links, and trusted software were repeatedly abused to steal credentials and deploy payloads.
Read More: https://thehackernews.com/2026/09/threatsday-ceo-phishing-kits-5k-dropbox.html