Follow the latest coverage, related explainers and connected technology stories.
Microsoft revealed that the phishing-as-a-service platform EvilTokens enabled AI-supported attacks and affected more than 12,000 mailboxes across more than 10,000 organizations. The platform was used to exploit the device code authentication flow and steal access tokens, before Microsoft’s Digital Crimes Unit coordinated an operation to disrupt the infrastructure associated with it.
Anthropic warned Claude users about information-stealing malware that hijacks login sessions and uses them to consume Claude Code quotas. Reported cases reveal that the absence of a detailed usage log can delay the detection of abuse and complicate account recovery.