Daily Reading for 2026-05-19
Daily Reading for 2026-05-19
Security
Security Risk Advisors
- 🚩 BlackFile extortion group uses vishing and AiTM techniques to compromise Microsoft 365 and Okta environments for large-scale SaaS data theft.
- Composer vulnerability leaks GitHub Actions tokens into CI logs through malformed token validation errors.
- 🚩 Tycoon2FA phishing kit now abuses Microsoft device code authentication to hijack Microsoft 365 accounts.
Microsoft Security Blog
- How Storm-2949 turned a compromised identity into a cloud-wide breach
- How to better protect your growing business in an AI-powered world