skip to content
The Weighted Average

Wire

Microsoft disrupts EvilTokens phishing service

Microsoft says the EvilTokens phishing service compromised more than 12,000 inboxes across over 10,000 organizations before its disruption. Microsoft’s investigation describes an AI-assisted platform and the scale of exposure; SpyCloud’s disruption report independently documents the campaign without turning the note into an attack recipe. Builders should audit device-code authentication, inbox-compromise signals, and third-party identity access before agentic workflows inherit the same trust; OpenAI’s sandbox-escape evidence shows why agent permissions need an explicit blast-radius budget.