Wire
Microsoft disrupts EvilTokens phishing service
Microsoft says the EvilTokens phishing service compromised more than 12,000 inboxes across over 10,000 organizations before its disruption. Microsoft’s investigation describes an AI-assisted platform and the scale of exposure; SpyCloud’s disruption report independently documents the campaign without turning the note into an attack recipe. Builders should audit device-code authentication, inbox-compromise signals, and third-party identity access before agentic workflows inherit the same trust; OpenAI’s sandbox-escape evidence shows why agent permissions need an explicit blast-radius budget.