Cybersecurity threats are real. Stay informed.
A public bulletin from FBM Security Intelligence. Real incidents. Verified sources. Plain language. Updated with the latest global threat intelligence.
Global Advisory
Device code phishing is active. Never enter a code at microsoft.com/devicelogin unless you started the sign-in yourself. Asked for a code by an email or document? Stop and report it.
Global threat level
May 2026- Credential stuffingCritical91%
- MFA bypassCritical84%
- PhishingHigh78%
- RansomwareHigh65%
- Social engineeringMedium58%
Based on NCSC, CISA, Europol, and Verizon DBIR 2025. Updated monthly.
- 26BCredential stuffing attempts/monthFortinet 2025
- 1.3BPasswords in the Synthient breachHIBP Nov 2025
- 246 daysAvg. time to detect a breachIBM Cost of a Breach 2025
- 80%MFA bypasses use stolen session tokensMicrosoft MDDR 2025
- 65.7BIdentity records in SpyCloud datalakeSpyCloud 2026
- 217%Rise in MFA fatigue attacks YoYVerizon DBIR 2025
- 22%Of breaches start with stolen credentialsVerizon DBIR 2025
- $4.67MAvg. cost of a credential breachIBM 2025
Latest News
-
Threat Watch: Kyber Ransomware, Casbaneiro and BambooToken
Ransomware that hits Windows and VMware at once, a banking trojan hiding in fake invoices across Latin America, and a backdoor that talks over an IoT protocol.
-
Vercel: Lumma Stealer Entered via a Roblox Cheat File
One game script from an unofficial site ran silently for two months, harvesting passwords and session tokens that led to a breach affecting hundreds of organisations.
-
Storm-2372: MFA Bypassed at Scale, No Password Stolen
A criminal group abused a legitimate Microsoft login flow. Victims clicked a link and pressed Allow, no password needed. FBI shut it down in April 2026.
-
Figure Technology: 967,000 Accounts Exposed After One Employee Was Manipulated
Attackers sent one convincing message. No malware. No hacking tools. 967,000 customer records stolen and published online.
-
APT28: 18,000 Routers Hijacked to Steal Session Tokens
A state-sponsored group stole OAuth tokens from 18,000 routers globally, bypassing MFA entirely. With a stolen token, no password or MFA code is needed.
-
Adobe: 13 Million Support Tickets Exposed via a Contractor's Device
One phishing email on a contractor's device gave attackers access to 13 million tickets, 15,000 employee records, and unpublished security vulnerabilities.
-
Synthient: 1.3 Billion Passwords Now Searchable in Have I Been Pwned
HIBP absorbed 1.96 billion emails and 1.3 billion passwords. 625 million had never been seen before. Check yours at haveibeenpwned.com.
-
Six Steps to Protect Yourself Right Now
Change your password. Deny unexpected MFA prompts. Stop reusing passwords. Six clear actions, no jargon, under 30 minutes.
2026 by the Numbers
- 26BCredential stuffing attempts per monthFortinet 2025
- 60%Of infostealer credentials from LummaC2Specops 2026
- 276MCredentials with active session cookies exposedRecorded Future 2025
- 97%Of identity attacks are password attacksMicrosoft Digital Defense 2025
Verified Sources
Every article is sourced from verified, authoritative outlets only. No unverified claims are published.
- BleepingComputerSecurity news, breach reporting, malware analysisbleepingcomputer.com
- The Hacker NewsCybersecurity reporting, APT tracking, vulnerability newsthehackernews.com
- TechCrunch SecurityBreach disclosure and tech industry security reportingtechcrunch.com
- NCSCUK National Cyber Security Centre: official guidancencsc.gov.uk
- CISAUS Cybersecurity & Infrastructure Security Agencycisa.gov
- ENISAEU Agency for Cybersecurity: annual threat landscapeenisa.europa.eu
- Have I Been PwnedCheck if your email appeared in a known breach, freehaveibeenpwned.com
- EuropolOperation Endgame, infostealer takedowns, EU enforcementeuropol.europa.eu