Cybersecurity threats are real. Stay informed.

A public bulletin from FBM Security Intelligence. Real incidents. Verified sources. Plain language. Updated with the latest global threat intelligence.

Global Advisory

Device code phishing is active. Never enter a code at microsoft.com/devicelogin unless you started the sign-in yourself. Asked for a code by an email or document? Stop and report it.

Global threat level

May 2026
  • Credential stuffingCritical91%
  • MFA bypassCritical84%
  • PhishingHigh78%
  • RansomwareHigh65%
  • Social engineeringMedium58%

Based on NCSC, CISA, Europol, and Verizon DBIR 2025. Updated monthly.

  • 26BCredential stuffing attempts/monthFortinet 2025
  • 1.3BPasswords in the Synthient breachHIBP Nov 2025
  • 246 daysAvg. time to detect a breachIBM Cost of a Breach 2025
  • 80%MFA bypasses use stolen session tokensMicrosoft MDDR 2025
  • 65.7BIdentity records in SpyCloud datalakeSpyCloud 2026
  • 217%Rise in MFA fatigue attacks YoYVerizon DBIR 2025
  • 22%Of breaches start with stolen credentialsVerizon DBIR 2025
  • $4.67MAvg. cost of a credential breachIBM 2025

Latest News

  1. Threat radar illustration
    HighThreat Watch

    Threat Watch: Kyber Ransomware, Casbaneiro and BambooToken

    Ransomware that hits Windows and VMware at once, a banking trojan hiding in fake invoices across Latin America, and a backdoor that talks over an IoT protocol.

  2. Vercel breach, Lumma Stealer supply chain attack
    CriticalSupply Chain

    Vercel: Lumma Stealer Entered via a Roblox Cheat File

    One game script from an unofficial site ran silently for two months, harvesting passwords and session tokens that led to a breach affecting hundreds of organisations.

  3. MFA bypass attack illustration
    CriticalMFA Bypass

    Storm-2372: MFA Bypassed at Scale, No Password Stolen

    A criminal group abused a legitimate Microsoft login flow. Victims clicked a link and pressed Allow, no password needed. FBI shut it down in April 2026.

  4. Social engineering attack illustration
    HighSocial Engineering

    Figure Technology: 967,000 Accounts Exposed After One Employee Was Manipulated

    Attackers sent one convincing message. No malware. No hacking tools. 967,000 customer records stolen and published online.

  5. Router hijacking session theft illustration
    CriticalSession Theft

    APT28: 18,000 Routers Hijacked to Steal Session Tokens

    A state-sponsored group stole OAuth tokens from 18,000 routers globally, bypassing MFA entirely. With a stolen token, no password or MFA code is needed.

  6. Contractor phishing breach illustration
    HighPhishing

    Adobe: 13 Million Support Tickets Exposed via a Contractor's Device

    One phishing email on a contractor's device gave attackers access to 13 million tickets, 15,000 employee records, and unpublished security vulnerabilities.

  7. Credential breach database illustration
    Industry-wideBreach Data

    Synthient: 1.3 Billion Passwords Now Searchable in Have I Been Pwned

    HIBP absorbed 1.96 billion emails and 1.3 billion passwords. 625 million had never been seen before. Check yours at haveibeenpwned.com.

  8. Security checklist guide illustration
    GuideBest Practice

    Six Steps to Protect Yourself Right Now

    Change your password. Deny unexpected MFA prompts. Stop reusing passwords. Six clear actions, no jargon, under 30 minutes.

2026 by the Numbers

  • 26BCredential stuffing attempts per monthFortinet 2025
  • 60%Of infostealer credentials from LummaC2Specops 2026
  • 276MCredentials with active session cookies exposedRecorded Future 2025
  • 97%Of identity attacks are password attacksMicrosoft Digital Defense 2025