Wednesday , June 24 2026
Microsoft 365

Hackers leverage CloudFlare Anti-Security to Steal Microsoft 365 Login Credentials

Security researchers recently identified a phishing campaign targeting Microsoft 365 users that takes advantage of CloudFlare’s anti-bot and verification systems. Attackers employ various anti-detection techniques to ensure only genuine victims access the credential-stealing sites.

CloudFlare Used as a Protective Shield

LastPass says hackers stole customer data via Klue, supply chain breach

LastPass has reported a security issue with its vendor, Klue. This incident allowed an attacker unauthorized access to customer data....
Read More
LastPass says hackers stole customer data via Klue, supply chain breach

New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

Researchers at cybersecurity firm Paradigm Shift found a new flaw called usbliter8. This flaw can get around main boot protections...
Read More
New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

A cyber attack seems to have affected one of India's top electronics companies. Tata Electronics has said there was a...
Read More
India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

Anthropic’s Mythos reportedly broke NSA classified systems in hours

The recent finding shows how powerful Mythos is: the AI can access the US government's secret networks in just a...
Read More
Anthropic’s Mythos reportedly broke NSA classified systems in hours

OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

Test before going live is important for AI developers. But there's a problem: testing usually uses fake scenarios that often...
Read More
OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

AryStinger botnet infected thousands of D-Link routers globally

AryStinger has taken control of over 4,000 old D-Link routers to use them as proxies for harmful traffic. The team...
Read More
AryStinger botnet infected thousands of D-Link routers globally

Hacker suspected of sending alerts across Brazil

Brazil's government suspects a hacking attack triggered an unauthorized ‌alert sent to cell phones across parts of the country early...
Read More
Hacker suspected of sending alerts across Brazil

CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

A new open-source cybersecurity tool named CyberSentinel AI v3.0 has come out. It is an important step in self-operated security...
Read More
CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

Barracuda hosts Dhaka roundtable on cyber resilience

Barracuda gathered industry people in Dhaka on 18 June 2026 for a roundtable talk about cyber resilience. The company shared...
Read More
Barracuda hosts Dhaka roundtable on cyber resilience

CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) asked Fortinet users with FortiGate devices on Thursday to act to protect...
Read More
CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

The campaign begins with a phishing domain hosted behind CloudFlare infrastructure.

Example domain observed in the campaign:

securedsnmail[.]com.
https[:]//securedsnmail[.]com/secdex.html.

When users visit the site, they see a CloudFlare human verification page first. This prevents automated tools from analyzing malicious content.

securedsnmail[.]com (Source : DomainTools).
Once the verification process is completed, the victim is redirected to the next stage of the attack.

The attackers used various methods to hide the phishing site from security systems.

These include:

CloudFlare uses human verification to block automated scanning tools.
IP filtering using data from api.ipify[.]org to identify the visitor’s IP address.
Hardcoded blocklists that exclude IP ranges belonging to security companies such as Palo Alto Networks, FireEye, AWS, and Google Cloud platforms.
User‑agent inspection to detect bots and crawlers such as Googlebot, Bingbot, AhrefsBot, and Twitterbot.

When a security scanner or bot is detected, the site shows a fake “404 Not Found” page. This stops the domain from being indexed by search engines or flagged by security tools.

Infrastructure Patterns

Several shared infrastructure indicators were observed across the campaign:

Nameservers: cloudflare.com.
Registrar: Namecheap.
MX hosts: registrar-servers[.]com, jellyfish[.]systems.
Hosting ISP: CloudFlare Inc.

These similarities indicate a planned phishing setup that allows for the rapid creation of new domains when the old ones are found. This campaign addresses a rising issue in cybersecurity. Attackers are using legitimate security platforms intended to protect websites as cover.

Security researchers suggest that improved customer verification and abuse monitoring by service providers can help reduce phishing and credential theft on their platforms.

IOCs

securedreach[.]com wirelessmailsent[.]com
suitecorporate[.]com suitetosecured[.]com

Check Also

Texas

Texas data breach exposes 3 million driver’s licenses

The Texas Parks and Wildlife Department (TPWD) revealed a data leak at its license system …