Error message

  • Deprecated function: Methods with the same name as their class will not be constructors in a future version of PHP; views_display has a deprecated constructor in require_once() (line 3080 of /home/ewg56ffgqu3p/public_html/includes/bootstrap.inc).
  • Deprecated function: Methods with the same name as their class will not be constructors in a future version of PHP; views_many_to_one_helper has a deprecated constructor in require_once() (line 113 of /home/ewg56ffgqu3p/public_html/modules/ctools/ctools.module).
  • Notice: Undefined offset: 5 in user_node_load() (line 3604 of /home/ewg56ffgqu3p/public_html/modules/user/user.module).
  • Notice: Trying to get property 'name' of non-object in user_node_load() (line 3604 of /home/ewg56ffgqu3p/public_html/modules/user/user.module).
  • Notice: Undefined offset: 5 in user_node_load() (line 3605 of /home/ewg56ffgqu3p/public_html/modules/user/user.module).
  • Notice: Trying to get property 'picture' of non-object in user_node_load() (line 3605 of /home/ewg56ffgqu3p/public_html/modules/user/user.module).
  • Notice: Undefined offset: 5 in user_node_load() (line 3606 of /home/ewg56ffgqu3p/public_html/modules/user/user.module).
  • Notice: Trying to get property 'data' of non-object in user_node_load() (line 3606 of /home/ewg56ffgqu3p/public_html/modules/user/user.module).
  • Notice: Trying to access array offset on value of type int in element_children() (line 6401 of /home/ewg56ffgqu3p/public_html/includes/common.inc).
  • Notice: Trying to access array offset on value of type int in element_children() (line 6401 of /home/ewg56ffgqu3p/public_html/includes/common.inc).
  • Notice: Trying to access array offset on value of type int in element_children() (line 6401 of /home/ewg56ffgqu3p/public_html/includes/common.inc).
  • Notice: Trying to access array offset on value of type int in element_children() (line 6401 of /home/ewg56ffgqu3p/public_html/includes/common.inc).
  • Notice: Trying to access array offset on value of type int in element_children() (line 6401 of /home/ewg56ffgqu3p/public_html/includes/common.inc).
  • Notice: Trying to access array offset on value of type int in element_children() (line 6401 of /home/ewg56ffgqu3p/public_html/includes/common.inc).
  • Notice: Trying to access array offset on value of type int in element_children() (line 6401 of /home/ewg56ffgqu3p/public_html/includes/common.inc).
  • Notice: Trying to access array offset on value of type int in element_children() (line 6401 of /home/ewg56ffgqu3p/public_html/includes/common.inc).
  • Notice: Trying to access array offset on value of type int in element_children() (line 6401 of /home/ewg56ffgqu3p/public_html/includes/common.inc).
  • Notice: Trying to access array offset on value of type int in element_children() (line 6401 of /home/ewg56ffgqu3p/public_html/includes/common.inc).
  • Notice: Trying to access array offset on value of type int in element_children() (line 6401 of /home/ewg56ffgqu3p/public_html/includes/common.inc).
  • Notice: Trying to access array offset on value of type int in element_children() (line 6401 of /home/ewg56ffgqu3p/public_html/includes/common.inc).
  • Notice: Trying to access array offset on value of type int in element_children() (line 6401 of /home/ewg56ffgqu3p/public_html/includes/common.inc).
  • Deprecated function: implode(): Passing glue string after array is deprecated. Swap the parameters in drupal_get_feeds() (line 394 of /home/ewg56ffgqu3p/public_html/includes/common.inc).
  • Deprecated function: The each() function is deprecated. This message will be suppressed on further calls in menu_set_active_trail() (line 2386 of /home/ewg56ffgqu3p/public_html/includes/menu.inc).

News

Steam survey shows GPUs with 16GB are now the most popular graphics cards — and that really doesn't bode well for gamers' wallets - Tuesday, August 4, 2026 - 18:00
  • The latest Steam survey shows GPUs with 16GB are the most popular
  • They're on 25.9% and have overtaken 8GB GPUs which are just behind on 25.32%
  • There's been quite a shift towards 16GB boards over the past year, but with news of more price hikes incoming, upgrading to this loadout could be a painful process for gamers

Graphics cards with 16GB of memory are the most popular GPU among Steam gamers now, although the way GPU prices are going means that people aiming for a board packing plenty of video RAM (VRAM) are looking at a rather depressing future.

TweakTown spotted that the latest Steam hardware survey for July shows that 16GB of VRAM is the most prevalent memory configuration at 25.9%, up 1.4% over last month. That means it just dethrones the previous top of the VRAM table, which was 8GB, a loadout that slipped slightly from last month down to 25.32%.

There's not much in it, of course, but nonetheless, it's a telling stat (bearing in mind the usual caveats about variance in Valve's hardware report based on how the survey is distributed).

Of course, the majority of Steam gamers are still running with less than 16GB, and only 36% have a GPU with 16GB or more. So, almost two-thirds are running less than 16GB, and just under half (47%) have a graphics card with 8GB or less.

But it's a hefty rise in the count of 16GB GPUs when you consider that less than a year ago, in August 2025, just 6.8% of Steam gamers had boards with that VRAM loadout (based on a Notebookcheck report from the time). Compared to July 2026, that's nearly quadruple the number of 16GB-equipped rigs, with a close to 20% increase — pretty eye-opening.

Analysis: 16GB ambitions and the ever-worsening RAM crisis

(Image credit: Future / John Loeffler)

It seems that, at least based on Steam's stats, RTX 5060 Ti 16GB and RX 9060 XT 16GB graphics cards (and 9070 models) must have been selling well — and of course higher-end Nvidia cards. The RTX 5070 is doing well for itself, too, and is now in third position in Steam's GPU ranking (although that's a 12GB offering and it should really be 16GB).

The ranks of the 16GB GPUs on Steam will also be bolstered by older models, of course, from past generations. Also, the visibility of AMD Radeon graphics cards with 16GB of VRAM was improved by Valve earlier this year, when an issue was fixed whereby these cards were misreported (not detected and lumped in a generic Radeon category), so that will have boosted numbers too.

At any rate, the fact that more gamers are looking at future-proofing their GPU purchases only makes sense, as 8GB in particular is looking too lean at this point. But there's a problem with GPUs that have heavier VRAM configurations, and this is, of course, that the memory crisis hits these models hardest.

We've already seen that GPU price hikes are making themselves felt, and just a couple of weeks back, Nvidia seemingly told its card-making partners that the price it charges for memory supplied with its graphics chips is going up (for both GDDR6 and GDDR7). A fresh report from Tom's Hardware also talks about price hikes for RTX 5000 models in South Korea beginning this month, driven not just by the increased cost of video RAM, but also the GPU chips themselves.

We're told the upshot is that Nvidia's Blackwell GPUs could see price increases of up to 30% in the country, and similar hikes may happen elsewhere. AMD price hikes are expected for its Radeon line-up, too, and Team Red has already warned us that the second half of 2026 is going to be a tough one for PC gamers.

With those gamers craving 16GB of video RAM more often, and prices heading inexorably upwards — and the memory crisis expected to worsen as this year rolls on, with the misery to continue into 2027 by all accounts — it's a gloomy picture for beefier graphics card upgrades.

'Tools don't have independent values — their values are human values': Quote of the day by Stanford professor Fei-Fei Li on building ethical AI - Tuesday, August 4, 2026 - 18:00

With AI advancing in capability and availability, many scientists and experts have begun highlighting the risks of deploying this emerging technology. There's an overriding desire to deploy AI ethically, or to instill models with human-based values, but it remains to be seen how to standardize such an approach or even whether to regulate the industry. That's where organizations like the Stanford Institute for Human-Centered AI (HAI) come in.

Computer says no

When interviewed for the journal Issues in Science and Technology, the so-called 'Godmother of AI' Fei-Fei Li tried to explain how scientists and engineers can build AI that truly adheres to our values.

Quote of the day

This article is part of TechRadar Pro's QOTD project to provide an insight into the minds of the brightest and most recognized figures in the technology industry today and in years gone by. Read the full series here.

Her thesis around the responsible use of AI centers not on anthropomorphizing AI or considering it an intelligence capable of navigating the world and arriving at its own independent conclusions. Rather, it will reflect the values that we instill into it, whether that's through training or continued use of these tools.

She added in this interview that it's also about recognizing that AI, as any tool, can both empower and harm humans.

Values-driven AI

The organization that the American computer scientist leads, HAI, is an interdisciplinary research center that focuses on how best to guide AI development so that it benefits humanity and doesn't incur or lead to harm.

In recent years, there's also been an increased emphasis on whether to regulate AI nationally (or even globally) and what shape that might take. Doing so, however, is far easier said than done, with progress occurring at different paces, in different guises, and inconsistently across oceans.

There are, for example, different values that different nations or groups of people may wish to instill into the AI models they build that clash with the values of others.

Cybercrime is costing the world trillions every year - new report says victims lose an average of nearly $10,000 in every hit - Tuesday, August 4, 2026 - 18:35
  • New study puts average cybercrime victim losses at $9,468, making a global annual toll at just over $1.24 trillion across 130.9 million victims
  • Cybercrime is still massively underreported by both victims and authorities, so official numbers might be 'softer' than the underlying problem
  • Some of the countries published limited, if any, financial data regarding cybercrime, making losses an estimate at best

New figures have claimed cybercrime victims lose $9,468 in the average incident, showing the scale of an increasingly global problem.

The report from Comparitech claims 130.9 million people are hit each year, and that the annual global toll comes to just over $1.24 trillion.

A December 2023 study from the company put those figures at $8,069 per victim, 88.5 million people and $714 billion in total losses respectively, highlighting a growing trend that sees a mix of illegal activity moving the needle further.

A growing problem with regional caveats

The United States remains a favorite for cybercriminals, topping the charts with 6.7 million victims losing $138.9 billion, a per-victim loss amount of ~$20,731, more than twice that of the global average.

This is in stark contrast with the next four countries on the list (Spain, France, Sweden and Turkey), all of which offered an average of approximately $10,000 per victim.

Russia, coming in 6th, reports a much larger number of victims than the four countries ahead of it, but offers a much lower per-victim loss estimate of $3,659. Interestingly, the total number of cybercrimes committed in 2025 dropped to 663,000 from 775,000 in 2024, despite an ongoing conflict with Ukraine, which often sees cyberattacks at both the industrial and localized levels by both parties.

However, a weakening economic situation, as well as Russia localizing many of its communication applications and restricting banking, might also mean that Russia's figures also remain inadvertently capped by policy decisions the country has taken.

With 18.8 million victims, India has the highest number of scam victims worldwide, even though its pro-rata number is considerably lower than the mean at ~$835 per victim, which may be attributable to the country's lower GDP per capita.

Interestingly, China, with 1.2 million victims, a fraction of its neighbor, managed to lose approximately $11.5 billion, a pro-rata number of approximately $9583, in line with global estimates by Comparitech and possibly fueled by the country's heavy-handed approach to cybercriminals, which saw it apply increasing amounts of pressure on neighboring Myanmar that culminated in it convicting and executing scammers arrested across the border.

Comparitech's $1.24 trillion figure is conservative, and the study acknowledges this, noting that it covers only victim losses. It notes that experts anticipated the global cost reaching $10.5 trillion in 2025 and calls its own $1.24 trillion a drop in the ocean by comparison.

That $10.5 trillion comes from Cybersecurity Ventures' 2016 report, which estimated $3 trillion for 2015 and projected it forward at an assumed 15 percent compound annual growth rate, describing the result as the greatest transfer of economic wealth in history.

At a time when AI automation offers better security, often allowing users to screen calls or leverage security applications that adapt on a case-by-case basis, the inverse is also true with hackers and cybercriminals considerably upping their game when it comes to bypassing security altogether; Comparitech's figures provide a sobering reality: if the industry estimates it has hold and are compared to the GDP of entire countries, the firm says it would rank 20th in the world in those terms alone.

Hank Green Is Reckoning With His Use of AI. So Should the Rest of Us - Wednesday, August 5, 2026 - 15:00
Commentary: I’ve been watching Hank Green since 2012. This AI controversy isn’t just about him.
SpaceX’s Future Plans Hinge Heavily on Starlink and Grok - Wednesday, August 5, 2026 - 12:25
Elon Musk’s rocket, internet and AI company gave investors its first update since its June IPO.
Walmart Deals of the Day: Score $49 Off the iPad A16 to Help With Apple’s Price Hikes - Wednesday, August 5, 2026 - 12:19
Plus, over $100 off a cordless Shark vacuum and $30 off a pair of open-ear Shokz headphones.
These Sennheiser Headphones Are Back Down to a Record Low of $190 - Wednesday, August 5, 2026 - 12:43
Immerse yourself in sound, focus when it counts and save a massive $210 with this deal.
Ditch the Darkness and the Holiday Hassle With $310 Off Eufy’s Permanent Outdoor Lights - Wednesday, August 5, 2026 - 13:42
From motion detection and vibrant lighting to Matter support, these smart lights are built to shine all year round. Get them for 36% off now.
Gaming’s Current Nightmare Is Probably the New Normal - Wednesday, August 5, 2026 - 14:18
Current trends in gaming are probably not going away any time soon, and you can thank AI and corporate greed for it.
An Abandoned SpaceX Rocket Crashed Into the Moon. Here’s What Happened - Wednesday, August 5, 2026 - 14:28
The rocket drifted in space for over a year before finally plummeting to the moon’s surface.
Today’s NYT Connections Hints and Answers for Aug. 6, #1152 - Wednesday, August 5, 2026 - 16:00
Here are hints and the answers for the NYT Connections puzzle No. 1152 for Aug. 6, 2026.
The Disney Plus App Is Getting TikToks. Is a Free Plan Next? - Wednesday, August 5, 2026 - 15:09
Disney-themed TikToks are coming to US subscribers. And the company’s executives defended box office flops as wins.
Today’s NYT Strands Hints, Answers and Help for Aug. 6 #886 - Wednesday, August 5, 2026 - 16:00
Here are hints and the answers for the NYT Strands puzzle No. 886 for Thursday, Aug. 6, 2026.
Today’s NYT Connections: Sports Edition Hints and Answers for Aug. 6, #682 - Wednesday, August 5, 2026 - 16:00
Here are hints and the answers for the NYT Connections: Sports Edition puzzle No. 682 for Thursday, Aug. 6.
I Shot the Sky With 2 Smart Telescopes, Both Under $400. Here’s My Take - Monday, July 20, 2026 - 10:54
The budget-friendly Dwarf Mini and Seestar S30 performed better than I’d anticipated. Here’s my take after shooting with both.
Ditch the Teflon: This Hack Transforms Stainless-Steel Pans Into Nonstick - Wednesday, July 8, 2026 - 09:05
Skip the fragile ceramic and the clunky cast iron. I found a nonstick hack for stainless-steel cookware.
Meta Is Challenging Claude Code and Codex With New Muse Code - Wednesday, August 5, 2026 - 17:13
With coding as a key capability for AI companies, Meta throws its hat into the ring.
NYT Connections hints and answers for Wednesday, August 5 (game #1151) - Tuesday, August 4, 2026 - 19:00
Looking for a different day?

A new NYT Connections puzzle appears at midnight each day for your time zone – which means that some people are always playing 'today's game' while others are playing 'yesterday's'. If you're looking for Tuesday's puzzle instead then click here: NYT Connections hints and answers for Tuesday, August 4 (game #1150).

Good morning! Let's play Connections, the NYT's clever word game that challenges you to group answers in various categories. It can be tough, so read on if you need Connections hints.

What should you do once you've finished? Why, play some more word games of course. I've also got daily Strands hints and answers and Quordle hints and answers articles if you need help for those too, while Marc's Wordle today page covers the original viral word game.

SPOILER WARNING: Information about NYT Connections today is below, so don't read on if you don't want to know the answers.

NYT Connections today (game #1151) - today's words

(Image credit: New York Times)

Today's NYT Connections words are…

  • LUCKY
  • MISSION
  • RANCH
  • CATTLE
  • WRANGLER
  • INVESTMENT
  • GAP
  • STEER
  • BROTH
  • PILOT
  • CAPE COD
  • MERCHANDISE
  • DRIVE
  • DIESEL
  • TUDOR
  • MANEUVER
NYT Connections today (game #1151) - hint #1 - group hints

What are some clues for today's NYT Connections groups?

  • YELLOW: Plot a path
  • GREEN: Purveyors of denim
  • BLUE: Types of home buildings
  • PURPLE: The common link rhymes with “lock”

Need more clues?

We're firmly in spoiler territory now, but read on if you want to know what the four theme answers are for today's NYT Connections puzzles…

NYT Connections today (game #1151) - hint #2 - group answers

What are the answers for today's NYT Connections groups?

  • YELLOW: NAVIGATE
  • GREEN: JEANS BRANDS
  • BLUE: HOUSE STYLES
  • PURPLE: WHAT "STOCK" MIGHT REFER TO

Right, the answers are below, so DO NOT SCROLL ANY FURTHER IF YOU DON'T WANT TO SEE THEM.

NYT Connections today (game #1151) - the answers

(Image credit: New York Times)

The answers to today's Connections, game #1151, are…

  • YELLOW: NAVIGATE: DRIVE, MANEUVER, PILOT, STEER
  • GREEN: JEANS BRANDS: DIESEL, GAP, LUCKY, WRANGLER
  • BLUE: HOUSE STYLES: CAPE COD, MISSION, RANCH, TUDOR
  • PURPLE: WHAT "STOCK" MIGHT REFER TO: BROTH, CATTLE, INVESTMENT, MERCHANDISE
  • My rating: Hard
  • My score: 1 mistake

I fell for the obvious trap and linked WRANGLER, CATTLE, RANCH, and STEER today. But unable at that point to see any alternative groups, I went for it anyway.

Thankfully, after this mistake I found my way to the four tiles that made up NAVIGATE.

Not for the first time I’d take issue with Connections and protest that GAP, while being a seller of jeans, is not exactly one of the top JEANS BRANDS. Very misleading. Oh well, I Guess I will have to Levi it there as it’s onLee a game.

Yesterday's NYT Connections answers (Tuesday, August 4, 2026, game #1150)
  • YELLOW: LONG CYLINDRICAL THINGS: CIGARETTE, FOAM ROLLER, POOL NOODLE, PRETZEL ROD
  • GREEN: ICONIC NYC SIGHTS: BODEGA, PIGEON, SUBWAY STATION, TAXI CAB
  • BLUE: THINGS WITH PEDALS: PIANO, SEWING MACHINE, SWAN BOAT, UNICYCLE
  • PURPLE: V-SHAPED THINGS: ANGLE BRACKET, CHEVRON, GOOSE FORMATION, PEACE SIGN
What is NYT Connections?

NYT Connections is one of several increasingly popular word games made by the New York Times. It challenges you to find groups of four items that share something in common, and each group has a different difficulty level: green is easy, yellow a little harder, blue often quite tough and purple usually very difficult.

On the plus side, you don't technically need to solve the final one, as you'll be able to answer that one by a process of elimination. What's more, you can make up to four mistakes, which gives you a little bit of breathing room.

It's a little more involved than something like Wordle, however, and there are plenty of opportunities for the game to trip you up with tricks. For instance, watch out for homophones and other word games that could disguise the answers.

It's playable for free via the NYT Games site on desktop or mobile.

Quordle hints and answers for Wednesday, August 5 (game #1654) - Tuesday, August 4, 2026 - 19:00
Looking for a different day?

A new Quordle puzzle appears at midnight each day for your time zone – which means that some people are always playing 'today's game' while others are playing 'yesterday's'. If you're looking for Tuesday's puzzle instead then click here: Quordle hints and answers for Tuesday, August 4 (game #1653).

Quordle was one of the original Wordle alternatives and is still going strong now more than 1,500 games later. It offers a genuine challenge, though, so read on if you need some Quordle hints today — or scroll down further for the answers.

Enjoy playing word games? You can also check out my NYT Connections today and NYT Strands today pages for hints and answers for those puzzles, while Marc's Wordle today column covers the original viral word game.

SPOILER WARNING: Information about Quordle today is below, so don't read on if you don't want to know the answers.

Quordle today (game #1654) — hint #1 — VowelsHow many different vowels are in Quordle today?

The number of different vowels in Quordle today is 4*.

* Note that by vowel we mean the five standard vowels (A, E, I, O, U), not Y (which is sometimes counted as a vowel too).

Quordle today (game #1654) — hint #2 — repeated lettersDo any of today's Quordle answers contain repeated letters?

The number of Quordle answers containing a repeated letter today is 1.

Quordle today (game #1654) — hint #3 — uncommon lettersDo the letters Q, Z, X or J appear in Quordle today?

• No. None of Q, Z, X or J appear among today's Quordle answers.

Quordle today (game #1654) — hint #4 — starting letters (1)Do any of today's Quordle puzzles start with the same letter?

The number of today's Quordle answers starting with the same letter is 2.

If you just want to know the answers at this stage, simply scroll down. If you're not ready yet then here's one more clue to make things a lot easier:

Quordle today (game #1654) — hint #5 — starting letters (2)What letters do today's Quordle answers start with?

• M

• W

• S

• W

Right, the answers are below, so DO NOT SCROLL ANY FURTHER IF YOU DON'T WANT TO SEE THEM.

Quordle today (game #1654) — the answers

(Image credit: Merriam-Webster)

The answers to today's Quordle, game #1654, are…

  • MOUND
  • WRONG
  • STOOD
  • WEIRD

It has taken me a long time, but I have finally realized that I need to take some games of Quordle more slowly.

Today was a good example of this. With multiple possibilities of a word ending O-U-N-D I had to use the other words to eliminate letters, before MOUND became the only possibility.

Daily Sequence today (game #1654) — the answers

(Image credit: Merriam-Webster)

The answers to today's Quordle Daily Sequence, game #1654, are…

  • FLUTE
  • SMEAR
  • LODGE
  • DIVER
Quordle answers: The past 20
  • Quordle #1653, Tuesday, 4 August: GOOEY, TARDY, HUMAN, CHALK
  • Quordle #1652, Monday, 3 August: FUNGI, MUDDY, DEBUT, MANIA
  • Quordle #1651, Sunday, 2 August: BOOTH, EASEL, REACH, MAKER
  • Quordle #1650, Saturday, 1 August: OMEGA, BIRCH, SMOCK, EERIE
  • Quordle #1649, Friday, 31 July: MANIA, SINGE, STOOL, LOFTY
  • Quordle #1648, Thursday, 30 July: MODAL, IDLER, CHUMP, LUMPY
  • Quordle #1647, Wednesday, 29 July: GAWKY, ALLOY, AUDIT, LATCH
  • Quordle #1646, Tuesday, 28 July: SMITE, ROACH, RUDDY, GLOBE
  • Quordle #1645, Monday, 27 July: TAFFY, FIGHT, GUILD, WAGER
  • Quordle #1644, Sunday, 26 July: STOMP, LIMIT, FUNKY, STEAD
  • Quordle #1643, Saturday, 25 July: SALON, SHEEN, BURST, GOURD
  • Quordle #1642, Friday, 24 July: DOLLY, EDIFY, LAGER, PRANK
  • Quordle #1641, Thursday, 23 July: LADEN, EVICT, WOVEN, SHIRE
  • Quordle #1640, Wednesday, 22 July: COYLY, SINGE, AWASH, AWOKE
  • Quordle #1639, Tuesday, 21 July: TRUSS, AXIAL, SWINE, THING
  • Quordle #1638, Monday, 20 July: ICING, SLICK, GAILY, RISEN
  • Quordle #1637, Sunday, 19 July: SPURT, ACRID, THRUM, BLEEP
  • Quordle #1636, Saturday, 18 July: KNAVE, TIGHT, BLEAT, CHAOS
  • Quordle #1635, Friday, 17 July: CUMIN, PALER, GRASS, INBOX
  • Quordle #1634, Thursday, 16 July: IGLOO, PLAIT, YEAST, AROMA
Watch out — Microsoft login pages are being abused as hackers try and lure in unlucky victims, here's what to look out for - Tuesday, August 4, 2026 - 19:15
  • Phishing campaign used fake Teams notifications to route victims to a genuine Microsoft sign-in page
  • Rather than stealing passwords, attackers asked victims to approve permissions for an attacker-controlled app, gaining access to mail, files, Teams, SharePoint, OneDrive and calendars without defeating MFA
  • Check Point says the technique has been commoditized in 2026 into a rentable service; the practical defense is restricting app consent rather than relying on users to spot a fake

A phishing campaign that ran from late June into July 2026 did something that breaks most of the advice organizations have spent a decade teaching their staff: it sent victims to a real Microsoft login page.

Check Point's email research team, which disclosed the campaign, identified more than 200 phishing emails targeting users across roughly 120 organizations worldwide.

The lure was a fake Microsoft Teams notification with a genuine destination; what actually compromised accounts was not a stolen password but a permissions prompt that the victim clicked through voluntarily.

A sophisticated attack that relied on tricking users into granting permissions

Check Point noted in its brief that what actually compromised the accounts was not a stolen password but a permissions prompt that the victim clicked through voluntarily. This is a reminder of a stark change in attackers' tactics: they have stopped forging Microsoft's front door and started walking through it.

The email appeared to be a Microsoft Planner task-assignment notification. The sender name read "There's New Activity On Team," the subject line claimed that HR had sent three messages via Teams chat, and the body referenced a payroll and benefits update, along with a counter showing four overdue employee tasks.

To someone who works in security, the message had its own telltale signs of being a typical phishing attempt: every link in the email, including both call-to-action buttons, routed through the same redirect. And the visible sender address belonged to the recipient's own organization, meaning the email appeared to have been sent to the same person it came from.

The link opened a real OAuth authorization URL on login.microsoftonline.com, not a look-alike domain. Signing in displayed a permissions prompt asking the user to approve the permissions or accept them on behalf of their organization.

If they did, Microsoft redirected the browser to the redirect address specified in the original request, which in this particular campaign was an AWS API Gateway endpoint under the attackers' control. The authorization code was delivered there, and the attackers exchanged it for access. No password was stolen at any point, and there was no fake page to spot.

This is not unlike how the phishing-as-a-service Kali365 platform compromises Microsoft accounts, but instead of stealing session cookies or OAuth tokens, it opts for a more permanent illicit grant of consent.

This runs counter to the usual security training checklist, which emphasizes adhering to norms rather than going against the grain; users are told to check the URL, look for the padlock, and watch for misspelled domains. None of those measures matter because there is nothing forged to catch. The domain and certificate are Microsoft's, while the sign-in page is the one the user sees every morning, offering a false sense of security to a user not looking for this particular attack vector.

Multi-factor authentication does not help either; it protects the login sequence but not access to the user's data post-login. The attacker never needs the password or the second factor because they walk away with a token granted by the user's valid session, a technique called 'consent phishing'.

There are many ways to prevent this, but the simplest two are asking users to check every single permission/consent screen they click (the phishing attempt still requires users to allow it) and limiting access to permissions for user accounts that applications can request via Microsoft Entra at the system administrator level.

It would be prudent to do the latter at a minimum, even as Check Point notes that the campaign is no longer active because the underlying technique it used is not going anywhere.

Pages