Infoblox A.I CyberSecurity Scoring
Infoblox
Company Information
Website:http://www.infoblox.com
Employees number:3,366
Number of followers:222,669
NAICS:541514
Industry Type:Computer and Network Security
Homepage:infoblox.com
Infoblox Risk Score (AI oriented)
Between 700 and 749
InfobloxComputer and Network Security
Updated:
22/07/2026
22/07/2026
738/1000
Moderate
Ba
Infoblox Global Score (TPRM)
xxxx
InfobloxComputer and Network Security
Score locked

InfobloxModerate
Current Score
738Ba (MODERATE)
01000
2 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
740
AUGUST 2026
739
JULY 2026
738
JUNE 2026
737
MAY 2026
753
Cyber Attack
01 May 2026 • Infoblox
Infoblox: Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions
Sophisticated AiTM Phishing Campaign Hijacks Microsoft 365 Sessions via Compromised Outlook Accounts
735
CRITICAL-18
INF1784716085
Sophisticated AiTM Phishing Campaign Hijacks Microsoft 365 Sessions via Compromised Outlook Accounts
In May 2026, security researchers at Infoblox uncovered a highly targeted adversary-in-the-middle (AiTM) phishing campaign abusing Microsoft Outlook mailboxes to steal multi-factor authenticated (MFA) Microsoft 365 sessions. The attack, which began with a single phishing email sent to a small group of employees, rapidly escalated into a cross-organizational compromise, leveraging trusted internal communication channels to spread.
### How the Attack Works
1. Initial Compromise – Attackers send procurement-themed phishing emails (e.g., RFIs, bid invitations, or shared documents) from compromised Outlook accounts, making them appear legitimate to recipients.
2. Fake Portals & Cloned Logins – Victims who click embedded links are redirected through compromised domains (e.g., testserveren[.]com, barifurniture[.]net) to fake document portals and spoofed Microsoft 365 login pages.
3. Session Hijacking – Using reverse proxy kits like EvilProxy, FlowerStorm, and Kali365, attackers intercept credentials and live session cookies, bypassing MFA and gaining full access to Outlook, SharePoint, and Microsoft 365 resources.
4. Lateral Movement – Once inside, attackers reuse compromised mailboxes to send new phishing emails, extending the attack chain to internal teams and external partners.
### Targets & Tactics
The campaign focuses on high-value organizations, including:
- Universities
- Enterprises
- Multinational institutions (e.g., EU and UN-linked bodies)
Phishing emails mimic routine business workflows, using urgent deadlines and familiar sender addresses to evade suspicion. Attackers exploit aged, legitimate-looking domains (e.g., testserveren[.]com) to bypass domain reputation checks, while RDGA-generated domains (e.g., consistenthostinghub[.]de) further obscure detection.
### Impact & Broader Threat Landscape
- Full Identity Inheritance – Stolen session cookies grant attackers authenticated access to email, files, and SaaS applications, enabling payroll fraud, data exfiltration, and further account takeovers.
- MFA Bypass – Since attackers proxy authentication flows in real time, MFA protections are rendered ineffective.
- Industry-Wide Trend – This campaign aligns with Storm-2755 and other AiTM attacks, where threat actors prioritize session hijacking over credential theft for deeper, persistent access.
### Detection Challenges & Defensive Insights
Traditional defenses MFA, URL filtering, and domain reputation checks struggle against these attacks. Infoblox recommends:
- DNS-based threat intelligence to detect infrastructure reuse and subdomain patterns.
- Continuous monitoring of Microsoft 365 sign-in behaviors to identify anomalous session activity.
- Conditional access policies to limit the lifespan of stolen sessions.
### Indicators of Compromise (IoCs)
Key domains linked to the campaign include:
- Compromised hosting domains: barifurniture[.]net, testserveren[.]com, satoriestate[.]com
- Phishing infrastructure: consistenthostinghub[.]de (FlowerStorm), assessmentevaluationreport[.]com (EvilProxy), duemineral[.]uk (Kali365)
The attack underscores the evolving sophistication of AiTM phishing, where trusted communication channels become attack vectors, and session-based compromises outpace traditional credential theft.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
753
MARCH 2026
752
FEBRUARY 2026
752
JANUARY 2026
767
Cyber Attack
19 Jan 2026 • Infoblox
Infoblox: Researchers Gained Access to Hacker Domain Server Using Name Server Delegation
Cybercriminals’ Push-Notification Scam Exposed by DNS Misconfiguration
751
LOW-16
INF1768815998
Cybercriminals’ Push-Notification Scam Exposed by DNS Misconfiguration
A recent investigation by Infoblox uncovered a large-scale push-notification scam targeting Android users, revealing how a simple DNS error exposed the criminal infrastructure behind it. The campaign bombarded victims with fake security alerts, gambling ads, and adult-content lures, generating revenue through clicks while evading detection behind random domains and hidden hosting.
The operation unraveled when a misconfigured name server left one of the attacker’s domains in a "lame delegation" state no longer resolving to a valid backend, yet still receiving traffic from infected devices. Infoblox researchers exploited this oversight by legitimately registering the abandoned domain, redirecting traffic to their own servers without altering victim devices or the attacker’s infrastructure.
Over several days, the team intercepted tens of millions of records from thousands of infected browsers worldwide. The data revealed aggressive tactics, including brand impersonation and scare-based messaging, with some users receiving over 100 notifications daily for months.
The infection process began when users visited compromised or malicious sites, tricked into enabling browser notifications amid deceptive pop-ups, cookie banners, and CAPTCHAs. Once granted, a hidden service worker embedded in the browser maintained persistent access, fetching updated scripts and ad templates from the attacker’s servers even after the original tab was closed.
The incident highlights how cybercriminals exploit web standards and poor DNS hygiene to sustain long-term access, while defenders can leverage misconfigurations to monitor and disrupt such operations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
767
NOVEMBER 2025
767
OCTOBER 2025
767
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Infoblox ??
What was Infoblox's A.I Rankiteo Cyber Score in August 2026 ??
What was Infoblox's A.I Rankiteo Cyber Score in July 2026 ??
What was Infoblox's A.I Rankiteo Cyber Score in June 2026 ??
What was Infoblox's A.I Rankiteo Cyber Score in May 2026 ??
What was Infoblox's A.I Rankiteo Cyber Score in April 2026 ??
What was Infoblox's A.I Rankiteo Cyber Score in March 2026 ??
What was Infoblox's A.I Rankiteo Cyber Score in February 2026 ??
What was Infoblox's A.I Rankiteo Cyber Score in January 2026 ??
What was Infoblox's A.I Rankiteo Cyber Score in December 2025 ??
What was Infoblox's A.I Rankiteo Cyber Score in November 2025 ??
What was Infoblox's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Infoblox's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Infoblox ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Infoblox's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?