Tag: phishing
-
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.”Greatness supports AiTM [adversary-in-the-middle] credential and First seen on thehackernews.com…
-
Hackers Claim They Stole a Directory of 135,000 UK Police Contacts
A new hacking group claims it stole 135,000 records from a UK police platform, exposing contact details that could support phishing and impersonation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-uk-police-pnld-data-breach-exfilsquad-emea/
-
Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass
Researchers at Huntress have identified an active phishing campaign impersonating Bank of America that culminates in the covert installation of a remote monitoring and management (RMM) tool, giving attackers persistent, hard-to-detect access to victims’ Windows machines. The campaign was flagged after a message landed in one of Huntress’s spamtrap accounts on 28 July, sent from…
-
PNLD Data Breach Exposes Police and Government Contact Details on Dark Web
The PNLD data breach has exposed contact information belonging to police officers, government partners, criminal justice professionals and customers after data from the Police National Legal Database (PNLD) was published on the dark web. The data breach at PNLD, identified on July 26, 2026, also affected some users of Ask the Police, raising concerns about targeted phishing attacks. First seen on thecyberexpress.com Jump to…
-
Unzerstörbare Phishing-as-aPlattformen – Warum Phishing-Kits wie Tycoon 2FA Zerschlagungen einfach überleben
First seen on security-insider.de Jump to article: www.security-insider.de/tycoon-2fa-zerschlagung-phishing-phaas-a-6a145d01694016cc3939c40d6ff97d2a/
-
KI macht Smartphones zur neuen Hochrisiko-Zone der Unternehmens-IT
Mobile Endgeräte rücken durch KI-gestützte Angriffe ins Zentrum der Cyberabwehr. Der »Global Mobile Threat Report 2026« von Zimperium zeigt, wie stark Phishing, Spyware, Schatten-KI und unsichere KI-generierte Apps die mobile Sicherheitslage in Unternehmen verschärfen und warum klassische Endpoint-Strategien nicht mehr ausreichen. Management Summary Mobile Security wird zur KI-Frage: KI-gesteuerte Phishing-Angriffe auf Mobilgeräte sind laut… First…
-
PNLD Confirms Data Breach Affecting UK Police and Justice Staff
UK police legal database breach exposed officers’ names and work emails, increasing phishing risks. NCA is investigating. The Police National Legal Database (PNLD), the legal reference system used by all 43 Home Office police forces in England and Wales, confirmed that a data breach exposed the contact details of police officers, staff, and criminal justice…
-
AI cut phishing from hours to seconds, which is where DMARC and BIMI come in
In this Help Net Security video, Mike Boyle, VP of Business Units at GMO GlobalSign, and Rahul Powar, CEO and founder of Red Sift, unpack the evolution of email security and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/dmarc-and-bimi-video/
-
Product showcase: Guardio Mobile Security turns breach alerts into a recovery plan
Guardio Mobile Security brings several protection features to iPhone and Android, allowing users to monitor exposed personal information, identify phishing attempts, and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/product-showcase-guardio-mobile-security/
-
AiTM phishing overtakes credential theft as top threat to law firms
First seen on scworld.com Jump to article: www.scworld.com/brief/aitm-phishing-overtakes-credential-theft-as-top-threat-to-law-firms
-
South Korea Warns of State-Backed Watering Hole Attacks
South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean…
-
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that First…
-
XRP Volatility Surges as Cybersecurity Threats and Market Changes Raise New Concerns
XRP volatility drives faster crypto trading as AI tools gain traction, while phishing, exchange attacks and automation risks test digital asset safeguards. First seen on hackread.com Jump to article: hackread.com/xrp-volatility-cybersecurity-threats-market-changes/
-
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing – the abuse of the OAuth 2.0 device authorization grant to steal access tokens – has evolved from a niche red-team technique to an industrial-scale threat in under six months.Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range…
-
KnowBe4 erweitert Sicherheitstraining um Vishing-Simulationen gegen Voice-Phishing und KI-Stimmklone
KnowBe4 erweitert seine Plattform um realistische Vishing-Simulationen und trainiert Mitarbeiter gegen Voice-Phishing, KI-Stimmklone und Telefonbetrug. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/knowbe4-erweitert-sicherheitstraining-um-vishing-simulationen-gegen-voice-phishing-und-ki-stimmklone/a45966/
-
Phishing 2026: Warum technische Abwehr nicht mehr reicht
Das größte Einfallstor der Angreifer bleibt Phishing. Der Lagebericht des BSI zur IT-Sicherheit in Deutschland führt seit vielen Jahren Phishing als eines der häufigsten Einfallstore für Ransomware und Datenabfluss an. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/phishing-2026-abwehr
-
Phishing-Kit Logokit baut Anmeldeseiten in Echtzeit nach
Die Phishing-as-a-Service-Plattform Logokit erstellt inzwischen für jedes Opfer individuell nachgebildete Anmeldeseiten in Echtzeit. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/phishing-kit-logokit
-
BCON Collective uncovers shared phishing infrastructure linked to ShinyHunters
Bridewell’s BCON Collective has uncovered an active phishing infrastructure spanning more than 100 malicious domains after investigating what initially appeared to be a routine blocked vishing attempt against one of its customers. The investigation found evidence suggesting the campaign is linked to the ShinyHunters cybercriminal group and revealed that the same phishing kit is being…
-
Astaroth Banking Trojan Adds WhatsApp Web Spambot to Spread Malware Across Brazil
Astaroth operators have expanded their Brazilian banking malware operations by weaponizing a new WhatsApp Web spambot module that turns infected hosts into automated malware relays, marking a significant evolution of the LATAM e-crime ecosystem. Traditionally propagated via email and archive-based phishing, recent campaigns such as STAC3150 and the “Boto Cor-de-Rosa” operation shifted distribution to WhatsApp…
-
AiTM Phishing Becomes Top Initial Access Threat to Law Firms
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/aitm-phishing-top-entry-point-law/
-
ChatGPT Joins Most Faked Brands Ranking in Phishing, Check Point Says
ChatGPT entered Check Point’s top 10 phishing brand ranking as fake ChatGPT Plus payment failure emails targeted users’ credit card details. The post ChatGPT Joins Most Faked Brands Ranking in Phishing, Check Point Says appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-chatgpt-top-10-phishing-brand-ranking/
-
Is Your SSO Protected Against Modern Credential Attacks?
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/is-your-sso-protected-against-modern-credential-attacks/
-
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/
-
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/
-
Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure patterns are already being repurposed in ongoing campaigns targeting Microsoft 365 environments. Despite being disrupted under Operation Olympus Blade, which led to the seizure of…
-
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Talos IR’s Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/ir-trends-q2-2026/

