Tag: phishing
-
Fortune 100: KI-gestützte Phishing-Angriffe auf 86 Prozent der großen Welt-Unternehmen
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/fortune-100-ki-phishing-angriffe-86-prozent-welt-unternehmen
-
Million Email Phishing Campaign Uses Text Salting
Barracuda researchers identified more than one million phishing emails using text salting to manipulate AI-powered email security. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/million-email-phishing-campaign-uses-text-salting/
-
ISMG Editors: AI Phishing Kits Go Mainstream
Also: Potential Fallout From HIPAA Rule Delay, AI Identity Governance Challenges. In this week’s panel, four ISMG editors discussed the rise of artificial intelligence-powered phishing toolkits, potential fallout from the U.S. government’s decision to delay a major overhaul of the HIPAA Security Rule and what security leaders see as the defining AI security challenges of…
-
Smartphone-Diebstahl: Betrüger locken mit Fake-SMS in Phishing-Falle
Smartphone-Diebstahl im Urlaub: Mit Fake-SMS locken Kriminelle Opfer in eine Phishing-Falle. So schützt du Apple-ID und Google-Konto. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/smartphone-diebstahl-fake-sms-phishing-falle-331552.html
-
“TTF Trap” Phishing Emails Use Fake Font Files to Deliver Windows Malware
An email that appears to contain a shipping document, payment request, or business proposal can infect a Windows… First seen on hackread.com Jump to article: hackread.com/ttf-trap-phishing-fake-font-files-windows-malware/
-
The script, not the voice, is what makes AI voice phishing work
The call comes in at 4:40 on a Friday. The voice belongs to a senior manager, or sounds close enough, and she needs a password reset before a flight. She is polite, she is in … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/17/research-ai-voice-phishing/
-
Five-Layer Fileless Malware Uses JScript and PowerShell to Evade AMSI and Load .NET Payload
An active phishing campaign using a five-layer, fileless malware loader to evade Microsoft’s Antimalware Scan Interface (AMSI), static detection controls, and disk-based forensic analysis. The campaign delivers a Windows Script Host JScript payload inside a TAR archive disguised as a purchase order, ultimately loading a .NET assembly directly into memory. The activity was first observed…
-
Kalender-Phishing: Cyberangreifer missbrauchen als harmlos geltende Pfade
Tags: phishingFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/kalender-phishing-cyberangreifer-missbrauch-harmlos-geltende-pfade
-
1M+ Emails Use Hidden Text to Dupe AI Security Filters
Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/1m-emails-hidden-text-dupe-ai-security-filters
-
Iran-nexus actors using AI to enhance cyber playbook
A report shows state-linked and hacktivist groups have used ChatGPT and other tools for malware development, phishing and mapping out industrial sites. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/iran-nexus-actors-ai-cyber-ChatGPT-malware/825415/
-
Phishing Campaign Hides Lua Loader as TrueType Font File
Global phishing campaign disguised a Lua loader as a font file to deploy RATs and infostealers First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/phishing-lua-loader-truetype-font/
-
CloudMail-Sicherheit: KnowBe4 zeigt Maßnahmen zum Schutz vor Phishing und Kontoübernahmen
Viele Unternehmen gehen davon aus, dass ihr Cloud-Anbieter E-Mail-Daten automatisch und dauerhaft schützt. Diese Annahme kann sich im Ernstfall als problematisch erweisen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cloud-e-mail-sicherheit-knowbe4-zeigt-massnahmen-zum-schutz-vor-phishing-und-kontouebernahmen/a45770/
-
Phishing Toolkits Harvest Entra Tokens in Real Time
Jalisco Device Code Phishing Tool Use Also Tied to EvilTokens and Kali365 Customers. Sophisticated phishing-as-a-service toolkits are driving a surge in phishing attack volume, experts warn, by giving users highly automated tools for personalizing lures and accessing previously niche tactics for generating valid authentication tokens for persistent access. First seen on govinfosecurity.com Jump to article:…
-
Phishing-as-a-Service: Cybercrime im Abo
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/phishing-as-a-service-cybercrime-abo
-
Phishing-as-a-Service: Cybercrime im Abo
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/phishing-as-a-service-cybercrime-abo
-
Phishing-as-a-Service: Cybercrime im Abo
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/phishing-as-a-service-cybercrime-abo
-
LastPass, Bitwarden users targeted with fake security alerts
Tags: phishingLastPass is warning users about an ongoing phishing campaign that is using fake security notices to direct them to fraudulent websites. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-targeted-with-fake-security-alerts/
-
Phishing aus dem Baukasten: So einfach kaufen Cyberkriminelle heute komplette Angriffe
Wer weiterhin ausschließlich auf Passwörter, Einmalcodes oder Push-Bestätigungen setzt, überlässt einen entscheidenden Teil der Sicherheit dem Verhalten einzelner Mitarbeiter. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/phishing-aus-dem-baukasten-so-einfach-kaufen-cyberkriminelle-heute-komplette-angriffe/a45749/
-
Phishing-as-a-Service Wenn Cyberkriminalität zum Abo-Modell wird
Mitte Juni hat das FBI im Rahmen der Operation Ghost-Hook gemeinsam mit Google und Black Lotus Labs die Plattform Outsider vom Netz genommen, einer der größten bislang bekannten Phishing-as-a-Service-Anbieter. Seit 2023 lieferte der Dienst Cyberkriminellen Phishing-Infrastruktur mit über 290 fertigen Vorlagen, die Banken, Behörden, Telekommunikationsanbieter und Einzelhändler imitierten. Die Ermittler nehmen an, dass seit der…
-
New phishing kits target Microsoft 365 accounts, evade MFA
Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accounts-evade-mfa/
-
Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads
Cybercriminals are operating an industrial-scale fraud ecosystem targeting Turkey’s financial sector, using more than 8,400 phishing domains, thousands of social media advertisements, fake loan offers, illicit gambling services, and money-mule recruitment to steal credentials. Group-IB’s investigation links these operations into five interconnected schemes targeting dozens of Turkish banking brands. Group-IB recorded more than 6,600 scam…
-
How to Defend Against AI-Powered Identity Fraud
e=4>Discover how deepfakes, voice cloning, and AI-powered phishing are reshaping digital deception”, and learn practical strategies to strengthen identity security with real-time, AI-driven defenses. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-to-defend-against-ai-powered-identity-fraud-a-32211
-
Open Directory Exposes Three Evilginx Phishing Operators
Misconfigured server exposed three phishing operators running Evilginx forks to bypass MFA First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/open-directory-exposes-evilginx/
-
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts.Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing First seen on thehackernews.com Jump to article:…
-
Turning the Tables on Email Scammers With ‘ScamBuster’
An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/turning-tables-email-scammers-scambuster
-
Dutch Nationals Suspected in Odido Hack That Exposed Six Million Customers
Dutch police suspect local hackers behind the Odido breach that exposed 6M customers after a phishing attack and seek public help identifying them. Dutch police have identified strong indications that Dutch nationals were involved in the February 2026 cyberattack on telecom provider Odido, which resulted in data from more than six million customers being stolen…
-
Spear-Phishing Campaign Uses Proton Drive Links and LNK Files to Deliver SpyGlace
The APT-C-60 threat actor has continued targeting Japanese organizations with a spear-phishing campaign that abuses Proton Drive, Windows shortcut files, trusted developer platforms, and native Windows utilities to deliver the SpyGlace malware. While the group retains several established tradecraft elements, including the abuse of legitimate services and the use of git.exe to execute malicious scripts,…
-
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history.From that one lapse, French security firm Lexfo lifted the operator’s entire toolkit and pivoted through…
-
Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens
A misconfigured server in Budapest exposed a live phishing operation built to bypass Microsoft 365 multi-factor authentication and retain access to compromised accounts. The server, hosted at 185.163.204[.]7185.163.204[.]7185.163.204[.]7, was running python3 -m http.server 8080 with directory listing enabled, making its operational files publicly accessible. Researchers found phishing configurations, Telegram session artifacts, credential logs, RMM installers,…
-
Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens
A misconfigured server in Budapest exposed a live phishing operation built to bypass Microsoft 365 multi-factor authentication and retain access to compromised accounts. The server, hosted at 185.163.204[.]7185.163.204[.]7185.163.204[.]7, was running python3 -m http.server 8080 with directory listing enabled, making its operational files publicly accessible. Researchers found phishing configurations, Telegram session artifacts, credential logs, RMM installers,…

