Tag: phishing
-
Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens
A misconfigured server in Budapest exposed a live phishing operation built to bypass Microsoft 365 multi-factor authentication and retain access to compromised accounts. The server, hosted at 185.163.204[.]7185.163.204[.]7185.163.204[.]7, was running python3 -m http.server 8080 with directory listing enabled, making its operational files publicly accessible. Researchers found phishing configurations, Telegram session artifacts, credential logs, RMM installers,…
-
Operation Capsule Vault Uses Malicious ISO Files and Process Injection to Deliver RokRAT
Operation Capsule Vault began with spear-phishing emails sent on June 22, 2026, posing as notices distributing materials from a legitimate academic event. The lures referenced the “Why Wonsan-Kalma Tourism Now?” conference, held at Seoul COEX on June 12, and incorporated publicly available event details, including its subject matter and host organizations. By reusing real-world conference…
-
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
New Helix Extortion Group Targets Enterprises With MFA Abuse and SharePoint Exfiltration
A previously unreported data extortion operation dubbed “Helix” that targets enterprises using identity-focused entry techniques and automated SharePoint exfiltration. The group’s playbook combines voice phishing (vishing), device-code phishing to capture session tokens and bypass Conditional Access controls, rapid MFA registration for persistence, and scripted enumeration and bulk download of SharePoint content all staged from shared…
-
New Helix Extortion Group Targets Enterprises With MFA Abuse and SharePoint Exfiltration
A previously unreported data extortion operation dubbed “Helix” that targets enterprises using identity-focused entry techniques and automated SharePoint exfiltration. The group’s playbook combines voice phishing (vishing), device-code phishing to capture session tokens and bypass Conditional Access controls, rapid MFA registration for persistence, and scripted enumeration and bulk download of SharePoint content all staged from shared…
-
Claude AI Prompt Injection Attack Turns Chatbot Into Stealthy C2 Agent to Achieve Remote Code Execution
Claude Desktop’s synced Personal Preferences feature can be exploited as a covert prompt-injection vector, transforming the AI assistant into a de facto command-and-control (C2) agent. This method allows for remote code execution on a compromised user workstation without the need for phishing emails or traditional malware delivery. In this attack chain, the initial access is…
-
ESicherheit im Gesundheitswesen: Wenn eine Nachricht den Klinikbetrieb gefährdet
Management Summary E-Mail ist im Gesundheitswesen längst Teil der Versorgungskette und damit ein geschäftskritischer Angriffsvektor für Kliniken, MVZ und Praxen. Gesundheitsdaten verlangen mehr als Standard-Schutz: Vertraulichkeit, Verfügbarkeit und nachvollziehbare Zugriffe müssen im Alltag zusammenspielen. Phishing, kompromittierte Postfächer und manipulierte Anhänge treffen auf Zeitdruck, Vertrauen und viele externe Kommunikationspartner ideale Bedingungen für Angreifer. Wirksame… First seen…
-
Neue Sicherheitslösung unterstützt FIDO2 und PKI für gesicherten logischen Zugriff
Die Infineon Technologies AG bringt SECORA ID Key S USB auf den Markt, eine auf Java Card basierende Lösung mit USB- und NFC-Konnektivität für gesicherte Authentifizierung und digitale Signaturen. Als erste für FIDO Level 3+ zertifizierte und CTAP 2.1-konforme Lösung ermöglicht der Authentifikator eine phishing-resistente, passwortlose Authentifizierung sowie Schutz vor aus der Ferne durchgeführten Softwareangriffen……
-
Fake Job Offers Impersonate Netflix, OpenAI, and FIFA to Steal Google Credentials
A fake recruitment phishing campaign impersonates major brands and uses trusted HR platforms to steal Google account credentials. The post Fake Job Offers Impersonate Netflix, OpenAI, and FIFA to Steal Google Credentials appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-fake-recruitment-phishing-google-credentials-2026/
-
Armored Likho Hits Government, Energy Sectors With BusySnake Stealer
Kaspersky details how the newly named Armored Likho APT uses BusySnake Stealer, AI-generated loaders, and phishing to target government and energy organizations. First seen on hackread.com Jump to article: hackread.com/armored-likho-government-energy-busysnake-stealer/
-
This Popular Antivirus is on Sale for $19.99
ESET NOD32 Antivirus blocks malware, ransomware, and phishing for $19.99 a year without slowing your PC down. The post This Popular Antivirus is on Sale for $19.99 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/eset-nod32-antivirus-for-windows/
-
New Ghost Phishing Wave Is Breaking Traditional Email Security
A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser.For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365…
-
Phishing-Anfälligkeit in Europa sinkt nach eingesetzten Sicherheitsschulungen
Europäische Unternehmen erweitern ihre Belegschaft um autonome KI-Agenten und vergrößern die Angriffsfläche auf eine Weise, die von herkömmlichen Kontrollmaßnahmen nicht abgedeckt wird First seen on infopoint-security.de Jump to article: www.infopoint-security.de/phishing-anfaelligkeit-in-europa-sinkt-nach-eingesetzten-sicherheitsschulungen/a45696/
-
Indian Income Tax Department Phishing Lure Deploys Gh0st RAT and AsyncRAT Implants
A targeted phishing campaign impersonating the Indian Income Tax Department has been observed delivering a sophisticated, six-stage infection chain that culminates in two in-memory remote-access implants: a Gh0st RAT derivative and a Quasar/AsyncRAT-family .NET payload. Victims are funneled to fake government pages that mimic Ministry of Finance and Income Tax branding and are pressured with…
-
Big Brand Jobs Scam Targets Marketing Pros’ Google Accounts
The phishing campaign uses several tactics, including nested redirects, to evade detection and steal credentials from unsuspecting targets. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/big-brand-jobs-scam-marketing-pros-google-accounts
-
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC.”The campaign did not depend on a fake Microsoft password page. It used a malicious collaboration-style lure to push users into the…
-
Phishing Attacks Targeted Facebook Users With Fake Verification Offer
Attacks also used a compromised chatbot in campaign to steal sensitive information from Business Users First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/phishing-facebook-fake-verification/
-
Two arrested over credit card phishing as the Netherlands is named Europe’s worst for payment fraud
Two young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/two-arrested-credit-card-phishing-netherlands-europe-payment-fraud
-
Webinar tomorrow: Why modern email attacks require a new approach to defense
Tomorrow’s webinar explores how behavioral AI can help organizations detect sophisticated phishing, business email compromise, and account takeover attacks while reducing alert fatigue through automated investigation and response workflows. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/webinar-tomorrow-why-modern-email-attacks-require-a-new-approach-to-defense/
-
Attackers Exfiltrate AnyDesk Configuration Data via Blat SMTP in Aerospace Phishing Campaign
A targeted spear-phishing campaign that configures AnyDesk for silent, persistent remote access and exfiltrates its configuration using the Blat SMTP utility. The campaign uses an aerospace-themed invoice lure that impersonates the Russian research institute VNIIR via a freshly registered spoof domain (vniir-avia.space) and delivers a password-protected archive that, when opened, triggers a multi-stage dropper and…
-
4 Best Email Security Solutions to Keep Employee Inboxes Safe
Compare leading and best email security solutions with AI threat detection, phishing defense, malware blocking, and DLP features for teams. First seen on hackread.com Jump to article: hackread.com/best-email-security-solutions-employee-inboxes-safe/
-
AI-Generated Malware Powers New Armored Likho APT Campaign
Armored Likho APT uses AI-generated malware, phishing, and BusySnake Stealer to target governments and power grids in Russia, Kazakhstan, and Brazil. Kaspersky’s threat research team has documented a previously unknown APT group they’re calling Armored Likho, also tracked under the name Eagle Werewolf. The group runs two parallel tracks: financially motivated attacks against private individuals…
-
Fake Interview Phishing Campaign Impersonates Top Brands to Steal Gmail Credentials
A sophisticated interview-themed phishing campaign that impersonates major global brands to harvest Gmail credentials. Attackers pose as recruiters offering marketing roles at well-known companies, leveraging personalized targeting and a layered redirection chain that uses legitimate platforms to mask malicious intent. The result is a convincing lure that directs recipients to a Gmail credential prompt embedded…
-
Phishing poses as big-brand job interview to steal Google accounts
A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/phishing-poses-as-big-brand-job-interview-to-steal-google-accounts/
-
WM 2026: KnowBe4-Bericht zeigt Anstieg von Phishing mit FIFA-Fakes, Tickets und Gewinnspielen
Fans sollten Angebote grundsätzlich über offizielle Kanäle prüfen, keine Zugangsdaten über Links aus E-Mails eingeben und bei Gewinnversprechen skeptisch bleiben. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/wm-2026-knowbe4-bericht-zeigt-anstieg-von-phishing-mit-fifa-fakes-tickets-und-gewinnspielen/a45686/
-
Hackers Use Trusted Microsoft Domain and One-Time Codes to Hijack Corporate Accounts
A rising phishing technique is exploiting a legitimate Microsoft authentication flow to hijack corporate accounts without stealing passwords. Attackers are weaponizing the OAuth 2.0 Device Authorization Grant commonly used to sign in input-constrained devices via a one-time user code to trick victims into approving access on Microsoft’s own domain. Because the final authentication occurs on…

