Tag: phishing
-
Hackers Abuse MSP360 and ScreenConnect RMM Tools for Persistent Access and Credential Theft
Tags: access, credentials, cyber, exploit, hacker, malware, monitoring, phishing, software, theft, tool, vulnerability, windowsThe phishing campaigns that weaponize legitimate remote monitoring and management software to establish persistent access and support credential theft on Windows systems. The campaign demonstrates a recurring operational trend: rather than exploit a vulnerability or deploy obvious custom malware, attackers are abusing trusted administrative platforms already designed to execute commands, transfer files, deploy applications, and…
-
Former US Air Force members behind million-dollar BEC scheme head to prison
Tags: phishingTwo men who ran BEC and phishing campaigns against US businesses while serving in the Air Force have been sentenced to a combined 189 months in federal prison. According to … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/30/air-force-members-sentenced-bec-phishing/
-
Former US Air Force members sent to prison over BEC attacks
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/
-
Phishing Exposure Nears 70% Across Key US Industries. What Should Security Teams Do?
Phishing exposure reached 69.9% across five key US industries, with finance and manufacturing facing the highest levels, according to ANY.RUN data. First seen on hackread.com Jump to article: hackread.com/phishing-exposure-us-industries-security-teams-to-do/
-
âš¡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface.Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work…
-
Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data
Tags: ai, breach, control, credentials, cyber, cybercrime, data, data-breach, infrastructure, Internet, phishing, toolAn internet-exposed cybercrime server linked to the BlackHatSect0r and DXQRTXX personas, revealing an operational environment that allegedly combined AI-assisted automation. Custom command-and-control tooling, phishing resources, stolen credentials, target lists, and internal operator communications. The exposure is notable not only for the scale of the material recovered, but also for its irony. Weeks later, infrastructure attributed…
-
Microsoft Entra TrustSink Attack Uses Rogue MFA Provider to Steal Passwords
TrustSink, a post-compromise credential-phishing technique that abuses Microsoft Entra External Authentication Methods (EAMs) to place a rogue password prompt inside an otherwise legitimate Microsoft sign-in flow. The attack enables an adversary with elevated tenant privileges to capture plaintext passwords while returning a valid signed token to Entra, allowing the victim’s login to complete without an…
-
Researchers Identify AliExpress Phishing Domains Before Registration
Tags: phishingEfficientIP says it flagged AliExpress phishing domains before they were registered First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/aliexpress-phishing-flagged-early/
-
Researchers Identify AliExpress Phishing Domains Before Registration
Tags: phishingEfficientIP says it flagged AliExpress phishing domains before they were registered First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/aliexpress-phishing-flagged-early/
-
‘Salesbleed’ Exploits Salesforce Agents to Enable Slack Phishing
Agentic AI can smuggle arbitrary instructions from the Web, across multiple apps, into trusted internal communications channels. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishing
-
Microsoft Disrupts EvilTokens Device Code Phishing Service
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts. First seen on darkreading.com Jump to article: www.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-service
-
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.”The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The…
-
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
The popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-eviltokens-cybercrime-service-takedown/
-
The next intellectual property thief may sound like your CEO
Impersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC’s The State of Online IP Risk 2026 … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/22/csc-online-intellectual-property-risk-report/
-
Cyberangriff auf Berliner Landesverwaltung zeigt Risiken für die gesamte öffentliche Hand
Der Cyberangriff auf Berlins Landesverwaltung zeigt: Gestohlene Behördendaten können Phishing und Folgeangriffe auf die gesamte öffentliche Hand ermöglichen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cyberangriff-auf-berliner-landesverwaltung-zeigt-risiken-fuer-die-gesamte-oeffentliche-hand/a46444/
-
Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits
A third Chinese threat actor has been linked to phishing campaigns that cloned trusted websites and chained Chrome and Windows zero-day exploits to deploy a previously undocumented backdoor. The activity occurred on September 3 and 4, 2026, while the targeted vulnerabilities remained unpatched in Google Chrome. It followed Volexity’s September 9 disclosure that UTA0560 and…
-
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities.”SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols,” Trellix researchers First seen on thehackernews.com Jump to…
-
Microsoft to Disable SMS as Primary Entra ID Sign-In Method in 2027
Microsoft will turn off SMS as a primary sign-in method for Microsoft Entra ID workforce tenants on February 1, 2027, accelerating its transition to phishing-resistant authentication. This change affects workers who currently use a registered phone number and a one-time SMS code as their initial sign-in credential, a passwordless flow utilized by frontline organizations. Microsoft…
-
Ambry Genetics Pays $700K HIPAA Fine in Phishing Breach
Settlement Comes After Firm Paid Nearly $12.3M to Settle Civil Claim for Same Hack. A genetics testing lab has agreed to pay a $700,000 HIPAA settlement and improve its security practices in the wake of a 2020 phishing hack that affected 225,370 patients. The firm paid a $12.25 million civil class action settlement in 2023…
-
Microsoft reminds admins to migrate Entra ID users to passkeys
Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-reminds-admins-to-migrate-entra-id-users-to-passkeys/
-
Revolut Customers Targeted with New Wave of Phishing Attacks
Following a major data breach, Revolut customers are being sent convincing phishing messages First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/revolut-customers-targeted-wave/
-
Hackers Are Using Passkey Updates as a New Microsoft Phishing Hook
Microsoft warns attackers are using passkey and MFA update requests to phish employees, hijack sessions, and access Microsoft 365 data. The post Hackers Are Using Passkey Updates as a New Microsoft Phishing Hook appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-passkey-phishing-mfa-device-code/
-
AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum
AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s…
-
ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts
Threat actors are increasingly impersonating OpenAI’s ChatGPT service in credential-phishing campaigns, exploiting the growing use of generative AI across both enterprise and personal environments. A recently observed campaign uses a fraudulent subscription-payment notice to lure victims into disclosing OpenAI account credentials and potentially payment details through a convincing fake ChatGPT login page. The lure claims…
-
Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links
A large-scale SMS phishing campaign is impersonating T-Mobile and warning recipients that their “rewards points” are about to expire, using fabricated balances, urgent deadlines, and lookalike redemption links to steal sensitive information. Security researchers have tracked the operation since early May 2026 and continue to observe new message variants despite a decline from its peak…
-
A fake ChatGPT billing email is after your OpenAI password
A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/chatgpt-phishing-email-openai-password/
-
Hackers Turn AI Agent Into a Cyber Weapon After Deleting Its Safety Refusals
A French-speaking cybercrime crew calling itself BlackHatSect0r && DXQRTXX allegedly disabled safety controls in a self-hosted AI agent and used the resulting system to automate mass credential harvesting, target discovery, phishing preparation, and attack orchestration. The internet-exposed server reportedly contained 4.9 GB of material across 9,299 files, including a custom Go-based command-and-control platform named DXSCAN,…

