Tag: phishing
-
Hackers Turn AI Agent Into a Cyber Weapon After Deleting Its Safety Refusals
A French-speaking cybercrime crew calling itself BlackHatSect0r && DXQRTXX allegedly disabled safety controls in a self-hosted AI agent and used the resulting system to automate mass credential harvesting, target discovery, phishing preparation, and attack orchestration. The internet-exposed server reportedly contained 4.9 GB of material across 9,299 files, including a custom Go-based command-and-control platform named DXSCAN,…
-
BlackHatSect0r Hackers Disable AI Safety Controls to Automate Credential Theft and Cyberattacks
Tags: ai, attack, control, credentials, cyber, cyberattack, cybercrime, data-breach, hacker, Internet, phishing, theftA French-speaking cybercrime crew calling itself BlackHatSect0r && DXQRTXX allegedly disabled safety controls in a self-hosted AI agent and used the resulting system to automate mass credential harvesting, target discovery, phishing preparation, and attack orchestration. The internet-exposed server reportedly contained 4.9 GB of material across 9,299 files, including a custom Go-based command-and-control platform named DXSCAN,…
-
SpearKampagne mit In-Memory-InfoStealer entdeckt
Konkret erstellten die Angreifer der jüngst durch Arctic Wolf aufgedeckten Spear-Phishing-Kampagne Phishing-Köder, die sich in drei Ländern als Baltic Control ausgaben. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/spear-phishing-memory-infostealer
-
FBI Warns About OAuth Consent Phishing Risks for K12 Schools
What you need to know about OAuth phishing and tips for protecting your district A staff member sees a familiar Google or Microsoft sign-in page while connecting what appears to be a legitimate app. The user signs in, sees a… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/fbi-warns-about-oauth-consent-phishing-risks-for-k12-schools/
-
Phishing mit gefälschten Voicemail-Transkripten
Die Sicherheitsforscher von Check Point Research haben eine groß angelegte Phishing-Kampagne aufgedeckt, bei der automatisierte Voicemail-Transkripte imitiert werden. Zwischen dem 17. und 31. August verzeichneten Forscher mehr als 58.000 bösartige E-Mails, die über 7.800 Organisationen erreichten und von mehr als 38.400 gefälschten Absenderadressen über mehr als 9.300 gefälschte Domains versendet wurden. Jede E-Mail täuscht die…
-
Phishing-Tool nutzt KI für voll automatisierte Vishing-Angriffe
Sicherheitsforscher von Group IB sind auf neue Entwicklungen im Bereich des Voice-Phishings (Vishing) gestoßen. Die in die Phishing-as-a-Service-(PhaaS-) Plattform ‘Balonx” integrierte Anwendung ‘CallFlow” kann mithilfe von mehreren KI-Systemen Phishing-Anrufe ohne menschliche Beteiligung führen. Dies könnte die Anzahl um ein Vielfaches erhöhen. Momentan konzentrieren sich die durch Callflow operierten Vishing-Angriffe vor allem auf Mexiko, eine weltweite…
-
SpearKampagne mit In-Memory-Infostealer
Das Arctic Wolf Adversary Research Team hat eine Phishing-Kampagne mit Beschaffungsbezug aufgedeckt, die sich gegen Gesundheitseinrichtungen, Industrieunternehmen und kritische Infrastrukturen in Mittel- und Osteuropa richtet. Justin Moore, Director of Adversary Research bei Arctic Wolf, gibt Einblicke in die Spear-Phishing-Kampagne. ‘Konkret erstellten die Angreifer der jüngst durch Arctic Wolf aufgedeckten Spear-Phishing-Kampagne Phishing-Köder, die sich in drei…
-
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity.From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud First…
-
Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials
A large-scale SMS phishing campaign linked to the Smishing Triad is using a sophisticated phishing kit dubbed JWR to harvest payment-card data, one-time passwords, online-banking credentials, identity information, and digital-wallet logins. Group-IB attributed the activity to an operator sub-cluster tracked as Outsider, which appears to operate as a customer within the wider phishing-as-a-service ecosystem rather…
-
PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian recipients and reflects a broader China-nexus pattern of tax-themed malware activity, although the available evidence does not support definitive attribution…
-
PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian recipients and reflects a broader China-nexus pattern of tax-themed malware activity, although the available evidence does not support definitive attribution…
-
PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian recipients and reflects a broader China-nexus pattern of tax-themed malware activity, although the available evidence does not support definitive attribution…
-
Google Search Makes It Harder to See Where a Link Really Goes Before You Click
Google has begun routing some organic Search result links through opaque google.com/goto?url=… redirects, reducing users’ ability to independently inspect a destination URL before clicking. The change appears designed to raise the technical and financial cost of mass scraping. However, it also weakens a long-standing, basic anti-phishing habit: hovering over a link to verify where it…
-
Google Search Makes It Harder to See Where a Link Really Goes Before You Click
Google has begun routing some organic Search result links through opaque google.com/goto?url=… redirects, reducing users’ ability to independently inspect a destination URL before clicking. The change appears designed to raise the technical and financial cost of mass scraping. However, it also weakens a long-standing, basic anti-phishing habit: hovering over a link to verify where it…
-
Google Search Makes It Harder to See Where a Link Really Goes Before You Click
Google has begun routing some organic Search result links through opaque google.com/goto?url=… redirects, reducing users’ ability to independently inspect a destination URL before clicking. The change appears designed to raise the technical and financial cost of mass scraping. However, it also weakens a long-standing, basic anti-phishing habit: hovering over a link to verify where it…
-
MSN Op September is the Most Dangerous Month for AI Phishing
This article was originally published in MSN on 9/10/26 by Charlie Sander. Here’s what schools should focus on the first weeks back to protect your data and systems. For cybercriminals, the start of the school year is a particularly attractive… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/msn-op-ed-september-is-the-most-dangerous-month-for-ai-phishing/
-
MSN Op September is the Most Dangerous Month for AI Phishing
This article was originally published in MSN on 9/10/26 by Charlie Sander. Here’s what schools should focus on the first weeks back to protect your data and systems. For cybercriminals, the start of the school year is a particularly attractive… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/msn-op-ed-september-is-the-most-dangerous-month-for-ai-phishing/
-
Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
Tags: attack, cyber, email, infrastructure, mail, malicious, malware, open-source, phishing, servicePhishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated domains, and multi-stage URL cloaking designed to defeat conventional email inspection. The continuously running VBSpam comparative test evaluated ten public full email-security products and one open-source solution against wanted, unwanted, and malicious mail streams. The assessment was conducted under the…
-
KI übernimmt den Phishing-Anruf: Vishing wird zur automatisierten Cybercrime-Maschine
KI automatisiert Voice-Phishing: CallFlow kombiniert Sprachmodelle, Voice-KI und Transkription zu skalierbaren Vishing-Angriffen ohne menschliche Call-Operatoren. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ki-uebernimmt-den-phishing-anruf-vishing-wird-zur-automatisierten-cybercrime-maschine/a46404/
-
53 Prozent mehr Cyber-Angriffe auf deutsche Unternehmen im August
Der Monthly-Cyber-Threat-Report für August 2026 von Check Point Research (CPR), die Sicherheitsforschungsabteilung von Check Point Software Technologies, zeigt einen Anstieg globaler Cyber-Angriffe um 22 Prozent. Auch Phishing-Mails und Ransomware-Angriffe nehmen weltweit deutlich zu. Im vergangenen Monat verzeichneten Unternehmen Analysen von Check Point Research zufolge weltweit durchschnittlich 2422 Cyber-Angriffe pro Woche. Dies entspricht einem Anstieg von…
-
Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
IntroductionSecurity teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continuously rather than as a one-off exercise.But no matter how much…
-
One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several…
-
Brevo Breach Sends Trezor Phishing Email to 347,000 Subscribers
A Brevo breach allowed attackers to send Trezor phishing emails to 347,000 subscribers, exposing security risks created by trusted third-party vendors. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-brevo-trezor-phishing-email-347000-subscribers/
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
Microsoft 365 Passkey Phishing Turns Login Into a Cloud Breach
Microsoft warns that passkey-themed phishing is hijacking Microsoft 365 accounts, adding rogue MFA methods, and slowly stealing business cloud data. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-passkey-phishing-microsoft-365-cloud-data/
-
Phishing ohne Webserver: Neuartige Browser-Angriffe aufgedeckt
Angreifer generieren gefälschte Anmeldeseiten mittels Blob-URLs direkt im Arbeitsspeicher der Opfer. Der Missbrauch vertrauenswürdiger Microsoft-Dienste hebelt klassische Filter aus. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/phishing-ohne-webserver
-
Detecting OAuth consent phishing in Microsoft 365 audit logs
OAuth consent phishing is a practical identity attack that abuses the trust users place in application consent prompts. Instead of stealing a password directly, the attacker persuades a user to grant a malicious app access to mailbox data, profile information,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-oauth-consent-phishing-in-microsoft-365-audit-logs/

