Tag: phishing
-
Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates…
-
Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates…
-
Saturday Security: AI Industrializes Phishing
This week’s Saturday Security Story shows how AI is industrializing an old scam, and doing it at a scale that should get everyone’s attention. Microsoft spotted a campaign that blasted more than 1 million fraudulent emails across a three-day… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/saturday-security-ai-industrializes-phishing/
-
Six Nigerians extradited to US over $6M online romance scam
Alleged members of Black Axe criminal network that swindled US women out of $6m flown from South AfricaSix Nigerian nationals linked to an organized criminal network that allegedly swindled American women out of more than $6m through <a href=”https://apnews.com/article/scams-online-scams-ai-internet-safety-phishing-fraud-takeaways-b1350fd421cce73ac585a649b07332d5″>online romance scams were extradited to the United States on Friday.<a href=”https://www.theguardian.com/world/southafrica”>South African police confirmed they were…
-
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on September 1, 2026, as using identical browser-to-kernel exploit components but ultimately installing separate espionage payloads: the GRIMWEDGE JScript backdoor and the LONGTALE credential-stealing Chrome…
-
New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets
A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files, conduct system reconnaissance, and potentially deploy payloads designed to steal credentials and local secrets. Fortra’s Intelligence and Research Experts (FIRE) said the activity began in June and remains active, with operators regularly recompiling malware samples to…
-
The Cost of Silence: Why Fear Kills Phishing Reporting
An employee clicks a link in an urgent email that seems to come from payroll. A login page flashes, then vanishes. In that split second, a cold wave of dread hits them. Their stomach drops, their heart rate spikes, and their… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-cost-of-silence-why-fear-kills-phishing-reporting/
-
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hackers-us-business-hours-m365/
-
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/
-
Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
Threat actors are using AI-assisted phishing templates, executive impersonation, fake ServiceNow invoices, and fabricated email threads to pressure finance teams into authorizing fraudulent ACH payments worth nearly $50,000. Microsoft detected more than one million messages in the campaign, demonstrating how business email compromise (BEC) operations are becoming more polished, scalable, and difficult to spot. The…
-
Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
Threat actors are using AI-assisted phishing templates, executive impersonation, fake ServiceNow invoices, and fabricated email threads to pressure finance teams into authorizing fraudulent ACH payments worth nearly $50,000. Microsoft detected more than one million messages in the campaign, demonstrating how business email compromise (BEC) operations are becoming more polished, scalable, and difficult to spot. The…
-
12 Best Server Security Solutions Compared (2026): Features Pricing
Quick Answer: CrowdStrike and SentinelOne lead server EDR; Trend Micro Deep Security owns virtual patching for unpatchable estates; Microsoft Defender for Servers is the per-resource anchor for Azure/hybrid; Bitdefender and ESET deliver efficacy at value. Server pricing runs per server/workload always confirm Linux feature parity. Servers are where ransomware crews head after the first phish:…
-
Hackers Abuse Claude AI Agents to Automate Cyberattacks, Exploitation and Data Theft
Threat actors increasingly deploy AI agents as operational systems for cyberattacks, moving beyond simple chatbot assistants. These AI systems automate various stages of the cyber kill chain, including reconnaissance, phishing, exploitation, persistence, and bulk data theft. Anthropic reported disrupting multiple such operations between December 2025 and August 2026, involving groups suspected to be linked to…
-
Companies may be measuring phishing resilience the wrong way
Companies that judge phishing simulation programs by how often employees click simulated attack emails may be overlooking more important indicators of cyber resilience, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/11/pistachio-employee-phishing-risk-report/
-
Multiple crypto companies warn customers of phishing emails after alleged provider breach
Subscribers to newsletters from Trezor, CoinTracking and BitBox received corrupted messages through an email provider that all three companies use. First seen on therecord.media Jump to article: therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders
-
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?”An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up…
-
Cryptohack Roundup: Trezor’s Phishing Warning
Also: ‘White-Hat’ Hackers Withdraw $320M From Liquid. Every week, ISMG rounds up cybersecurity incidents in digital assets. This week, Trezor warns customers after email provider breach, Liquid pauses network after $320 million Bitcoin withdrawal, man pleads guilty in $245 million theft and India targets 15 crypto platforms over compliance failures. First seen on govinfosecurity.com Jump…
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and disrupted, this campaign delivers malicious content assembled only after a user follows the attack chain. A blob URL is a…
-
Trezor, Bitbox, Cointracking: Phishing-Mails von echten Supportadressen verschickt
Zahlreiche Krypto-Nutzer haben kürzlich täuschend echte Phishing-Mails erhalten. Ursache ist wohl ein Vorfall bei einem E-Mail-Marketing-Anbieter. First seen on golem.de Jump to article: www.golem.de/news/trezor-bitbox-cointracking-phishing-welle-verunsichert-unzaehlige-krypto-nutzer-2609-212856.html
-
Trezor, Bitbox, Cointracking: Phishing-Welle verunsichert unzählige Krypto-Nutzer
Zahlreiche Krypto-Nutzer haben kürzlich täuschend echte Phishing-Mails erhalten. Ursache ist wohl ein Vorfall bei einem E-Mail-Marketing-Anbieter. First seen on golem.de Jump to article: www.golem.de/news/trezor-bitbox-cointracking-phishing-welle-verunsichert-unzaehlige-krypto-nutzer-2609-212856.html
-
Trezor, Bitbox, Cointracking: Phishing-Welle verunsichert unzählige Krypto-Nutzer
Zahlreiche Krypto-Nutzer haben kürzlich täuschend echte Phishing-Mails erhalten. Ursache ist wohl ein Vorfall bei einem E-Mail-Marketing-Anbieter. First seen on golem.de Jump to article: www.golem.de/news/trezor-bitbox-cointracking-phishing-welle-verunsichert-unzaehlige-krypto-nutzer-2609-212856.html
-
Trezor warns users of email provider breach, phishing attacks
Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/
-
Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
Threat actors targeting organizations across Latin America are increasingly embedding commercial large language models (LLMs) into intrusion workflows, using AI-assisted scripting, troubleshooting, and proxy deployment to accelerate post-exploitation and data theft. The campaigns show that AI is no longer limited to phishing, content generation, or reconnaissance. Instead, attackers appear to be using LLMs as an…

