Tag: phishing
-
Cybercriminals are building phishing pages that exist only inside victims’ browsers
A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/browser-based-phishing-blob-urls-microsoft-oauth/
-
Hackers Route Phishing Through Google to Steal Microsoft Credentials
KnowBe4 found hackers abusing trusted Google services to hide phishing pages that steal Microsoft credentials and enable persistent ScreenConnect remote access. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-google-phishing-credential-theft-screenconnect/
-
Trezor customers hit with phishing calls and letters after shipping-partner breach
Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/trezor-shipping-partner-breach-phishing-attacks/
-
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
CloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365 First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/bigbear-2-phaas-5000-microsoft/
-
Hackers Steal Microsoft 365 Sessions to Hijack Accounts Even After MFA
Cybercriminals are using a rebranded Evilginx2 phishing-as-a-service platform dubbed BigBear 2.0 to intercept authenticated Microsoft 365 sessions, allowing them to take over accounts even after victims complete multi-factor authentication (MFA). CloudSEK’s TRIAD team uncovered the operation after gaining administrative access to its control panel in June 2026 The campaign demonstrates a critical reality for Microsoft…
-
Phishing-Warnung: Kleinanzeigen informiert Nutzer über Datenpanne
Tags: phishingAngreifer sind über eine Schnittstelle von Kleinanzeigen an Nutzerdaten gelangt. Der Anbieter warnt vor einem möglichen Missbrauch für Phishing. First seen on golem.de Jump to article: www.golem.de/news/phishing-warnung-kleinanzeigen-informiert-nutzer-ueber-datenpanne-2609-212751.html
-
Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak
Condé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud and scams. A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a 5,000-record sample and concluded that it is consistent with genuine Condé…
-
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/
-
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems.According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake First seen on…
-
Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials
Tags: access, control, credentials, cyber, email, google, infrastructure, network, phishing, serviceA large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly personalized credential-harvesting pages, and, in some cases, install ScreenConnect remote-access software. The campaign’s central advantage is that it presents trusted Google-owned domains at nearly every point a gateway, proxy, or analyst is likely to…
-
KnowBe4 beobachtet starken Anstieg von Phishing-Angriffen über .vu-Domains
Tags: phishingPhishing-Angreifer setzen verstärkt auf .vu-Domains. KnowBe4 registriert einen Anstieg um 159,6 Prozent und mehr als 28 Millionen schädliche E-Mails. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/knowbe4-beobachtet-starken-anstieg-von-phishing-angriffen-ueber-vu-domains/a46347/
-
Is Hotel WiFi Safe?
Hotel Wi”‘Fi is not automatically unsafe, but it is never a network you should blindly trust. Tom Eston and Scott Wright break down Microsoft’s CaptiveCrunch reporting, including how manipulated captive portals can lead to credential phishing, device-code abuse, and malware… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/is-hotel-wifi-safe/
-
Attackers conceal phishing lures using invisible Unicode characters
Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/
-
Mehr als Phishing: Bildungseinrichtungen besonders häufig von schwerwiegenden EAngriffen betroffen
Bildungseinrichtungen stehen im E-Mail-Kanal unter außergewöhnlichem Druck: hohes Phishing-Aufkommen trifft auf knappe Ressourcen, begrenzte Incident-Response-Kompetenz und besonders folgenreiche Angriffe. Die Daten zeigen, warum Entscheider Prävention, Erkennung und Wiederherstellung als durchgängigen Prozess steuern müssen. Management Summary Risikolage: 77 Prozent der Bildungseinrichtungen verzeichneten binnen zwölf Monaten einen E-Mail-Sicherheitsvorfall; Ransomware und Kontoübernahmen liegen deutlich über dem Branchenschnitt. Angriffsvolumen:……
-
Weltweiter SEO-Betrug: Gambling Goblin kapert brasilianische Regierungsseiten
Eine von Check Point Research beobachtete Kampagne nutzt kompromittierte brasilianische Regierungswebsites, um Phishing- und Glücksspielinhalte zu verbreiten. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/seo-betrug-gambling-goblin
-
Microsoft Finds ASCII Smuggling Repurposed for Phishing Campaign
Attackers have adapted a technique popularized in AI prompt injection research for a high-volume phishing campaign, using invisible Unicode characters to evade email filtering, Microsoft researchers reported Thursday. The finding came from Microsoft Defender for Office 365 prompt injection protection research. A hunting signature built to detect ASCII smuggling in email recorded a surge beginning..…
-
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a “high-volume phishing campaign” that’s using invisible Unicode tag characters to bypass email filters.”Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them,” the Microsoft Security…
-
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a “high-volume phishing campaign” that’s using invisible Unicode tag characters to bypass email filters.”Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them,” the Microsoft Security…
-
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a “high-volume phishing campaign” that’s using invisible Unicode tag characters to bypass email filters.”Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them,” the Microsoft Security…
-
Protecting Against Zero-Click Attacks
By Aimee Steele, threat intelligence analyst at Talion Cyber Security Last month, the UK’s National Cyber Security Centre (NCSC) issued an advisory around a new phishing campaign targeting organisations in the West that was being carried out by the Russian state-sponsored threat actor known as Laundry Bear. The campaign, saw the threat actors exploiting a…
-
Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud
Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help organizations reduce phishing and fraud risks associated with malicious QR code campaigns. Listed under Microsoft 365 Roadmap ID 570439, this feature is currently in development and is scheduled for rollout in…
-
Hackers Abuse AI-Era ASCII Smuggling to Hide Phishing Content in Millions of Emails
Threat actors have repurposed an AI prompt-injection technique known as ASCII smuggling to evade email security controls at massive scale, hiding invisible Unicode characters within financial phishing lures. Microsoft observed the activity reach more than 2.3 million messages per day, demonstrating how techniques first popularized in AI-security research can quickly migrate into conventional phishing operations.…
-
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/microsoft-teams-qr-code-phishing-protection/
-
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/microsoft-teams-qr-code-phishing-protection/
-
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/microsoft-teams-qr-code-phishing-protection/
-
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/microsoft-teams-qr-code-phishing-protection/
-
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/microsoft-teams-qr-code-phishing-protection/
-
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/microsoft-teams-qr-code-phishing-protection/
-
X Users Are Getting Flooded With Password Reset Emails After X Money Launch
X users are reporting repeated password-reset emails after the X Money launch, raising concerns about phishing and potential account takeover attempts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-x-money-password-reset-phishing-attacks/

