Tag: phishing
-
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/
-
Why Payload-Free Phishing Bypasses Every Filter
Traditional email filters look for malicious links, but modern attackers use AI agents to build trust through payload-free dialogue. Learn how to stop them. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/why-payload-free-phishing-bypasses-every-filter/
-
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method.The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys…
-
ZeroTokens Phishing Platform Steers Attacks in Real Time
ZeroTokens gives phishing operators live control of victim sessions targeting 53 financial brands First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/zerotokens-phishing-real-time/
-
Fake Recruiter Scams Target Corporate Credentials on Mobile
RecruitTrap campaigns use mobile-optimized phishing pages to target enterprise credentials First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fake-recruiter-scams-corporate/
-
A Master Class on the Anatomy of a Modern Phishing Attack
<div cla Five layers of a 2026 phish, two studies three years apart, and the tells that replaced the ones you were taught. In October 2022, Osterman Research published a study we commissioned, The Business Cost of Phishing. It created a baseline for us to use as a pulse check on how phishing impacts organizations.…
-
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication.According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based.Mirage2FA Campaign First seen on thehackernews.com Jump…
-
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.”While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t do harm, the threat actor’s use of npm isn’t to…
-
Phishing-Warnung: Betrüger ködern mit angeblicher Steuererstattung
Tags: phishingViele Bürger warten seit Wochen auf ihren Steuerbescheid 2025. Betrüger nutzen das aktuell vermehrt aus, um mittels Phishing Daten abzugreifen. First seen on golem.de Jump to article: www.golem.de/news/verbraucherzentrale-warnt-phishing-mails-koedern-mit-angeblicher-steuererstattung-2608-212265.html
-
TikTok phishing: How to spot fake login and verification pages
Scammers use fake TikTok login pages, warnings, and verification offers to trick you into handing over your account details. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/tiktok-phishing-how-to-spot-fake-login-and-verification-pages/
-
EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords
EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Victims can complete a legitimate Microsoft sign-in and MFA challenge, yet unknowingly authorize an attacker-controlled session. The PhaaS operation was advertised on Telegram from mid-February 2026 and was later documented by Sekoia researchers as a turnkey…
-
The Most Effective Cybersecurity Awareness Programs for Companies (2026)
<div cla The most effective cybersecurity awareness programs pair phishing simulation testing with role-based training, then tie both to live email threat detection. IRONSCALES, KnowBe4, Proofpoint, Cofense, and Mimecast lead this market. IRONSCALES is the only one that builds awareness training directly into an AI-powered email security platform, so the same system that trains your…
-
Does AI Create New Cybersecurity Risks? What Actually Changes
<div cla AI does not create new attack vectors. It accelerates the ones that already dominate most risk registers. Code exploitation, injection, credential and identity abuse, phishing, and misconfiguration are the same vectors security teams tracked before generative AI reached the enterprise. What changed is how quickly they can be found and exploited, and the…
-
Does AI Create New Cybersecurity Risks? What Actually Changes
<div cla AI does not create new attack vectors. It accelerates the ones that already dominate most risk registers. Code exploitation, injection, credential and identity abuse, phishing, and misconfiguration are the same vectors security teams tracked before generative AI reached the enterprise. What changed is how quickly they can be found and exploited, and the…
-
Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages
Threat actors are increasingly using Google and Bing as phishing delivery channels, employing a cloaking technique that presents harmless pages to security scanners while serving credential-harvesting banking portals to genuine search users. The campaigns target users of major financial institutions and combine search-engine optimization abuse, recently registered lookalike domains, and referral-aware payload delivery to extend…
-
North Korean Hackers Hide AnyDesk on Victim PCs to Maintain Secret Remote Access
Tags: access, cyber, email, hacker, korea, malicious, north-korea, phishing, powershell, software, spear-phishing, theft, windowsNorth Korea-linked Kimsuky operators have targeted organizations in South Korea and Japan with spear-phishing campaigns that install and conceal AnyDesk, giving attackers persistent, interactive remote access while blending into legitimate software activity. The operation combines OneDrive-hosted lures, malicious Windows shortcut files, scheduled-task persistence, PowerShell payloads, and email theft across Thunderbird, Outlook, and Gmail. The archives…
-
Missbrauch von Passkeys: Phishing-Toolkit soll Passwort-Reset umgehen können
Ein ab 10.000 US-Dollar gehandeltes Phishing-Toolkit soll Angreifern über Passkeys einen dauerhaften Zugriff etwa auf gekaperte Google-Konten verleihen. First seen on golem.de Jump to article: www.golem.de/news/missbrauch-von-passkeys-phishing-toolkit-soll-passwort-reset-umgehen-koennen-2608-212226.html
-
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is…
-
New SynkLoader Malware Uses Fake Windows Lock Screen to Steal Passwords and Pivot Networks
SynkLoader, a newly identified modular malware framework that combines Python, C#, C++, PowerShell, and memory-resident payloads to evade endpoint detection. Delivered through Microsoft Teams phishing, the operation uses a convincing fake Windows lock screen to capture credentials before enabling network tunneling and interactive access to compromised enterprise environments. Compile timestamps and file metadata indicate the…
-
Fake bank websites play dead to evade security scanners
A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/24/chameleon-seo-poisoning-fake-banking-websites-phishing/
-
Phishing-Kit klont PayPal und Apple: ‘JWR” stiehlt Daten live beim Tippen
Das Phishing-Kit JWR klont Seiten von PayPal und Apple. Es überträgt Eingaben wie Kreditkarten und Passwörter live an Angreifer. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/phishing-kit-klont-paypal
-
New SynkLoader malware pushed in Microsoft Teams phishing campaign
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/
-
Amazon’s Order Email Privacy Change Creates a Potential Phishing Trade-Off
Amazon’s less-detailed order emails protect purchase data but may make phishing harder to spot. Learn how to verify order messages safely online. The post Amazon’s Order Email Privacy Change Creates a Potential Phishing Trade-Off appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-amazon-order-email-privacy-phishing-trade-off/
-
Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
Tags: access, authentication, conference, cyber, defense, espionage, google, group, intelligence, phishing, russia, tactics, threat, toolGoogle tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead. Threat actors target researchers,…
-
New Manic Android Malware Targets 169 Apps, Steals PINs and Exfiltrates Data via Wi-Fi Mesh
A newly discovered Android malware family called Manic, which combines banking fraud functions with advanced spyware and remote device control capabilities. The operation’s active infrastructure dates back to February 2026, with early wrappers and implants emerging in late May. Manic has rapidly evolved through July, incorporating stronger anti-analysis protections, in-memory DEX loading, lock-screen phishing, and…
-
How MSPs can catch phishing attacks email filters miss
AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past the inbox. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-msps-can-catch-phishing-attacks-email-filters-miss/
-
ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated malware uses invisible overlays to capture PIN input from more than 140 banking and cryptocurrency applications, while its broader phishing framework targets 349 banking, financial, e-wallet, and crypto applications across 16 countries. ToxicPanda was previously…
-
Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud
Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC). The attackers used an adversary-in-the-middle (AiTM) phishing kit to capture an authenticated Microsoft 365 session token, bypass multi-factor authentication, and quietly redirect vendor payments to attacker-controlled bank accounts. The lure contained a “View…
-
When Attackers Can Spin Up a Phishing Site in 90 Minutes, Your Blocklist is Already Stale
AI-generated phishing is outpacing reputation-based DNS filtering, forcing organizations to adopt real-time AI classification of unknown domains before users reach malicious sites. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/when-attackers-can-spin-up-a-phishing-site-in-90-minutes-your-blocklist-is-already-stale/

