Tag: phishing
-
When Attackers Can Spin Up a Phishing Site in 90 Minutes, Your Blocklist is Already Stale
AI-generated phishing is outpacing reputation-based DNS filtering, forcing organizations to adopt real-time AI classification of unknown domains before users reach malicious sites. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/when-attackers-can-spin-up-a-phishing-site-in-90-minutes-your-blocklist-is-already-stale/
-
Def Con Attendees Targeted by Persistent Phishing Campaign
Huntress researcher explains how they were targeted by an elaborate and persistent phishing scam following Def Con First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/def-con-attendees-persistent/
-
SilkParasite Threatens Central Asian Orgs With Flurry of RATs
A spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by China’s APTs. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/silkparasite-central-asian-orgs-flurry-rats
-
Abnormal Is Not Malicious. Malicious Is No Longer Abnormal
AI-powered email security is moving beyond anomaly detection to reason about intent, context and deception as advanced phishing attacks increasingly hide inside trusted brands and ordinary business communication. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/abnormal-is-not-malicious-malicious-is-no-longer-abnormal/
-
Crypto Scammer Uses Claude Code to Screen 100,000+ Phone Numbers in Phishing Operation
Rapid7 found a crypto scammer used Claude Code on more than 100,000 phone numbers in a phishing and vishing operation targeting cryptocurrency holders. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/news-claude-code-crypto-vishing/
-
Wie das ‘Bulletproof”-Kit Secure-EGateways und Multi-Factor-Authentification umgehen kann
Die Sicherheitsforscher des KnowBe4 Threat Labs haben eine aktive Phishing-Infrastruktur untersucht, die gezielt eine Schwachstelle klassischer E-Mail-Sicherheitsmechanismen ausnutzt. Das von den Angreifern selbst als ‘Bulletproof” bezeichnete Redirector-Kit versteckt die eigentliche Phishing-Infrastruktur hinter kompromittierten, legitimen Websites. Dadurch können schädliche Links Secure-E-Mail-Gateways (SEGs) und klassische URL-Reputationsprüfungen umgehen. Das Umgehen von SEGs ist jedoch nur ein sekundärer Vorteil.…
-
Phishing 3.0: The Fight Moves to Agent Versus Agent
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message’s intent, and it is failing now that the sender…
-
Balonx PhaaS Steals Bank OTPs in Real Time While AI Calls and Android RAT Target Victims
Mexico’s banking sector is facing a more industrialized fraud threat as the Balonx Sistema phishing-as-a-service (PhaaS) operation combines real-time OTP theft, Android malware, and AI-generated vishing calls. Balonx is not a conventional credential-harvesting kit. It operates as a subscription-based criminal service that rents access to affiliates, lowering the barrier for telemarketing fraud groups and inexperienced…
-
Phishing hinter legitimen Websites: ‘Bulletproof”-Kit trickst SEGs und MFA aus
Das ‘Bulletproof”-Phishing-Kit nutzt kompromittierte Websites, um E-Mail-Schutz zu umgehen. AiTM-Angriffe können zudem MFA-Sitzungen übernehmen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/phishing-hinter-legitimen-websites-bulletproof-kit-trickst-segs-und-mfa-aus/a46199/
-
Taylor Swift, Nine Other Celebrity Women Top the List of Deepfakes
AI-powered deepfakes are making phishing and impersonation attacks harder to detect, forcing security teams to rethink identity verification, authentication and fraud prevention. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/taylor-swift-nine-other-celebrity-women-top-the-list-of-deepfakes/
-
Fake Claude Install Guide Steals Mac Passwords and Turns Trusted Crypto Wallet Apps Into Phishing Traps
A Google-sponsored search result for Claude installation instructions is being used to deliver a sophisticated macOS stealer and remote-access trojan (RAT) named MacSync. The campaign abuses a legitimate Claude shared-conversation page on the claude.ai domain, demonstrating how trusted AI-hosting infrastructure can be weaponized to bypass users’ normal phishing instincts. The intrusion investigated by Huntress began…
-
So umgeht QR-Code-Phishing die Sicherheitsmaßnahmen von Unternehmen
‘Quishing” hat sich zu einer beliebten Alternative zum herkömmlichen Phishing entwickelt. Hier erfahren Sie, wie Unternehmen diese Lücke schließen können. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/business-security/so-umgeht-qr-code-phishing-die-sicherheitsmanahmen-von-unternehmen/
-
Keeper Security Issues Cybersecurity Guidance for Education IT Teams As Students Return to Campus
Every fall, school districts and universities across the country race to onboard thousands of new students, faculty and staff, provisioning accounts, issuing credentials and connecting a wave of new devices to institutional networks. It is a moment of organized chaos, and cybercriminals know it. Now, with artificial intelligence supercharging phishing campaigns and a hidden layer…
-
Hacker Claims Millions of Records Stolen From Azure Tenants
A threat actor is claiming to have stolen millions of employee records from the Microsoft Azure environments of several major companies, raising concerns that the information could be used to launch targeted phishing, impersonation, and privilege escalation attacks. The threat actor, known as >>TheHatman,<< has reportedly posted internal employee directories belonging to companies including McDonald's,…
-
BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims
BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely operate infected phones, and automate theft. Its emergence illustrates how leaked malware source code and low-code tooling are turning mobile fraud into a scalable franchise. The malicious lnat-tv-pro.apk sample connected to server[.]yaarsa[.]com/con over…
-
JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud
JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment fraud operation. Rather than waiting for a victim to submit a form, JWR streams keystrokes to an attacker over an AES-CTR-encrypted WebSocket channel, allowing the operator to react while card numbers, passwords and one-time codes are still…
-
Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX, a cryptocurrency fraud campaign that combined account enumeration, branded phishing, targeted voice calls, and trojanized wallet software to capture victims’ recovery phrases. The campaign’s exposed operational server also revealed an unusually detailed view of how the operator incorporated AI coding tools into active fraud development. Named after the Asterisk telephony platform found on…
-
Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX, a cryptocurrency fraud campaign that combined account enumeration, branded phishing, targeted voice calls, and trojanized wallet software to capture victims’ recovery phrases. The campaign’s exposed operational server also revealed an unusually detailed view of how the operator incorporated AI coding tools into active fraud development. Named after the Asterisk telephony platform found on…
-
Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX, a cryptocurrency fraud campaign that combined account enumeration, branded phishing, targeted voice calls, and trojanized wallet software to capture victims’ recovery phrases. The campaign’s exposed operational server also revealed an unusually detailed view of how the operator incorporated AI coding tools into active fraud development. Named after the Asterisk telephony platform found on…
-
SafePal Warns of Phishing Risk After Data Exposure Hits Nearly 40,000 Customers
SafePal says a security flaw exposed personal and order information for nearly 40,000 customers, increasing the risk of targeted phishing attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity-threats/news-safepal-data-breach-40000-customers/
-
‘MessiahGPT’ AI Service Promises Ransomware, Phishing Kits, and Malware
Trellix says MessiahGPT is marketed to cybercriminals as an uncensored AI service for ransomware, phishing kits, malware, and breach exploitation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/news-messiahgpt-malware-phishing-ai/
-
CEVA Logistics Breach Triggers Customer Data Alerts Across Europe
CEVA Logistics’ data breach exposed customer and order information across European clients, raising phishing and third-party security concerns. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-ceva-data-breach-emea-eu/
-
Steam-Versandpartner gehackt Phishing-Angriffe zu erwarten
Steam, die Videospiel-Vertriebsplattform von Valve, hat begonnen, Kunden per E-Mail zu warnen. Laut Valve haben Angreifer zwischen dem 29. Juli und dem 1. August CEVA Logistics attackiert das Unternehmen, das den Versand von Steam-Hardware an Kunden in ganz Europa abwickelt. Für diese Aufgabe erhält CEVA Lieferdaten von Steam und die Angreifer haben vermutlich […] First…
-
Former BlackFile affiliates linked to extortion campaign targeting private equity
Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/former-blackfile-extortion-campaign-private-equity/827574/
-
Phishing-Angriffe über Facetime
Vor Kurzem hat Apple in einem Supportbeitrag seine iPhone and iPad-Kunden vor einer neuen Phishing-Angriffswelle gewarnt. Zur initialen Kontaktaufnahme setzen die Angreifer unter anderem auch auf die Videokommunikationsplattform Facetime und geben sich als Mitarbeiter des Apple-Kundensupports aus. Um ihre Angriffe möglichst überzeugend zu gestalten, bringen sie gefälschte Anrufer-IDs und gefälschte Logos zum Einsatz. In die…
-
PassPasskey Attack Exploits Windows and Entra ID to Bypass MFA
Tags: attack, authentication, credentials, cyber, exploit, mfa, microsoft, passkey, phishing, windowsSecurity researchers have recently revealed a new attack family named “Pass-the-Passkey,” which enables adversaries to impersonate enterprise users and circumvent phishing-resistant multi-factor authentication (MFA) protections in Windows 11 and Microsoft Entra ID environments. This research challenges the belief that passkeys are inherently immune to credential replay and session abuse. Pass-the-Passkey Attack Exploits Windows The attack…
-
M365 als Angriffsinfrastruktur – Phishing nutzt echte Microsoft-Anmeldeseiten aus
First seen on security-insider.de Jump to article: www.security-insider.de/phishing-nutzt-echte-microsoft-anmeldeseiten-aus-a-d623eeb22614be43cbe10944e6643c75/
-
AI Threat Intelligence vs. Traditional Threat Intelligence: A Practical Guide for CISOs
Most CTI programs aren’t failing because analysts lack skill. They’re failing because signal volumes have outpaced what any manual workflow can process. Thousands of newly registered domains, phishing kit variants, and brand impersonation attempts surface daily. Human teams can’t triage all of it. Threat intelligence automation addresses the throughput problem by automating collection, enrichment and..…

