LIVE · cybersecurity feed
Live wire
Cisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
phishing

A fake ChatGPT billing email is after your OpenAI password

A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redirect to the attacker’s page. The lure targets ChatGPT users on work and personal accounts alike, and it copies the kind of bill a subscriber already expects. Cre

zeroday.news ·

A new phishing campaign is targeting ChatGPT users with a fake billing email designed to steal OpenAI account credentials. The scheme directs users to a deceptive login page that captures any username and password entered.

The phishing email, which purports to be from "ChatGPT" with the subject line "Urgent: Update Your Payment Method to Avoid Service Interruption," attempts to mimic a legitimate billing notification. It features the ChatGPT logo, a "final notice" tag, and claims an outstanding balance of $23.80. The message warns of potential account suspension if payment information is not updated within 48 hours and includes a prominent green "Update Payment Information" button, signed off by "The OpenAI Team."

However, several details betray the email's fraudulent nature. The sender's address, support@9527db6e1a[.]nxcli[.]io, is not an official OpenAI domain. Furthermore, the "Update Payment Information" button does not link directly to the phishing site. Instead, its URL begins with notifications[.]googleapis[.]com, a Google API redirect service that then forwards the user's browser to the attacker's page. This redirection complicates typical phishing detection methods, as hovering over the link reveals a Google address rather than an OpenAI one.

Upon clicking the link, victims are led to a fake landing page that displays the ChatGPT logo and a "Welcome back" greeting above fields for username and password. After credentials are submitted, they are sent to the attacker, and the victim is redirected to an error page. The authentic OpenAI sign-in page is located at auth.openai.com, and users are advised to always verify this URL in their browser's address bar before entering any login details.

Security researchers have identified specific indicators of compromise for this campaign. These include the Google redirect link and two paths on the nxcli[.]io host: login.php and key.php. Organizations are encouraged to search their email logs for these indicators. The most critical defense for individual users remains vigilant inspection of the browser's address bar to confirm it displays auth.openai.com before submitting any login information.

phishingai
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two updates posted September 15, AWS said it can no longer recover customer data and resources stored in its Middle East (Bahrain) region, known as me-south-1, or in one availability zone of its Middle East (UA

patch

Windows 11 24H2 Home and Pro reach end of support in October

Microsoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...]

malware

Chosen Brick, Iran’s Surveillance Malware

UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the […]

vulnerabilityhigh

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]

vulnerability

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.

finance

Anthropic wants Claude to analyze your bank account and financial data

Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." [...]