LIVE · cybersecurity feed
Live wire
Android’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsEven with OT network visibility, critical infrastructure operators struggle with legacy equipmentASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-Day

phishing news

111 stories · page 1 of 3
phishing

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Cybersecurity researchers have uncovered a human-operated phishing platform designed to impersonate advertising portals for popular artificial intelligence (AI) chatbots. The platform specifically targets users by mimicking ad products for services such as Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. Its primary objective is to capture user credentials and…

cyber espionagehigh

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

A China-aligned cyber espionage group, designated TA419, has reportedly been observed targeting U.S. AI policy experts through sophisticated phishing campaigns. These operations are characterized by the impersonation of prominent individuals and the deployment of a technique known as Frameless Browser-in-the-Browser (BitB) to construct highly convincing fake Microsoft login pages. The primary…

phishing

Fake Zoom installer hides macOS backdoor CloudSyncD

Jamf Threat Labs has uncovered a new macOS backdoor, dubbed CloudSyncD, which is distributed through a fake Zoom installer. The malware was first observed in development on September 15, 2026, and quickly transitioned to live command-and-control infrastructure within two days.

backdoorhigh

Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel

Cisco Talos researchers have identified a new Rust-based backdoor, dubbed Antino, which a China-linked threat actor known as UAT-11587 is using to conduct espionage against government and policy organizations in Asia. The backdoor uniquely leverages Microsoft 365 services, specifically Outlook and OneDrive, for its command-and-control (C2) communications, allowing its traffic to blend in with…

aihigh

Microsoft: AI Cuts Post-Compromise Attack Time to Minutes

Microsoft's Digital Defense Report 2026, released October 1, 2026, warns that artificial intelligence (AI) has dramatically accelerated portions of the cyber-attack lifecycle, compressing post-compromise activities from days to mere minutes. This rapid evolution, driven by threat actors' early adoption of AI, presents a significant challenge for cybersecurity defenders.

browser securityhigh

The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

Endpoint Detection and Response (EDR) systems, while crucial for detecting host-level code execution, may not fully address the evolving landscape of browser-based attacks, according to recent analysis. Many modern threats leverage browser sessions and cloud applications, performing malicious actions that do not generate the typical endpoint artifacts EDR solutions are designed to monitor.…

phishing

Researchers find Chinese hacking campaigns targeting AI firms, Asian governments

Two independent reports published this week detail separate, recent campaigns by Chinese government-backed hacking groups targeting artificial intelligence firms, universities, and several Asian governments. The campaigns, which occurred between September 2025 and July 2026, primarily relied on phishing and social engineering tactics to achieve intelligence gathering objectives.

phishing

Many expect AI in the SOC to make entry jobs harder to get

The increasing integration of artificial intelligence into Security Operations Centers (SOCs) is reshaping the cybersecurity career landscape, particularly for entry-level positions. While AI tools are largely welcomed by current security staff for automating repetitive tasks, concerns are emerging about their potential impact on skill development and the accessibility of junior analyst roles.

phishing

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Microsoft has issued a warning regarding active phishing campaigns that are leveraging legitimate remote monitoring and management (RMM) software, specifically MSP360, to establish remote access on targeted systems. The campaigns reportedly distribute an installer for MSP360, masquerading it as various lures such as meeting invitations, PDF documents, or software update prompts, to trick users…

phishing

Phishing Abuses RMM Tools for Persistent Access

Microsoft has reported observing phishing campaigns that are leveraging legitimate Remote Monitoring and Management (RMM) tools to establish persistent access to victim systems. Specifically, the campaigns were noted to abuse MSP360 RMM to facilitate the deployment of ScreenConnect, a legitimate remote desktop solution. This tactic creates redundant remote-access channels, enabling attackers…

espionagehigh

Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond

A Russian government-backed hacking group, identified by Microsoft as Star Blizzard and affiliated with the Federal Security Service (FSB), has significantly expanded its targeting and refined its attack methods. The group, also known as SEABORGIUM, Callisto Group, TA446, and COLDRIVER, has shifted from highly targeted spear-phishing to larger-scale phishing campaigns, impacting over 100…

business email compromisehigh

Former US Air Force members sent to prison over BEC attacks

Two former members of the United States Air Force have been sentenced to federal prison for their involvement in a multi-year scheme of business email compromise (BEC) and phishing campaigns. Chijioke Timothy Odimegwu, 25, received a sentence of 111 months, while Harafat Mogaji, 26, was sentenced to 78 months. Both individuals will also serve a three-year term of supervised release following…

phishinghigh

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Russian state-sponsored hacking group, Star Blizzard, has reportedly targeted over 100 organizations with sophisticated phishing campaigns designed to deliver backdoor malware. The attacks, which commenced in January, leverage fake event invitations to deceive recipients into installing a backdoor known as CosmicPulse on Windows systems. The primary targets of these campaigns are organizations…

phishing

AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

Three researchers from Hacktron successfully exploited a vulnerability in the Discourse forum used by OpenAI, gaining unauthorized access to staff accounts for ChatGPT and Codex. The attack, which took less than 72 hours from initial discovery to accessing an internal OpenAI code repository, highlighted risks associated with shared single sign-on (SSO) systems.

phishing

A fake ChatGPT billing email is after your OpenAI password

A new phishing campaign is targeting ChatGPT users with a fake billing email designed to steal OpenAI account credentials. The scheme directs users to a deceptive login page that captures any username and password entered.

phishing

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has reported details concerning two distinct campaigns where threat actors leveraged third-party email delivery infrastructure to distribute financial fraud scam messages. These campaigns employed passkey-themed social engineering tactics to compromise cloud environments, ultimately leading to the hijacking of Microsoft cloud accounts and subsequent data exfiltration.

aihigh

AI Enables Mass Generation of Personalized Fraud Emails

Recent reports indicate that artificial intelligence (AI) is being leveraged by threat actors to generate highly personalized fraudulent emails on a mass scale. This development suggests a significant shift in the capabilities of cybercriminals, enabling them to produce phishing campaigns that are both more numerous and more convincing than previously observed.

phishing

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Microsoft has issued a warning regarding a series of passkey-themed phishing attacks that have led to the compromise of corporate Microsoft accounts and the theft of data from Microsoft 365 services. The activity, observed since May 2026, involves threat actors linked to various extortion gangs, including those tracked by Microsoft as Storm-3121 and Storm-3032, and by Google Threat…

phishing

Phishing Research Challenges Conventional Security Awareness Testing

New research into phishing simulations suggests that conventional security awareness testing methods may be insufficient for accurately gauging an organization's resilience against real-world threats. The study, which analyzed 2.47 million simulated phishing attacks, indicates that current metrics often focus too heavily on user clicks, potentially overlooking more critical indicators of…

phishing

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

Recent reports have highlighted several significant developments in the cybersecurity landscape, including a novel phishing technique leveraging invisible Unicode characters, a substantial bounty offered for an Iranian cyber official, and new insights into the military affiliations of a Chinese hacking group. These stories, though varied in nature, underscore ongoing challenges in digital…

phishing

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A phishing-as-a-service (PhaaS) framework known as BigBear 2.0 has been identified as a tool used to bypass multi-factor authentication (MFA) across 258 organizations, resulting in the theft of over 5,000 Microsoft 365 credentials. Cybersecurity researchers gained administrative access to the service's control panel, revealing an operation that managed 42 virtual private server (VPS) nodes,…

phishinghigh

Attackers conceal phishing lures using invisible Unicode characters

Threat actors have been observed employing an advanced phishing technique known as ASCII smuggling, which leverages invisible Unicode characters to bypass email security filters. This method, previously noted in AI prompt injection attacks, involves embedding Unicode characters from the Tags block (U+E0000 to U+E007F) to obscure malicious instructions or keywords.

phishing

ASCII smuggling isn't just an AI security risk

Microsoft has identified a large-scale phishing campaign that repurposed a technique known as ASCII smuggling, typically associated with AI security risks, to evade email content filters. The campaign, which peaked at over 2.37 million messages in late February, utilized invisible Unicode tag characters to obfuscate financial keywords within phishing emails.

phishinghigh

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

A large-scale phishing campaign has been identified that leverages invisible Unicode tag characters to bypass email security filters. The campaign, which has been active for several months and involved millions of emails, was reported by Microsoft. The primary goal of the attackers appears to be the distribution of phishing lures, often disguised as business loan or funding opportunities.

phishing

Outsider Phishing Kit Survives Takedown With 700 New Pages

A phishing-as-a-service (PaaS) operation known as Outsider has continued to generate new campaigns despite a coordinated takedown effort in June, with more than 700 new phishing pages identified within a month of the disruption. Researchers at Group-IB have tracked the Outsider Phishing Kit, operated by a threat actor known as ChenLun, identifying over 100,000 phishing pages targeting at least…

phishing

FBI raises alarm over deceptive phishing campaign targeting prominent people

The Federal Bureau of Investigation has issued a public warning regarding an ongoing and sophisticated social engineering campaign that targets high-profile individuals, their family members, and acquaintances. The campaign, which the FBI has been tracking since late 2025, aims to gain long-term access to victims' accounts on commercial messaging applications and cloud services.

malwarehigh

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

A new cyber campaign, dubbed TerminalFix, has been reported to be actively targeting organizations through a sophisticated, multi-stage intrusion process. This campaign, identified as a variant of the previously known ClickFix operation, primarily relies on social engineering to initiate the attack chain, specifically by deceiving users into executing malicious PowerShell commands. The initial…

phishingcritical

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

A new phishing-as-a-service (PhaaS) platform, dubbed AnonyMousKIT, is actively being used to automate the theft of Apple ID credentials, which are necessary to bypass the Activation Lock feature on stolen iPhones. The platform leverages advanced AI voice calls to impersonate Apple Support and trick victims into revealing their device passcodes and other sensitive information.

phishing

Bogus recruiters go after high-value corporate credentials on mobile

A sophisticated phishing campaign is targeting high-value corporate credentials through fake job recruitment schemes, leveraging a technique known as browser-in-the-browser (BitB) to deceive victims. The attackers impersonate human resources staff from well-known companies, crafting convincing interview scheduling flows designed to steal corporate passwords.

phishing

Hackers abuse npm mirrors to host phishing redirect pages

Threat actors are leveraging the npm package registry and its mirroring services to host malicious HTML pages, effectively turning these platforms into free web hosting for phishing redirects. This technique, distinct from typical supply-chain attacks that infect developer systems, uses npm as a validated storage mechanism for attacker-controlled content.

phishing

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

A new phishing-as-a-service (PhaaS) platform named AnonyMousKIT has been identified as automating the process of obtaining passcodes for stolen Apple devices, enabling the disabling of Apple's Activation Lock feature and access to sensitive user data. Active since early 2024, the service supports an ecosystem for selling stolen iPhones, harvesting Apple IDs, and accessing iCloud backups and…

phishing

ZeroTokens Phishing Platform Steers Attacks in Real Time

A new phishing platform known as ZeroTokens allows attackers to monitor victim sessions in real time and dynamically alter the prompts displayed, enabling adaptive attacks aimed at harvesting credentials and financial data. The platform provides operators with live visibility into information entered by victims, allowing them to steer individual phishing interactions while simultaneously using…

phishing

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

WhatsApp has reportedly enhanced its account security features by introducing support for multiple passkeys for a single user account. This update aims to provide a more robust, phishing-resistant sign-in method for users across both iOS and Android platforms. The move follows the initial introduction of passkey support for Android devices in October 2023, expanding its utility to a broader…

phishing

TikTok phishing: How to spot fake login and verification pages

Users of the popular social media platform TikTok are being targeted by sophisticated phishing campaigns designed to steal login credentials and other personal information. These campaigns often leverage convincing fake login pages and deceptive messages to trick users into divulging their account details.

phishing

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

ReliaQuest has confirmed that it was targeted by the ShinyHunters hacking group, acknowledging that an employee fell victim to a phishing attack. The incident resulted in unauthorized access to an internal dashboard, though the company has stated that the impact was limited.

scamhigh

Fake Microsoft security scans trick victims into uninstalling their antivirus

A new refund scam is leveraging fake Microsoft-branded security scans to trick users into uninstalling their legitimate antivirus software, ultimately aiming to steal personal, banking, and remote-access information. Multiple websites, operating under names like SysScan, present convincing but fraudulent security scans that invariably conclude the user's computer has severe issues, falsely…

phishing

New SynkLoader malware pushed in Microsoft Teams phishing campaign

A previously undocumented malware family, named SynkLoader, is being distributed through phishing campaigns targeting Microsoft Teams users. The attacks aim to steal credentials by presenting victims with a deceptive lock screen.

phishing

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

A new phishing toolkit, dubbed iAuthFlow V2, has been identified by security researchers. This toolkit reportedly leverages passkeys to maintain persistent access to compromised accounts, even in scenarios where the legitimate user has reset their password and revoked active sessions. The core innovation reported is the toolkit's ability to register an attacker-controlled passkey, which then…

espionagehigh

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

Google's Threat Intelligence Group (GTIG) has identified three distinct Russia-linked cyber espionage clusters, designated UNC6293, UNC7005, and UNC5976, which are targeting researchers, academics, government officials, think-tank analysts, and defense sector personnel in Europe and the United States. These groups employ persistent and adaptive phishing campaigns, leveraging sophisticated…

phishing

Russian snoops add OAuth abuse to targeted phishing campaigns

Three suspected Russian cyber-espionage groups have been observed employing OAuth abuse in targeted phishing campaigns against individuals in academia, aerospace, defense, government agencies, and think tanks across Europe and the United States. These highly focused operations, which have been ongoing since at least last year, involve fewer than 100 targets per campaign and typically result in…

phishing

How MSPs can catch phishing attacks email filters miss

AI-powered phishing campaigns are increasingly sophisticated, making them harder for traditional email filters to detect and significantly increasing the risk of successful breaches. Attackers are leveraging artificial intelligence to automate and enhance every stage of a phishing operation, from reconnaissance to content generation and delivery.

identity theft

Attackers Exploit Collaboration Tools for Identity Theft

Cybersecurity researchers have observed a significant increase in threat actors exploiting enterprise collaboration platforms for identity-focused attacks, including phishing, impersonation, credential theft, and malware delivery. Over the past year, alerts related to malicious activity involving these tools have quadrupled, indicating a growing trend in their misuse.

phishing

Def Con Attendees Targeted by Persistent Phishing Campaign

Attendees of the recent Black Hat and Def Con cybersecurity conferences are being warned to watch for persistent phishing attempts following a campaign that targeted a security researcher. The attacker employed multiple tactics, including social media direct messages, malicious Google Docs, and fake file-sharing installers, to deliver various malware payloads.

phishing

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A new spear-phishing campaign, dubbed "SilkParasite," has been observed targeting organizations in Central Asia. The campaign, attributed to a Chinese-nexus threat group with reported links to FamousSparrow, is notable for deploying a variety of Remote Access Trojans (RATs). This activity provides a window into the evolving geopolitical, technical, and strategic operational patterns of certain…

phishinghigh

Phishing 3.0: The Fight Moves to Agent Versus Agent

The cybersecurity community is reportedly facing a new phase of attack, dubbed "Phishing 3.0," characterized by the increasing deployment of AI-powered agents by malicious actors. This development signifies a shift in the nature of phishing campaigns, moving towards more automated and sophisticated multi-channel assaults. The core concern is that these AI agents are enhancing attackers'…

scam

Polite replies to wrong-number texts can confirm number validity for scammers

Replying to a "wrong number" text message, even with a polite correction, can inadvertently confirm the validity of a phone number and a user's responsiveness, making them a more valuable target for various scam operations. This initial interaction, while seemingly harmless, is often the first step in a sophisticated process designed to identify and exploit potential victims.

phishinghigh

CISA gives feds 3 days to fix actively exploited Ray RCE bug

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for federal agencies to patch a critical vulnerability in the open-source Ray framework within three days. The flaw, identified as CVE-2025-62593, is actively being exploited and carries a CVSS v4 score of 9.4, indicating a severe risk of remote code execution (RCE).

phishing

Heights Finance data breach: What customers need to know

Heights Finance Holdings has confirmed a data breach affecting a third-party cloud platform, potentially exposing sensitive personal, financial, and identity information for current and former customers, as well as individuals who merely inquired about loan products. The company discovered the unauthorized access on May 7 and initiated an investigation, which concluded that an intruder may…