phishing news
111 stories · page 2 of 3
17th August – Threat Intelligence Report
Several organizations across various sectors have recently reported cyberattacks and data breaches, while security researchers have detailed new vulnerabilities and emerging threat trends, including the use of AI in cyberespionage.

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure
Since late July 2026, a cluster of seven incidents involving autonomous or semi-autonomous AI systems deployed for offensive cyber operations has been tracked, indicating a shift from theoretical risk to operational reality. The most prominent of these, confirmed by Taiwan’s Ministry of Digital Affairs on August 13, 2026, involved a near-autonomous AI cyberattack against government infrastructure.

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
Recent cybersecurity incidents affecting Vercel and Composio have revealed an evolving attack pattern targeting Google Workspace environments, where the initial compromise bypasses traditional email-based phishing and instead leverages stolen OAuth tokens. This shift represents a significant departure from the long-held assumption that email is the primary entry point for workspace attacks.

Dissecting the JWR phishing framework
A previously undocumented phishing framework, internally dubbed "JWR" by its developers, has been identified as a real-time, operator-driven system designed to impersonate checkout and login pages for major payment and shopping platforms. Cybersecurity researchers at Cisco Talos discovered the framework, noting its capability to harvest extensive victim data, including payment card details,…

Smashing Security podcast #480: This is the AI service you should never sign up to
A new phishing-as-a-service (PaaS) platform named "Greatness" has emerged, offering a sophisticated attack vector that bypasses traditional password theft and fake website tactics. This platform leverages a legitimate Microsoft login page to gain full access to a victim's emails, files, and potentially their entire organizational infrastructure. The attack relies on a moment of misplaced trust…

Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily
Google Chrome's integrated anti-abuse systems are currently blocking an average of 7 billion unwanted Android push notifications daily, according to figures released by Google for the first quarter of this year. These protections are a multi-layered effort combining Chrome Security, Firebase Cloud Messaging (FCM), and Safe Browsing to detect and prevent malicious or deceptive content…

Ready-made $500 kit puts a crypto scam within anyone’s reach
A cybercrime forum vendor is offering a comprehensive scam kit for $500, enabling individuals with minimal technical skills to execute sophisticated cryptocurrency fraud. The kit, discovered by Malwarebytes researchers on May 16, provides a complete "scam-in-a-box" solution, integrating social engineering, phishing, and financial fraud into a single, ready-to-use package.

Valve warns Steam hardware buyers: Expect fake delivery scams
Valve has issued a warning to European customers who recently purchased hardware through its Steam platform, advising them to be vigilant against potential delivery scams following a cyberattack on its shipping partner, CEVA Logistics. The incident, which occurred between July 29 and August 1, 2026, exposed personal information including names, home addresses, phone numbers, Steam email…

North Korean spies are running local LLMs to cause AI mischief
A North Korean state-sponsored cyber-espionage group, Kimsuky, is reportedly integrating artificial intelligence (AI) into its attack operations, including malware development and data analysis. According to a South Korean security firm, Genians, Kimsuky has been observed setting up and operating local large language model (LLM) environments and collecting various AI-related technologies.

U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data
IEH Corporation, a U.S. defense and aerospace manufacturer, has confirmed it experienced a cybersecurity incident stemming from a phishing attack that compromised an employee's Microsoft 365 mailbox. The breach, discovered on August 4, 2026, potentially exposed sensitive information, including export-controlled military data.

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
Recent reports indicate a series of cybersecurity incidents across various sectors, including a notable restriction on Chinese data center technology, a supply chain compromise affecting QuickFox VPN, and a successful phishing attack against IEH Corporation. Further developments suggest that the proliferation of AI-generated content might be complicating Apple's bug bounty program, a North…

Real emails, hijacked payments: Two H1 2026 attack chains
Cybersecurity researchers have detailed two distinct attack campaigns observed in the first half of 2026, both of which leveraged legitimate system functions or compromised trusted accounts to achieve their objectives. One campaign focused on banking fraud through business email compromise and browser manipulation, while the other targeted cryptocurrency users with a Rust-based clipboard…

Attacker phished way into US defense supplier's Microsoft 365 account
IEH Corporation, a US defense and aerospace supplier, has confirmed that an attacker gained unauthorized access to one of its Microsoft 365 mailboxes through a phishing scam. The incident, disclosed in a Form 8-K filing with the Securities and Exchange Commission, involved an employee falling victim to a sophisticated phishing attempt that harvested their M365 credentials.

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have reported an active and widespread email-driven phishing campaign targeting Microsoft 365 accounts. This campaign leverages adversary-in-the-middle (AitM) techniques to compromise accounts, with the ultimate goal of identifying key personnel involved in financial workflows and exfiltrating related email communications. The observed activity indicates a focused…

What the first year of EU AI Act transparency enforcement could look like
The initial year of enforcement for the EU AI Act's Article 50 is expected to prioritize corrective orders over substantial financial penalties, according to an analysis by Edwin Weijdema, Field CTO at Veeam. While breaches of Article 50 carry potential exposure of up to 15 million euros or three percent of worldwide turnover, regulators are likely to adopt a "bedding-in" approach,…

AI-generated phishing texts bypass human intuition
A recent pilot study conducted at Brigham Young University indicates that individuals struggle to distinguish between phishing text messages generated by AI and those crafted by humans, particularly when the messages are personalized with work-related details. The study involved 25 volunteers who were presented with a mix of AI-generated and human-written text messages, tailored to their…

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit named Greatness has reportedly integrated support for device code phishing. This new capability allows the crimeware solution to leverage the OAuth 2.0 Device Authorization Grant flow, a legitimate mechanism, for malicious purposes. The primary goal of this addition is to bypass Multi-Factor Authentication (MFA) and facilitate the theft of…

How legitimate cloud platforms enable phishers to bypass MFA
Threat actors are increasingly leveraging legitimate cloud services to host phishing infrastructure, enabling them to bypass traditional security measures and multi-factor authentication (MFA). Researchers have observed a consistent migration of phishing operations to platforms such as Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS throughout 2025 and 2026. This trend is driven by…

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
New reports indicate that phishing campaigns are actively targeting providers of artificial intelligence solutions, specifically mentioning services such as ChatGPT. These campaigns leverage the established tactic of impersonation, a common characteristic of phishing attacks designed to exploit user concerns over potential loss of access or information.

South Korea Warns of State-Backed Watering Hole Attacks
South Korean authorities have issued a joint advisory warning citizens and businesses about ongoing state-backed cyberattacks employing both phishing and watering hole techniques. The National Intelligence Service, National Police Agency, Korea Internet & Security Agency, and Financial Security Institute collaborated on the alert, which details how attackers are silently compromising systems.

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
A sophisticated threat actor, identified as Storm-2945, a sub-cluster of the group known as Midnight Blizzard, has reportedly initiated a global campaign dubbed "CaptiveCrunch." This operation specifically targets travelers by exploiting captive portal networks to facilitate malware delivery and credential theft. The threat actor is said to manipulate network traffic to achieve these…

ESET tracks rise in malicious AI skills and adaptable malware
ESET's H1 2026 Threat Report indicates a significant increase in the use of artificial intelligence by attackers, both in developing malicious AI components and integrating AI into malware itself. The cybersecurity firm analyzed nearly 900,000 AI "skills"—functional components for AI agents—during the first half of 2026, identifying tens of thousands as suspicious and thousands as overtly…

XRP Volatility Surges as Cybersecurity Threats and Market Changes Raise New Concerns
Recent reports indicate a significant surge in the volatility of XRP, a prominent digital asset, driven by a confluence of factors including evolving cybersecurity threats and broader market changes. This increased volatility is reportedly accelerating crypto trading activities, particularly as artificial intelligence (AI) tools become more prevalent in the market. The reports highlight that…

The $5 million threat: AI Is supercharging phishing attacks
A recent study indicates a significant increase in the financial impact and sophistication of phishing and social engineering attacks, with artificial intelligence playing a growing role in their augmentation. The research suggests that the costs associated with recovering from these incidents are rising, and the attacks themselves are becoming more difficult for organizations to detect.

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
A recent report highlights device code phishing as a rapidly escalating threat, transitioning from a specialized red-team tactic to a widespread concern within a six-month period. This attack vector exploits the OAuth 2.0 device authorization grant, a protocol initially designed to facilitate user authentication on input-constrained devices, to illicitly obtain access tokens. The increasing…

Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
Reports indicate that a state-sponsored threat group, identified as "Laundry Bear," has been actively exploiting a zero-day vulnerability within Zimbra email collaboration software. The campaign specifically targets organizations in the United States and Ukraine, utilizing a sophisticated phishing technique that requires minimal user interaction to trigger.

International alert spotlights Russia-linked attacks on Zimbra webmail
Cybersecurity agencies from the United States, United Kingdom, Europe, Australia, and New Zealand have issued a joint alert regarding a series of zero-click phishing attacks targeting Zimbra Collaboration Suite webmail. These attacks, attributed to the Russian state-aligned advanced persistent threat (APT) group known as Laundry Bear, exploit a vulnerability, CVE-2025-66376, which was patched…

Russian hackers exploit Zimbra zero-click flaw for email theft
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a Russian state-sponsored hacking group, known as Laundry Bear or Void Blizzard, which is actively exploiting a zero-click vulnerability in Zimbra Collaboration email servers. The group is combining phishing attacks with the exploitation of CVE-2025-66376, a cross-site scripting (XSS) flaw in Zimbra…

Year-long Russian attacks infect users as soon as they look at an email
A Russian state-sponsored threat group, identified as Laundry Bear or Void Blizzard, has been exploiting a cross-site scripting (XSS) vulnerability in the Zimbra web-based email and collaboration suite for at least a year. The attacks, which began in July 2025, allow adversaries to compromise victims simply by viewing a malicious email, without requiring any clicks or file openings.

Police dismantle Kratos phishing platform, arrest developer
Law enforcement agencies in Germany and the United States have dismantled the Kratos phishing-as-a-service (PhaaS) platform and arrested its developer in Indonesia. The operation, dubbed "Operation Olympus Blade," involved the seizure of over 200 servers, effectively rendering the malicious service inoperable.

Kratos phishing-as-a-service kit loses its battle with international law enforcement
German authorities, supported by US and Indonesian law enforcement, have dismantled the primary infrastructure of the Kratos phishing-as-a-service (PhaaS) kit. The operation led to the arrest of the alleged developer and technical administrator in Indonesia.

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
Security researchers at Rapid7 have reportedly uncovered an AI-assisted phishing toolkit after a malware operator inadvertently exposed their delivery server. The server, left wide open, contained 1,048 files, offering a comprehensive look into the attacker's operations. This cache included lure templates, tests for filename spoofing, execution experiments, various droppers, builder notes, and…

Attackers Use Text Salting to Evade AI-Powered Spam Filters
Cybersecurity firm Barracuda has reported a significant increase in phishing attacks employing "text salting," an older technique now being used to bypass AI-powered email filters. Since April, Barracuda has detected over one million retail-themed phishing attempts utilizing this method. While text salting has historically been effective against traditional secure email gateways, Barracuda…

Phishing Emails Use Fake Font Files to Deliver Windows Malware
A recent report indicates that threat actors are employing a novel technique involving fake font files to distribute malware via phishing emails, targeting Windows systems. These campaigns leverage specially crafted font files that, upon being opened by a user, can trigger the execution of arbitrary code, ultimately leading to a malware infection. The emails themselves are designed to appear…
Forg365 Phishing Platform Leverages AI for Microsoft 365 Account Theft
A new phishing-as-a-service (PhaaS) platform named Forg365 has emerged, specializing in the theft of Microsoft 365 accounts. The platform integrates adversary-in-the-middle (AiTM) and device code phishing techniques with AI-assisted lure generation, and provides a browser extension for persistent access to compromised accounts.

Telegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware Tools
Researchers have discovered RedWing, an Android spyware operation being sold as a subscription service via Telegram, with suspected ties to Russian threat actors. This sophisticated Malware-as-a-Service (MaaS) product lowers the barrier to entry for novice attackers, providing documentation, tutorial videos, and a bot that customizes and builds malicious applications on demand. The entire…

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
A sophisticated phishing campaign is actively targeting marketing professionals with deceptive job offers, aiming to compromise their Google account credentials. The attackers are impersonating well-known brands to lend credibility to their fraudulent recruitment efforts.

How the Reddit and Discord false report scam steals accounts
A social engineering scam is targeting users on Reddit and Discord, aiming to steal account credentials and lock users out of their accounts. The scam typically begins with a direct message from a stranger claiming that their account has been reported, and that the reporting account appears to be yours. Alternatively, the scammer might claim they accidentally reported your account and need…

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A sophisticated phishing campaign has been observed exploiting Microsoft 365's device code flow to gain unauthorized access to user accounts. The campaign, which ran from the last week of June into early July, utilized collaboration-themed lures to trick victims into compromising their credentials.

Fake Netflix, Coca-Cola, and FIFA job scams target marketers
Cybercriminals are impersonating well-known corporations like Netflix, Coca-Cola, Adidas, and FIFA in a sophisticated job-scam campaign targeting marketing professionals. The attackers are leveraging legitimate services and browser manipulation techniques to create a veneer of authenticity for their phishing operations.

Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud
Two young men have been arrested in the Netherlands in connection with a credit card phishing operation. Dutch police detained a 23-year-old from Zaandam and a 21-year-old from Amsterdam on June 23, 2026. Their homes were searched, and devices believed to be used in fraudulent activities, along with luxury items and a car, were seized.

Webinar tomorrow: Why modern email attacks require a new approach to defense
A webinar scheduled for July 8th will address the evolving landscape of email-based cyber threats and the limitations of current defense strategies. The event, titled "Stop chasing alerts: Automating email security with behavioral AI," will feature insights from Dan Nickolaisen, Solutions Architect Manager at Abnormal AI, and Eric Danneker, Director of Cyber Vigilance and Defense at Novant Health.

Google Is Suing Chinese Scammers Who Are Using Gemini
Google has initiated legal action against Outsider Enterprise, a China-based group accused of operating a "phishing-as-a-service" scheme that leverages Google's Gemini AI to generate fraudulent content. The lawsuit, filed by Google, alleges that Outsider Enterprise provides tools and instructions to individuals for creating sophisticated phishing websites and text message campaigns, even those…

Phishing poses as big-brand job interview to steal Google accounts
A sophisticated phishing campaign is targeting marketing professionals by impersonating over 30 major brands in fake job interview invitations, aiming to steal their Google account credentials. The operation leverages legitimate cloud services and a domain linked to Salesforce Marketing Cloud to build trust before redirecting victims to a malicious landing page.

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
A sophisticated cyber-espionage campaign, attributed to a threat actor with suspected ties to China, has been identified targeting Indian taxpayers, tax professionals, and corporate finance departments. The objective of this operation appears to be the deployment of a remote access trojan (RAT) known as DcRAT, with the ultimate goal of exfiltrating sensitive data from compromised systems.

When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website
Researchers have identified a sophisticated phishing campaign that bypasses traditional URL-checking defenses by exploiting a legitimate Microsoft authentication feature. The attack leverages the Microsoft Identity Platform's Device Authorization Grant, a protocol designed for devices with limited input capabilities, such as smart TVs or IoT devices, to authenticate users.

New Avalon Malware Framework Packs CrownX Ransomware Capabilities
A newly identified modular malware framework, dubbed Avalon, has been observed incorporating the capabilities of the CrownX ransomware. This sophisticated framework is being distributed through a multi-stage phishing campaign designed to circumvent standard security measures.

Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign
A newly identified threat actor, dubbed Armored Likho, has been observed conducting targeted phishing campaigns against government agencies and the electric power sector in Russia, Brazil, and Kazakhstan. This group, also referred to as Eagle Werewolf based on circumstantial evidence, employs a sophisticated toolkit that includes a previously undocumented information stealer named BusySnake…