LIVE · cybersecurity feed
Live wire
Android’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsEven with OT network visibility, critical infrastructure operators struggle with legacy equipmentASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-Day

phishing news

111 stories · page 3 of 3
phishing

Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

Cybercriminals are employing sophisticated phishing techniques that automatically adapt to a victim's device and operating system, a tactic designed to significantly boost the success rate of their malicious campaigns. This adaptive approach allows attackers to tailor their attacks, delivering payloads specifically engineered for the target's environment, thereby increasing the likelihood of a…

banking trojanhigh

Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

Researchers have observed a new campaign by the banking Trojan Ousaban, which is actively targeting users in Spain and Portugal. This malware, previously known for its activity in Brazil, is being distributed via a sophisticated phishing scheme that employs geofencing and environmental checks to limit its reach.

CVE-2026-20245high

Texas Parks and Wildlife, WordPress Plugin Vendor Hit by Data Breaches

The Texas Parks and Wildlife Department has confirmed a data breach affecting its hunting and fishing license system vendor, exposing personal information for over 3 million customers. Separately, ShapedPlugin, a vendor of WordPress plugins, suffered a supply chain attack that delivered malicious updates to its paid plugins.

phishing

ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365

A phishing-as-a-service platform known as ARToken has been identified, exhibiting significant overlap with the previously documented EvilTokens operation. This platform provides affiliates with a comprehensive toolkit for targeting Microsoft 365 accounts, including capabilities for device code phishing, Primary Refresh Token (PRT) persistence, email access, business email compromise (BEC)…

phishing

Phishing Attack Targets MetaMask Users with Fake Credentials

A phishing campaign is targeting users of the popular cryptocurrency wallet MetaMask, attempting to steal their account credentials. The fraudulent emails, which began circulating recently, mimic legitimate communications to trick users into revealing sensitive information.

phishing

Phishers Gain Persistence at EU, Asia Hospitality Orgs

Cybercriminals are employing sophisticated phishing campaigns targeting organizations in the European Union and Asia, leveraging malicious zip files and social engineering tactics to gain a foothold and establish persistence. These attacks, observed by Microsoft and Trend Micro, utilize obfuscation techniques and even exploit blockchain technology to evade detection and deliver malware.

CVE-2026-20245high

29th June – Threat Intelligence Report

A recent threat intelligence report has detailed a range of cyber incidents, from supply chain attacks and data breaches affecting major companies to the exploitation of artificial intelligence technologies for malicious purposes. The report highlights the ongoing evolution of cyber threats, emphasizing the need for robust security measures across various sectors.

email securityhigh

Cybercriminals Target Email Inboxes for Identity Theft

Email inboxes are increasingly targeted by cybercriminals due to their central role in digital identity and access, according to cybersecurity researchers. Attackers leverage compromised email accounts to gain broader access to other online services, facilitate financial fraud, and launch more sophisticated attacks.

e-commerce fraudhigh

Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams

A recent investigation by Bitdefender Labs has uncovered a significant escalation in fake online shop campaigns targeting consumers across 12 European countries between March and May 2026. These operations, far from being isolated incidents, are now functioning as coordinated, multinational businesses employing professional e-commerce tactics.

phishing

Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed

AI coding assistants can be tricked into leaking sensitive company information through specially crafted bug reports, bypassing traditional security measures like phishing emails or malware. This vulnerability arises from the extensive trust and access granted to these AI tools, which can read code, browse file systems, and execute commands.

malwarehigh

Threat Actors Weaponize AI Hype to Deliver AsyncRAT

Cybercriminals are leveraging the widespread interest in artificial intelligence to distribute malware, according to a recent analysis by FortiGuard Labs. Threat actors are creating malicious files that appear to be guides or resources related to AI, aiming to trick individuals searching for information on the technology.

fifa world cup

Cybercriminals Are Targeting the FIFA World Cup 2026

Cybercriminals are actively targeting the upcoming FIFA World Cup 2026, establishing infrastructure and launching various scams to exploit the event's global appeal, according to research from FortiGuard Labs. The tournament, set to begin on June 11, 2026, is expected to attract significant attention and drive a high volume of digital transactions, creating a fertile ground for malicious actors.

scams

Football Fever Fuels Scam Campaigns Across Email and Social Media

Football fans are increasingly becoming targets of sophisticated scam operations that leverage the excitement surrounding major tournaments and club loyalties, according to recent findings from Bitdefender Labs. Investigations have uncovered over 55 distinct scam campaigns exploiting various aspects of football fandom, including merchandise, streaming services, collectibles, and giveaways.…

phishinghigh

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data

A recent phishing campaign is distributing a variant of the PureLogs malware, designed to steal sensitive data from compromised Windows systems. The campaign employs a multi-stage attack chain involving obfuscated JavaScript, PowerShell, and process hollowing techniques.

smishing

Operation Road Trap: Fake toll and parking texts are spreading worldwide

Scammers are globally targeting drivers with fraudulent text messages impersonating toll operators, parking authorities, and transport agencies, according to a recent analysis by Bitdefender Labs. Since December 2025, researchers have tracked these "smishing" campaigns, which have sent over 79,000 deceptive messages across 12 countries. The active campaigns aim to trick recipients into paying…