phishing

A fake ChatGPT billing email is after your OpenAI password

A fake ChatGPT billing email is after your OpenAI password 2026-09-17 at 16:01 By Anamarija Pogorelec A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google […]

A fake ChatGPT billing email is after your OpenAI password Read More »

Phishing Research Challenges Conventional Security Awareness Testing

Phishing Research Challenges Conventional Security Awareness Testing 2026-09-11 at 20:23 By Kevin Townsend Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks. The post Phishing Research Challenges Conventional Security Awareness Testing appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Phishing Research Challenges Conventional Security Awareness Testing Read More »

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack 2026-09-11 at 15:48 By Eduard Kovacs Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking. The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek. This article […]

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack Read More »

Attackers call employees’ personal phones to break into Microsoft 365 accounts

Attackers call employees’ personal phones to break into Microsoft 365 accounts 2026-09-10 at 16:26 By Sinisa Markovic Attackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into handing over access to corporate cloud accounts. Once inside, they pull files and email […]

Attackers call employees’ personal phones to break into Microsoft 365 accounts Read More »

Cybercriminals are building phishing pages that exist only inside victims’ browsers

Cybercriminals are building phishing pages that exist only inside victims’ browsers 2026-09-10 at 10:14 By Sinisa Markovic A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda. “Instead of delivering a phishing page from a […]

Cybercriminals are building phishing pages that exist only inside victims’ browsers Read More »

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser 2026-09-09 at 13:00 By Kevin Townsend Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first […]

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser Read More »

Trezor customers hit with phishing calls and letters after shipping-partner breach

Trezor customers hit with phishing calls and letters after shipping-partner breach 2026-09-08 at 14:30 By Zeljka Zorz Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone numbers, and shipping addresses were exposed. “The leaked information could be used for […]

Trezor customers hit with phishing calls and letters after shipping-partner breach Read More »

IT help-desk vishing tricks executives into handing over Microsoft 365 access

IT help-desk vishing tricks executives into handing over Microsoft 365 access 2026-09-08 at 14:17 By Sinisa Markovic IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and other SaaS accounts, according to Arctic Wolf. The company is tracking the […]

IT help-desk vishing tricks executives into handing over Microsoft 365 access Read More »

Microsoft Teams is about to make QR code phishing much harder

Microsoft Teams is about to make QR code phishing much harder 2026-09-04 at 11:28 By Sinisa Markovic Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the organization. Users will need to reveal the image […]

Microsoft Teams is about to make QR code phishing much harder Read More »

Attackers are going after prominent individuals through OAuth phishing, FBI warns

Attackers are going after prominent individuals through OAuth phishing, FBI warns 2026-09-02 at 13:58 By Sinisa Markovic Attackers are targeting prominent individuals, their relatives and personal contacts to gain persistent access to their accounts, including private emails and files, the FBI has warned. The FBI’s Internet Crime Complaint Center (IC3) says the activity, which uses […]

Attackers are going after prominent individuals through OAuth phishing, FBI warns Read More »

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks 2026-09-01 at 17:07 By Sinisa Markovic A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Palo Alto Networks’ […]

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks Read More »

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes 2026-08-26 at 15:46 By Sinisa Markovic A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation […]

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes Read More »

Bogus recruiters go after high-value corporate credentials on mobile

Bogus recruiters go after high-value corporate credentials on mobile 2026-08-26 at 13:05 By Sinisa Markovic Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are using a technique called browser-in-the-browser, or BitB, which CTM360 documented in earlier research on recruitment […]

Bogus recruiters go after high-value corporate credentials on mobile Read More »

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack 2026-08-25 at 12:24 By Sinisa Markovic Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system. The admission came after the extortion group […]

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack Read More »

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited 2026-08-24 at 20:38 By Eduard Kovacs A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard. The post ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited Read More »

Fake bank websites play dead to evade security scanners

Fake bank websites play dead to evade security scanners 2026-08-24 at 08:00 By Sinisa Markovic A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners has been discovered by Fortra. The company’s threat intelligence unit, Fortra Intelligence and Research Experts (FIRE), […]

Fake bank websites play dead to evade security scanners Read More »

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets 2026-08-21 at 17:22 By Kevin Townsend Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek. […]

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets Read More »

Brand Impersonation Takedown: From Whack-a-Mole to Managed Response

Brand Impersonation Takedown: From Whack-a-Mole to Managed Response 2026-08-18 at 05:23 By Mihir Bagwe Manual brand impersonation takedowns fail because attackers move faster than ticket-based abuse reports can resolve — phishing pages and fake executive profiles often do their damage within hours of going live, while manual removal can take days. A managed takedown program […]

Brand Impersonation Takedown: From Whack-a-Mole to Managed Response Read More »

SafePal breach affects 39,798 customers, data allegedly for sale

SafePal breach affects 39,798 customers, data allegedly for sale 2026-08-17 at 13:29 By Sinisa Markovic Cryptocurrency wallet maker SafePal disclosed a data breach that exposed order information for 39,798 customers, including names, email addresses, shipping addresses, phone numbers and purchase details. The company traced the exposure to an authorization flaw in a plug-in used for […]

SafePal breach affects 39,798 customers, data allegedly for sale Read More »

Lazarus hackers pair fake job offers with Windows zero-day exploit

Lazarus hackers pair fake job offers with Windows zero-day exploit 2026-08-12 at 14:48 By Sinisa Markovic The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found. The activity is part of Operation Dream Job, a […]

Lazarus hackers pair fake job offers with Windows zero-day exploit Read More »

Scroll to Top