phishing

Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks

Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks 2026-07-30 at 14:22 By Sinisa Markovic Attackers are moving away from fake Microsoft login pages in favor of abusing Microsoft’s own authentication system, letting phishing campaigns slip past the warning signs employees are trained to spot, according to Check Point. Between June 25 and […]

Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks Read More »

Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts

Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts 2026-07-28 at 07:30 By Sinisa Markovic Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have warned. Victims are asked to log in with their email address

Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts Read More »

ChatGPT joins the most impersonated brands in phishing attacks

ChatGPT joins the most impersonated brands in phishing attacks 2026-07-27 at 14:08 By Anamarija Pogorelec Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts

ChatGPT joins the most impersonated brands in phishing attacks Read More »

Russian hackers exploit unpatched Zimbra servers to steal emails

Russian hackers exploit unpatched Zimbra servers to steal emails 2026-07-24 at 15:09 By Sinisa Markovic Russian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform. Laundry Bear (also known as Void Blizzard, CL-STA-1114, and

Russian hackers exploit unpatched Zimbra servers to steal emails Read More »

Police dismantle Kratos phishing platform behind 15,000 monthly campaigns

Police dismantle Kratos phishing platform behind 15,000 monthly campaigns 2026-07-22 at 11:02 By Sinisa Markovic German and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was arrested in Indonesia by local police. Seizure banner (Source: BKA) The takedown was led by the Frankfurt public

Police dismantle Kratos phishing platform behind 15,000 monthly campaigns Read More »

The script, not the voice, is what makes AI voice phishing work

The script, not the voice, is what makes AI voice phishing work 2026-07-17 at 10:31 By Sinisa Markovic The call comes in at 4:40 on a Friday. The voice belongs to a senior manager, or sounds close enough, and she needs a password reset before a flight. She is polite, she is in a hurry,

The script, not the voice, is what makes AI voice phishing work Read More »

Finance phishing works because it sounds boringly normal

Finance phishing works because it sounds boringly normal 2026-07-16 at 06:53 By Anamarija Pogorelec Finance departments process a constant stream of invoices, contracts, payment notices, and procurement emails, making email one of the most common initial access vectors for threat actors. According to Cofense, attackers exploit those workflows with phishing emails that resemble legitimate business

Finance phishing works because it sounds boringly normal Read More »

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers 2026-07-10 at 14:06 By Ionut Arghire The attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages. The post Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers Read More »

Thousands of malicious AI skills found capable of stealing data, running malware

Thousands of malicious AI skills found capable of stealing data, running malware 2026-07-08 at 12:00 By Anamarija Pogorelec AI agents can browse the web, use external tools, execute commands, and perform tasks on behalf of users. Many rely on skills that define how they interact with services and data. Malicious skills can abuse those capabilities

Thousands of malicious AI skills found capable of stealing data, running malware Read More »

The ARToken phishing panel targets Microsoft 365 accounts

The ARToken phishing panel targets Microsoft 365 accounts 2026-07-01 at 13:00 By Sinisa Markovic Accounts-payable staff at U.S. companies keep receiving invoice emails that look like they come from vendors they already work with. One landed at a life-sciences company in April 2026, addressed to the person who handles payments and written in the voice

The ARToken phishing panel targets Microsoft 365 accounts Read More »

$3 Million Reportedly Stolen in Polymarket Hack

$3 Million Reportedly Stolen in Polymarket Hack 2026-06-26 at 12:47 By Eduard Kovacs The decentralized prediction market said hackers targeted some of its users through a compromise of a third-party vendor. The post $3 Million Reportedly Stolen in Polymarket Hack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

$3 Million Reportedly Stolen in Polymarket Hack Read More »

Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials

Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials 2026-06-26 at 12:26 By Sinisa Markovic Mirage2FA, a phishing kit that combines short-lived HTML smuggling with obfuscated JavaScript loaders to deliver fake Microsoft 365 login pages and steal credentials during MFA prompts, has been identified by researchers at Fortra. Fortra based its analysis on

Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials Read More »

Algerian national accused of running cybercrime marketplaces extradited to US

Algerian national accused of running cybercrime marketplaces extradited to US 2026-06-24 at 17:09 By Sinisa Markovic An Algerian national accused of running online marketplaces that sold phishing kits and fraud tools has been extradited from Spain to the United States to face bank fraud conspiracy charges. The post Algerian national accused of running cybercrime marketplaces

Algerian national accused of running cybercrime marketplaces extradited to US Read More »

Phishing attack on healthcare firm Xsolis impacts 1.4 million people

Phishing attack on healthcare firm Xsolis impacts 1.4 million people 2026-06-24 at 15:00 By Sinisa Markovic Healthcare technology company Xsolis confirmed that a phishing attack resulted in unauthorized access to its network. The company develops AI-powered software for hospitals, health systems, and health plans and serves more than 600 hospitals and health insurers. “On January

Phishing attack on healthcare firm Xsolis impacts 1.4 million people Read More »

Phishing hides in routine Microsoft 365 workflows

Phishing hides in routine Microsoft 365 workflows 2026-06-23 at 11:26 By Sinisa Markovic Attackers are abusing Outlook Groups and Microsoft 365 collaboration features to make phishing campaigns appear routine, according to Fortra. “The technique shifts malicious intent away from a single phishing email into a trusted productivity workflow. A user may see what looks like

Phishing hides in routine Microsoft 365 workflows Read More »

Operation FanTrap: Inside the FIFA 2026 Fraud Ecosystem

Operation FanTrap: Inside the FIFA 2026 Fraud Ecosystem 2026-06-18 at 17:05 By Ashish Khaitan Executive Summary  The FIFA World Cup 2026 has become more than a global sporting event. It has evolved into a large-scale cybercrime opportunity exploited by threat actors through a coordinated ecosystem of fraudulent domains, social media channels, messaging platforms, pirated streaming

Operation FanTrap: Inside the FIFA 2026 Fraud Ecosystem Read More »

FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service

FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service 2026-06-15 at 12:31 By Ionut Arghire The platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses. The post FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service Read More »

Cybercriminals are moving away from mass phishing campaigns

Cybercriminals are moving away from mass phishing campaigns 2026-06-12 at 13:47 By Sinisa Markovic Phishing activity declined by roughly 20% in both 2024 and 2025, according to research from Zscaler’s ThreatLabz team. The drop followed years of growth that pushed phishing activity above 2 billion hits in 2023. “Phishing volume measured by blocked emails is

Cybercriminals are moving away from mass phishing campaigns Read More »

New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials

New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials 2026-06-10 at 17:24 By Sinisa Markovic A new Browser-in-the-Browser (BitB) phishing campaign is targeting Microsoft 365 users with fake login popups designed to closely mimic legitimate browser authentication windows, according to Palo Alto Networks Unit 42. The attack relies on a fake browser

New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials Read More »

MokN Raises $15 Million for Phish-Back Platform

MokN Raises $15 Million for Phish-Back Platform 2026-05-29 at 17:34 By Ionut Arghire MokN’s platform deploys realistic decoy access points to lure attackers into revealing compromised credentials, enabling organizations to respond before abuse occurs. The post MokN Raises $15 Million for Phish-Back Platform appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

MokN Raises $15 Million for Phish-Back Platform Read More »

Scroll to Top