phishing

Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations

Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations 2026-05-05 at 17:45 By Eduard Kovacs The malicious emails claim to contain a conduct report and lure victims to a Microsoft phishing website that leverages AitM. The post Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations appeared first on SecurityWeek. This article is an excerpt […]

Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations Read More »

Robinhood Vulnerability Exploited for Phishing Attacks

Robinhood Vulnerability Exploited for Phishing Attacks 2026-04-28 at 18:06 By Eduard Kovacs Legitimate-looking emails coming from Robinhood systems lured recipients to phishing websites. The post Robinhood Vulnerability Exploited for Phishing Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Robinhood Vulnerability Exploited for Phishing Attacks Read More »

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface 2026-04-23 at 14:17 By Kevin Townsend New analysis from Abnormal AI reveals how attackers have abandoned technical exploits to weaponize routine workflows and internal trust. The post The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface appeared first on SecurityWeek. This article

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface Read More »

Cyberattack on French government agency triggers phishing alert

Cyberattack on French government agency triggers phishing alert 2026-04-22 at 19:55 By Sinisa Markovic France Titres, a French government agency, has disclosed a data breach that may have exposed user data from its online portal. France Titres, also known as the Agence nationale des titres sécurisés (ANTS), operates under the French Ministry of the Interior

Cyberattack on French government agency triggers phishing alert Read More »

Phishing reclaims the top initial access spot, attackers experiment with AI tools

Phishing reclaims the top initial access spot, attackers experiment with AI tools 2026-04-22 at 13:48 By Anamarija Pogorelec Phishing returned as the leading method attackers used to break into organizations in the first quarter of 2026, accounting for over a third of engagements where initial access could be determined, according to Cisco Talos. It is

Phishing reclaims the top initial access spot, attackers experiment with AI tools Read More »

Scattered Spider hacker pleads guilty to stealing $8 million in cryptocurrency

Scattered Spider hacker pleads guilty to stealing $8 million in cryptocurrency 2026-04-21 at 17:36 By Sinisa Markovic A British national tied to the Scattered Spider cybercrime group pleaded guilty to hacking multiple companies via SMS phishing and stealing over $8 million in virtual currency from US victims. Tyler Robert Buchanan, 24, of Dundee, Scotland, pleaded

Scattered Spider hacker pleads guilty to stealing $8 million in cryptocurrency Read More »

AI platform ATHR makes voice phishing a one-person job

AI platform ATHR makes voice phishing a one-person job 2026-04-20 at 14:37 By Zeljka Zorz For $4,000 and a cut of the take, a lone criminal can now run a fully automated voice-phishing operation via ATHR, a plaform that spoofs emails alerts from Google, Microsoft, and Coinbase, buries a phone number in each message, and

AI platform ATHR makes voice phishing a one-person job Read More »

Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks 2026-04-18 at 15:32 By Ionut Arghire Threat actors are reusing Tycoon 2FA tools across other phishing kits following the platform’s disruption. The post Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks Read More »

Windows is getting stronger RDP file protections to fight phishing attacks

Windows is getting stronger RDP file protections to fight phishing attacks 2026-04-16 at 01:19 By Sinisa Markovic Microsoft has introduced new Windows protections starting with the April 2026 security update to reduce phishing attacks that abuse Remote Desktop (.rdp) files. With these updates, the Remote Desktop Connection app displays stronger warning dialogs before a connection

Windows is getting stronger RDP file protections to fight phishing attacks Read More »

W3LL phishing service sold for $500 dismantled by the FBI

W3LL phishing service sold for $500 dismantled by the FBI 2026-04-14 at 18:15 By Sinisa Markovic The W3LL phishing kit, a cybercrime tool used to impersonate legitimate login pages and steal usernames and passwords, has been dismantled by the FBI and Indonesian law enforcement authorities. Officials estimate the operation was tied to more than $20

W3LL phishing service sold for $500 dismantled by the FBI Read More »

Booking.com data breach: Customer reservation data exposed

Booking.com data breach: Customer reservation data exposed 2026-04-14 at 16:21 By Zeljka Zorz “Unauthorized third parties may have been able to access certain booking information associated with your reservation,” email alerts sent out by Booking.com over the weekend warn. The online travel agency did not say which system(s) were accessed by the unauthorized third parties

Booking.com data breach: Customer reservation data exposed Read More »

Phishers sneak through using GitHub and Jira’s own mail delivery infrastructure

Phishers sneak through using GitHub and Jira’s own mail delivery infrastructure 2026-04-09 at 08:27 By Sinisa Markovic Attackers are abusing the notification systems of SaaS platforms like GitHub and Jira to send phishing and spam emails, Cisco Talos researchers are warning. “Because the emails are dispatched from the platform’s own infrastructure, they satisfy all standard

Phishers sneak through using GitHub and Jira’s own mail delivery infrastructure Read More »

AI-enabled device code phishing campaign exploits OAuth flow for account takeover

AI-enabled device code phishing campaign exploits OAuth flow for account takeover 2026-04-07 at 14:59 By Anamarija Pogorelec A phishing campaign that bypasses the standard 15-minute expiration window through automation and dynamic code generation, leveraging the OAuth Device Code Authentication flow to compromise organizational accounts at scale, has been observed by the Microsoft Defender Security Research

AI-enabled device code phishing campaign exploits OAuth flow for account takeover Read More »

Why your phishing simulations aren’t building a security culture

Why your phishing simulations aren’t building a security culture 2026-03-25 at 08:07 By Help Net Security Security culture isn’t built by phishing simulations. In this Help Net Security video, Dan Potter, VP of Cyber Resilience at Immersive, argues that annual training videos and quarterly phishing tests happen in calm, controlled settings that tell us nothing

Why your phishing simulations aren’t building a security culture Read More »

Tycoon 2FA Fully Operational Despite Law Enforcement Takedown

Tycoon 2FA Fully Operational Despite Law Enforcement Takedown 2026-03-23 at 12:32 By Ionut Arghire Attack volumes are back to pre-disruption levels, and the adversary tactics have remained unchanged. The post Tycoon 2FA Fully Operational Despite Law Enforcement Takedown appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Tycoon 2FA Fully Operational Despite Law Enforcement Takedown Read More »

Russian hackers go after high-value targets through Signal

Russian hackers go after high-value targets through Signal 2026-03-23 at 11:20 By Sinisa Markovic Russian intelligence-linked hackers are targeting commercial messaging platforms, with Signal a primary focus, the FBI and CISA warn. The campaign is aimed at individuals of intelligence interest, including government personnel, journalists, and others with access to sensitive communications. It is believed

Russian hackers go after high-value targets through Signal Read More »

Russian APT Exploits Zimbra Vulnerability Against Ukraine

Russian APT Exploits Zimbra Vulnerability Against Ukraine 2026-03-19 at 16:53 By Ionut Arghire Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser. The post Russian APT Exploits Zimbra Vulnerability Against Ukraine appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Russian APT Exploits Zimbra Vulnerability Against Ukraine Read More »

Scroll to Top