phishing

W3LL phishing service sold for $500 dismantled by the FBI

W3LL phishing service sold for $500 dismantled by the FBI 2026-04-14 at 18:15 By Sinisa Markovic The W3LL phishing kit, a cybercrime tool used to impersonate legitimate login pages and steal usernames and passwords, has been dismantled by the FBI and Indonesian law enforcement authorities. Officials estimate the operation was tied to more than $20 […]

W3LL phishing service sold for $500 dismantled by the FBI Read More »

Booking.com data breach: Customer reservation data exposed

Booking.com data breach: Customer reservation data exposed 2026-04-14 at 16:21 By Zeljka Zorz “Unauthorized third parties may have been able to access certain booking information associated with your reservation,” email alerts sent out by Booking.com over the weekend warn. The online travel agency did not say which system(s) were accessed by the unauthorized third parties

Booking.com data breach: Customer reservation data exposed Read More »

Phishers sneak through using GitHub and Jira’s own mail delivery infrastructure

Phishers sneak through using GitHub and Jira’s own mail delivery infrastructure 2026-04-09 at 08:27 By Sinisa Markovic Attackers are abusing the notification systems of SaaS platforms like GitHub and Jira to send phishing and spam emails, Cisco Talos researchers are warning. “Because the emails are dispatched from the platform’s own infrastructure, they satisfy all standard

Phishers sneak through using GitHub and Jira’s own mail delivery infrastructure Read More »

AI-enabled device code phishing campaign exploits OAuth flow for account takeover

AI-enabled device code phishing campaign exploits OAuth flow for account takeover 2026-04-07 at 14:59 By Anamarija Pogorelec A phishing campaign that bypasses the standard 15-minute expiration window through automation and dynamic code generation, leveraging the OAuth Device Code Authentication flow to compromise organizational accounts at scale, has been observed by the Microsoft Defender Security Research

AI-enabled device code phishing campaign exploits OAuth flow for account takeover Read More »

Why your phishing simulations aren’t building a security culture

Why your phishing simulations aren’t building a security culture 2026-03-25 at 08:07 By Help Net Security Security culture isn’t built by phishing simulations. In this Help Net Security video, Dan Potter, VP of Cyber Resilience at Immersive, argues that annual training videos and quarterly phishing tests happen in calm, controlled settings that tell us nothing

Why your phishing simulations aren’t building a security culture Read More »

Tycoon 2FA Fully Operational Despite Law Enforcement Takedown

Tycoon 2FA Fully Operational Despite Law Enforcement Takedown 2026-03-23 at 12:32 By Ionut Arghire Attack volumes are back to pre-disruption levels, and the adversary tactics have remained unchanged. The post Tycoon 2FA Fully Operational Despite Law Enforcement Takedown appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Tycoon 2FA Fully Operational Despite Law Enforcement Takedown Read More »

Russian hackers go after high-value targets through Signal

Russian hackers go after high-value targets through Signal 2026-03-23 at 11:20 By Sinisa Markovic Russian intelligence-linked hackers are targeting commercial messaging platforms, with Signal a primary focus, the FBI and CISA warn. The campaign is aimed at individuals of intelligence interest, including government personnel, journalists, and others with access to sensitive communications. It is believed

Russian hackers go after high-value targets through Signal Read More »

Russian APT Exploits Zimbra Vulnerability Against Ukraine

Russian APT Exploits Zimbra Vulnerability Against Ukraine 2026-03-19 at 16:53 By Ionut Arghire Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser. The post Russian APT Exploits Zimbra Vulnerability Against Ukraine appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Russian APT Exploits Zimbra Vulnerability Against Ukraine Read More »

Security Firm Executive Targeted in Sophisticated Phishing Attack

Security Firm Executive Targeted in Sophisticated Phishing Attack 2026-03-16 at 16:43 By Ionut Arghire The attackers used a DKIM-signed phishing email, trusted redirect infrastructure, compromised servers, and Cloudflare-protected phishing pages. The post Security Firm Executive Targeted in Sophisticated Phishing Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Security Firm Executive Targeted in Sophisticated Phishing Attack Read More »

AI-Assisted Phishing Campaign Exploits Browser Permissions to Capture Victim Data

AI-Assisted Phishing Campaign Exploits Browser Permissions to Capture Victim Data 2026-03-16 at 08:24 By rohansinhacyblecom Executive Summary Cyble Research & Intelligence Labs (CRIL) has identified a widespread, highly active social engineering campaign hosted primarily on edgeone.app infrastructure. The initial access vectors are diverse — ranging from “ID Scanner,” and “Telegram ID Freezing,” to “Health Fund

AI-Assisted Phishing Campaign Exploits Browser Permissions to Capture Victim Data Read More »

HR, recruiters targeted in year-long malware campaign

HR, recruiters targeted in year-long malware campaign 2026-03-10 at 15:39 By Zeljka Zorz An attack campaign targeting HR departments and job recruiters has been stealthily compromising systems, Aryaka researchers have discovered. By avoiding analysis environments and leveraging a specialized module designed to kill antivirus and endpoint detection software, the Russian-speaking attacker(s) behind this campaign have

HR, recruiters targeted in year-long malware campaign Read More »

Phishing campaign spoofs local officials to steal permit fees

Phishing campaign spoofs local officials to steal permit fees 2026-03-10 at 13:01 By Sinisa Markovic The FBI is warning about a phishing scheme in which cybercriminals impersonate city and county officials to solicit fraudulent payments for planning and zoning permits. Criminals mine publicly available permit data to find likely targets and make their outreach appear

Phishing campaign spoofs local officials to steal permit fees Read More »

Russian hackers crack into officials’ Signal and WhatsApp accounts

Russian hackers crack into officials’ Signal and WhatsApp accounts 2026-03-09 at 17:02 By Sinisa Markovic Russian state hackers are trying to break into Signal and WhatsApp accounts used by diplomats, military staff, and government officials worldwide, Dutch intelligence agencies warned. They believe journalists and other people who attract attention from Moscow may also be affected.

Russian hackers crack into officials’ Signal and WhatsApp accounts Read More »

Internet Infrastructure TLD .arpa Abused in Phishing Attacks

Internet Infrastructure TLD .arpa Abused in Phishing Attacks 2026-03-09 at 15:37 By Ionut Arghire Abusing DNS record management controls, the threat actor hides the location of malicious content via Cloudflare. The post Internet Infrastructure TLD .arpa Abused in Phishing Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Internet Infrastructure TLD .arpa Abused in Phishing Attacks Read More »

Why phishing still works today

Why phishing still works today 2026-03-06 at 08:30 By Help Net Security In this Help Net Security video, Gal Livschitz, Senior Penetration Tester at Terra Security, explains how phishing has evolved and why employees still fall for it. He outlines how phishing now uses HTTPS, branded pages, and lookalike domains, making attacks harder to spot.

Why phishing still works today Read More »

Authorities pull plug on Tycoon 2FA phishing-as-a-service platform

Authorities pull plug on Tycoon 2FA phishing-as-a-service platform 2026-03-05 at 10:51 By Sinisa Markovic Tycoon 2FA, a phishing-as-a-service platform that allowed cybercriminals to bypass MFA and break into online accounts, has been disrupted by law enforcement agencies and cybersecurity partners. Takedown of the Tycoon 2FA phishing-as-a-service platform (Source: Europol) Active since August 2023, Tycoon 2FA

Authorities pull plug on Tycoon 2FA phishing-as-a-service platform Read More »

Scroll to Top