2026-08-21 11:11 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-21 11:40 UTC
Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead. Threat actors target researchers, […]
P0
2026-08-20 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Kaseya · indexed 2026-08-20 14:20 UTC
AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past the inbox. [...]
P0
2026-08-20 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-20 14:40 UTC
Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an additio…
P0
2026-08-20 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Joey Chen · indexed 2026-08-20 10:15 UTC
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
P0
2026-08-20 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Bill Batchelor · indexed 2026-08-20 10:05 UTC
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.
P0
2026-08-19 16:58 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-08-19 17:15 UTC
A spear-phishing campaign by a China-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by the country's APTs.
P0
2026-08-19 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress researcher uncovers post-Black Hat & DEF CON phishing campaign using X DMs & malicious documents to deliver AMOS, NetSupport RAT, and other malware.
P0
2026-08-19 11:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 13:35 UTC
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person. From Bad Content to Bad Intent to AI on Both Sides Phishing 1.0 was bad
P0
2026-08-19 07:28 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB exposes a Mexican PhaaS operation targeting over 20 financial institutions with live phishing, AI vishing, and mobile RAT capabilities.
P0
2026-08-18 12:49 UTC
Vendor Research
Rapid7 · Rapid7 Labs · indexed 2026-08-18 15:35 UTC
You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive program…
P15
2026-08-18 07:18 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-18 07:50 UTC
Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a […]
P0
2026-08-17 15:44 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-08-17 16:25 UTC
The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.
P0
2026-08-17 12:00 UTC
Government
NIST Cybersecurity Insights · Julie Haney, Jody Jacobs · indexed 2026-08-17 12:40 UTC
When was the last time a cybersecurity process at work made you want to scream? Maybe it was a password requirement so complicated you had to write it down (defeating the purpose), a phishing simulation test that felt more like a trap than a lesson, or a confusing security warning pop-up that interrupted your work. Or maybe you’re on the other side of the equation, working as a cybersecurity professional who is wrangling a half dozen disconnected dashboards, drowning in alerts (all flagged "urg…
P0
2026-08-17 11:29 UTC
Vendor Research
Rapid7 · Anna Širokova · indexed 2026-08-18 15:35 UTC
Operation ASTERIX overviewRapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered …
P0
2026-08-17 09:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.
P0
2026-08-14 14:00 UTC
Security Journalism
BleepingComputer · Sponsored by Material Security · indexed 2026-08-15 14:33 UTC
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. [...]
P0
2026-08-14 10:57 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC
Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials and, in more advanced cases, relay multi-factor authentication (MFA) prompts in real time. CTM360, which detailed the activity in a new report titled RecruitTrap, said it
P0
2026-08-13 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Chetan Raghuprasad · indexed 2026-08-15 14:33 UTC
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.
P0
2026-08-10 13:19 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC
North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware. South Korean security firm Genians says it uncovered the
P0
2026-08-10 12:25 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a
P0
2026-08-07 18:16 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via
P0
2026-08-07 10:38 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. "The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,
P0
2026-08-06 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice p…
P0
2026-08-04 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A fake Bank of America phishing email kicks off a multi-stage malware infection chain. See how one convincing bank scam unravels.
P0
2026-08-04 07:00 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-08-15 18:55 UTC
Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.
P0
2026-07-31 21:01 UTC
Vendor Research
Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-08-15 18:55 UTC
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first on Microsoft Security Blog.
P0
2026-07-31 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is tracking an evolving wave of device code phishing that abuses trusted Microsoft 365 sign-in flows. Learn the signals defenders should watch for and how to respond.
P0
2026-07-28 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Lexi DiScola · indexed 2026-08-15 14:33 UTC
Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.
P0
2026-07-27 09:32 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Most business email compromise (BEC) attacks start with stolen credentials, not a malicious email. Group-IB uses threat intelligence to detect compromised accounts before attackers log in — predicting BEC before it starts.
P0
2026-07-16 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Build personalized, realistic phishing scenarios with Huntress Custom HTML for Custom Phishing, tailored to your organization's unique risks and vendors.
P0