2026-07-09 20:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Build a security awareness training program that actually changes user behavior. Huntress Managed SAT delivers engaging content, phishing sims, and results.
P0
2026-07-07 12:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is tracking a threat actor group as they evolve a phishing attack that uses a Facebook feature to send the initial spam lure.
P0
2026-07-02 12:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress Managed SAT now offers localized phishing simulations for Canada, using familiar, country-specific brands and scenarios to provide more effective security awareness training for your learners.
P0
2026-07-01 08:35 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog documents Group-IB’s research into an SMS phishing campaign targeting Serbian road users through the impersonation of Serbia's state road authority, and how it can be linked to both Darcula and Phoenix PhaaS platforms with victims across the globe.
P0
2026-06-22 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
During the June Tradecraft Tuesday, Huntress researchers looked at device code phishing variations and why threat actors love this attack so much.
P0
2026-06-18 04:45 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Se ha descubierto una infraestructura de phishing modular dirigida a múltiples bancos mexicanos, que abusa de GitHub Pages, emplea scripts ofuscados y centraliza la exfiltración de credenciales mediante la API de SheetBest, lo que indica una operación de phishing escalable y persistente de múltiples marcas.
P0
2026-06-17 06:57 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
A modular phishing infrastructure targeting multiple Mexican banks has been uncovered, abusing GitHub-hosted Pages, employing obfuscated scripts, and featuring a centralized credential exfiltration via SheetBest API, indicating a scalable and persistent multi-brand phishing operation.
P0
2026-06-15 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A compromised terminal server became a phishing stager. A fake Boots survey aimed at 8.9 million inboxes, with the payload on a hacked Bolivian government site.
P0
2026-06-15 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and abuse…
P0
2026-06-15 08:55 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages
P0
2026-06-11 18:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress traced device code phishing from Tencent Cloud to Kali365, a Microsoft 365 kit that steals tokens and keeps access even after MFA or password resets.
P0
2026-06-11 07:51 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog provides a deep-dive into SniperDz, a centralised PhaaS platform with more than 80 ready-made phishing templates impersonating over 30 global brands, and uncovers the hidden infrastructure behind this sophisticated and highly-organized fraud ecosystem.
P0
2026-06-10 07:33 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
SilabRAT (aka SnappyClient) is an advanced Remote Access Trojan (RAT) sold as a Malware-as-a-Service (MaaS) on Darkweb forums. Developed by the threat actor "o1oo1," SilabRAT is heavily focused on financial gain through credential theft. It offers stability and is capable of bypassing existing security measures.
P0
2026-06-05 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC
Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United States. UNC3753 leverages voice phishing (vishing) and social engineering deception tech…
P0
2026-06-04 06:15 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Los investigadores de Group-IB exponen una operación de smishing y phishing a gran escala que suplanta más de 260 marcas en 72 países, utilizando páginas de error 524 falsas para evadir el análisis.
P0
2026-06-03 07:00 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB researchers expose a large-scale smishing and phishing operation impersonating 260+ brands across 72 countries, using fake Cloudflare error pages, geofencing, and encrypted WebSocket channels for real-time credit card theft.
P0
2026-05-29 14:19 UTC
Vendor Research
Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC
Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered a 1-click open redirection technique in Amazon Cognito that can be triggered by abusing the OAuth error-handling mechanism. The vulnerability stems from AWS's OAuth implementation validation sequence: if validation fails due to an unsupported scope, mismatched PKCE parameters, or an unsupported response type, the error handling processes the failure and automatically issues…
P0
2026-05-29 13:56 UTC
Vendor Research
Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC
Microsoft Entra ID 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered new techniques to trigger 1-click open redirection attacks in Microsoft Entra ID by abusing the OAuth error-handling mechanism. The attack relies on an initial setup phase where a threat actor registers an OAuth application in an actor-controlled tenant and configures its redirect_uri to point to an attacker-controlled domain. When a victim clicks on a specifically craf…
P0
2026-05-27 06:57 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
With the 2026 FIFA World Cup just weeks away, Group-IB researchers have uncovered six distinct fraud schemes, four independent threat actors, and over 4,300 fraudulent domains impersonating FIFA's official web presence — including a sophisticated phishing operation run by the Chinese-speaking threat actor GHOST STADIUM, whose campaign could cause losses reaching billions of dollars.
P0
2026-05-25 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that region. These services not only lower the barrier to entry for Chinese cyber criminals, but reveal …
P0
2026-05-15 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gain…
P0
2026-05-15 11:28 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Digital brand protection helps organizations detect and disrupt external threats, such as phishing sites, fake social profiles, counterfeit listings, and leaked credentials, before they become customer-facing fraud or reputational damage.
P0
2026-05-13 12:52 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This highly targeted scam scheme uses advanced phishing and social engineering cues, rely on brand recognition, event-based campaigns and emotional manipulation to defraud victims twice.
P0
2026-05-11 17:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Device code phishing doesn't need stolen passwords or malware—just a legitimate auth flow. Learn how EvilTokens weaponized AI to run this attack across 344 organizations.
P0
2026-05-01 17:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Social engineering has evolved. Device code phishing and AI lures bypass MFA and blend in. Build a cyber resilience strategy before the next attack lands.
P0
2026-04-29 06:54 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
While analyzing global smishing operations spanning APAC, LATAM, Europe, and MEA, Group-IB researchers uncovered the 'Phoenix System' administrative panel, a centralized Phishing-as-a-Service (PhaaS) platform with real-time victim monitoring, geofencing, and live-phishing interventions to bypass multi-factor authentication.
P0
2026-04-23 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC
Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim…
P0
2026-04-22 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Attackers are building workflows around AI—fake tools, spoofed answers, and machine-speed phishing. See how Huntress is tracking this shift and what it means for defenders.
P0
2026-04-16 06:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
The takedown of a global phishing-as-a-service ecosystem
P0
2026-04-01 10:32 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB researchers uncover an ongoing phishing campaign targeting major banks in the Philippines. This blog details how threat actors abuse trusted and legitimate platforms to deceive users and evade detection. It highlights a significant threat escalation with the successful hijacking of a legitimate domain to host malicious infrastructure, enabling threat actors to operate with even greater credibility and reduced detection.
P0