< ciso
brief />
Tag Banner

All news with #phishing tag

805 articles

Phishing Campaigns Hide AI Prompts to Manipulate Systems

📧 Researchers at Barracuda found phishing emails embedding hidden prompt injections alongside traditional lures, targeting both human recipients and AI assistants that summarize inboxes. The samples mimicked legitimate internal correspondence and used techniques like HTML comments, invisible CSS text, Base64 encoding and zero-width characters to conceal instructions. These hidden prompts could override assistant behavior to fake urgency, request wire transfers, or leak data, bypassing reputation and signature-based defenses.
read more →

Phishing Platform Mimics AI Ads to Harvest Credentials

🔒 Cybersecurity researchers disclosed a human-operated phishing platform impersonating AI ad products like Google Gemini, Anthropic Claude, and OpenAI ChatGPT. The sites lure targets with ad-management pitches and use a browser-in-the-browser (BitB) trick to present spoofed login windows that capture credentials and MFA codes. Operators fingerprint devices, relay victim inputs over Socket.IO, and select subsequent MFA challenges to complete account takeovers. The campaign surfaced pages such as museads.ai and leverages fake invitation emails, shared technology stacks, and misconfigured GitHub repos to scale attacks.
read more →

Rapid domain impersonation around Jev launch

🔍 TypeSafe launched the decision-model Jev in mid-September 2026 and within days attracted widespread lookalike domain registrations. Researchers monitored newly registered domains from August 14 to September 28 and found 167 Jev-related lookalikes, many designed for hyphenation, typos, or reseller plays. Several domains were configured with hosting and mail, elevating the risk of phishing, credential theft, and API key capture. The report highlights how quickly brand protection must act during intense public attention.
read more →

Scams and fake GTA VI leaks targeting gamers

🎮 Scammers are exploiting excitement around GTA VI’s November 19, 2026 release with fake leak sites, fraudulent preorders, and token schemes. Some sites claim to sell early builds or demo access for high prices, push dubious “human verifications” to harvest traffic or downloads, or collect personal and payment data via cloned storefronts. Others promote a $GTAVI crypto token promising access to the game, while many mimic Rockstar’s branding to fool users. Check domains carefully, avoid downloading archives from untrusted sources, and never pay or provide sensitive information to suspicious sites.
read more →

Fake AI Sites Steal Ad Accounts and MFA Codes

🔒 Researchers warn of a phishing campaign that uses fake ChatGPT, Gemini, Claude, and Perplexity pages to steal advertising account credentials and MFA codes via browser-in-the-browser attacks. The pages impersonate AI tools that promise ad planning and auditing, then open a simulated Google login to harvest passwords and authentication codes. Operators use a kit that mimics multiple OS/browser styles and can request repeated password and MFA entries, enabling account takeover or resale of compromised ad accounts.
read more →

Nikkei reports employee cloud account intrusions

🔒 Nikkei has disclosed unauthorized access to two employee cloud accounts, one of which was used to send about 9,000 phishing emails to staff and contacts. The company says a Google Workspace account was accessed since late July, potentially exposing 1,646 names and email addresses, and a Microsoft 365 account was abused on September 30 to distribute malicious messages. Nikkei reset passwords, notified affected individuals, and reported both incidents to Japan's data protection regulator while investigations continue.
read more →

ASOS push-notification claims Snowflake compromise

📣 Customers of online fashion retailer ASOS received a push notification on October 6 claiming a Snowflake compromise and urging engagement or data leakage. The message, signed ‘xuanyewengateway’, included a Telegram link; ASOS has not confirmed any breach. Experts cautioned users not to follow the link, advised password changes, and urged ASOS to review Snowflake logs and follow incident response protocols. Analysts noted the claim could indicate access to connected systems but stressed further verification is needed.
read more →

Nikkei discloses employee email account breaches

📧 Nikkei reported that attackers accessed two employee email accounts, first a Google Workspace account in late July and later a Microsoft 365 account in September. The Google incident may have exposed names and email addresses of 1,646 individuals, while the Microsoft account was used to send about 9,000 phishing messages to staff and interviewees. Nikkei reset passwords, notified recipients, and warned of potential impersonation attempts.
read more →

China-aligned TA419 targets US AI policy experts

🛡️ TA419, a China-aligned cyber espionage group, has run credential phishing campaigns aimed at U.S. AI policy experts at think tanks, universities, and law firms. The actor impersonated economists, policymakers, and an Anthropic employee to phish victims via shortened links that redirect to an OneDrive adversary-in-the-middle (AitM) page using a Frameless BitB technique. Proofpoint links this activity to broader Chinese intelligence objectives amid U.S.–China AI tensions.
read more →

Microsoft warns AI compresses attack timelines

🔍 Microsoft’s 2026 Digital Defense Report warns that AI has allowed threat actors to compress parts of the cyber-attack lifecycle from days to minutes, pressuring defenders to adapt rapidly. The report highlights increased use of agentic models for vulnerability discovery, customized phishing, and bespoke malware, and calls for investment in AI-based defenses and stronger identity controls like phishing-resistant MFA.
read more →

Amazon Prime Big Deal Days 2026: Rising Cyber Threats

🔎 New Check Point Research findings show a surge in Amazon- and Prime Day-related domain registrations ahead of Fall Prime Day (October 6–7, 2026), with many domains flagged as malicious. The report documents phishing campaigns, fake storefronts, and credential-theft infrastructure targeting shoppers worldwide, and warns that generative AI is enabling more convincing scams. It urges consumers and organizations to verify URLs, enable MFA, and block threats proactively.
read more →

CSuite phishing campaign escalates to account and endpoint access

🔍 ANY.RUN researchers traced a US-focused CSuite phishing campaign across hundreds of sandbox analyses, finding 51% of submissions from the United States and heavy exposure in technology, manufacturing, government, and consulting. The operation uses business-themed lures (Adobe, DocuSign, Zoom, Microsoft 365) to either harvest credentials or deliver droppers that install legitimate remote-access tools like ScreenConnect and Action1. This dual path enables mailbox takeover, financial fraud, persistent RMM access, and lateral misuse of trusted identities, expanding impact beyond typical phishing.
read more →

Phishing abuses RMM tools to secure persistent access

🛡️ Microsoft observed July 2026 phishing campaigns that distributed a masqueraded, digitally signed MSP360 RMM installer via diverse social-engineering lures and hosting services. The installer established persistent MSP360 services after UAC elevation and was used to silently download and install a ConnectWise ScreenConnect client as a secondary remote-access channel. Threat actors then used these legitimate administration platforms to deploy additional tooling for credential access and information collection while blending into normal IT workflows.
read more →

Ex-Air Force Members Sentenced for BEC Fraud

🔒 Two former U.S. Air Force airmen were sentenced to a combined 189 months in federal prison for conducting multi-year business email compromise (BEC) and phishing campaigns while stationed at Dover Air Force Base. They stole employee email credentials, used spoofed addresses to redirect corporate payments, and laundered funds through accomplices in the U.S. and abroad. The pair diverted millions in wire transfers and were also ordered to pay substantial restitution and serve supervised release after prison.
read more →

Star Blizzard adopts RedFlick to streamline malware delivery

🛡️ Since January 2026, Microsoft observed Russian state-affiliated actor Star Blizzard refine large-scale phishing, use compromised-site accounts, and adopt a novel malware delivery technique called RedFlick. RedFlick leverages scheduled tasks to deploy the actor’s Python backdoor CosmicPulse, reducing required user interaction to a single response and improving evasion. Microsoft details observed TTPs, IOCs, mitigations, and detection guidance to help organizations defend against this evolving threat.
read more →

Device Linking Enables Eavesdropping on Messaging Apps

🔐 Modern messaging apps permit linking a phone account to desktop clients like WhatsApp Web and Signal Desktop, and authorities are abusing this to surveil suspects. Germany’s Customs Office reportedly connects a police-controlled computer to a target’s account, receiving messages without breaking encryption. Access is obtained via physical phone access or by intercepting verification codes through phishing or telephone surveillance. The key point is that these methods rely on obtaining user consent or one-time codes, and users need clearer visibility of connected devices.
read more →

Phishing’s new realism: evolving email threats

📧 Modern email phishing now evades traditional telltale signs, using polished language, QR codes, AI-tailored lures and token-theft flows to bypass training and defenses. Attackers exploit live sessions, device hops and legitimate sites to harvest OAuth tokens or trick users into pasting commands, while deepfakes and delayed fraud increase believability. Organizations must pair awareness with verification, layered controls and MDR capabilities to detect and contain these subtler social engineering campaigns.
read more →

Weekly ThreatsDay: AI Search Poisoning and Malware

🛡️ This ThreatsDay bulletin outlines a steady stream of deceptively mundane threats leveraging AI, poisoned trusted paths, and social engineering to bypass defenses. Highlights include an AI-assisted Android banking trojan, AI code privacy concerns from Z.ai, and FBI/CISA guidance on ICS integrator access. Also covered are super-app surveillance findings, browser-in-the-browser phishing, novel EDR evasion, and large-scale AI search poisoning campaigns targeting major brands.
read more →

Placeholder domains weaponized to deliver ClickFix lures

🛡️ Manifold Security discovered that the documentation placeholder domain third-party[.]com has been registered and weaponized to serve a ClickFix social engineering lure for Windows visitors while showing benign decoys to others. The domain, referenced in over 1,700 public GitHub repositories, poisons the clipboard and prompts users to paste and run a command that fetches a remote PowerShell payload. It has been flagged as malicious on VirusTotal and Google Safe Browsing, and the researchers found a further 13 non-reserved placeholder domains being abused to serve scams and scareware to macOS users.
read more →

How Bitcoin ATM scams work and how to avoid them

🚨 Crypto ATMs let users buy or sell cryptocurrency with cash or card, but scammers exploit them to steal funds via urgent impersonation calls. Fraudsters instruct victims to withdraw cash and use a Bitcoin ATM or scan a QR code that directs payments to the criminal's wallet, which is nearly impossible to reverse. If contacted unexpectedly, never follow instructions to use a crypto ATM; verify via official channels and report incidents immediately.
read more →