< ciso
brief />
Tag Banner

All news with #phishing tag

745 articles

Attackers Use FTP Banners to Deliver New Windows RATs

πŸ” Threat actors are embedding commands in FTP server banners to deliver two new remote access trojans, E4del and PINHOLE, observed in attacks since July 2026. The campaign begins with a ZIP archive and LNK-based infection chain, likely introduced via phishing, and uses FTP banners as dead-drop resolvers to retrieve PowerShell stagers. SOCRadar discovered the technique and highlights indicators of compromise to help defenders identify affected systems. E4del is a Node.js RAT masquerading as Discord, while PINHOLE uses Pinterest and SurveyMonkey for C2 resilience.
read more β†’

Communication Channels and Identity Risks in SaaS Era

πŸ›‘οΈ Enterprise collaboration platforms are now central to business workflows and have become part of the identity attack surface. Threat actors increasingly misuse trusted collaboration tools for identity phishing, impersonation, credential theft and malware delivery, often leveraging compromised accounts, external federation or guest access. Unit 42 observations show a significant rise in malicious activity tied to collaboration tools, and defenders may lack visibility into actions that occur after authentication. The report reviews techniques attackers use and offers detection and mitigation guidance, noting enhanced protection through Palo Alto Networks products.
read more β†’

Back-to-School Cyber Risks Hit Education Hard

πŸ“š Check Point Research reports that the education sector was the most targeted industry between January and July 2026, averaging 4,696 weekly attacks per organizationβ€”more than double the global cross-industry average. Attack volumes rose further in July, while APAC saw the highest regional pressure and Europe and Latin America recorded the fastest growth. Researchers also observed surges in newly registered education-themed domains and coordinated phishing campaigns targeting students and staff, often leveraging counterfeit sites and compromised legitimate pages.
read more β†’

QR code phishing risks and corporate defenses

πŸ›‘οΈ QR codes have become ubiquitous in daily life and are increasingly used in email-based attacks known as "quishing." These attacks encode malicious URLs in QR images to bypass traditional email filters and move victims from managed corporate devices to less-protected personal phones. Threat actors exploit brand impersonation and urgency to harvest credentials, bypass app stores, push fraudulent payments, or capture MFA tokens. Organizations should combine user training, email and mobile security, phishing-resistant MFA, MDM, and incident response planning to reduce risk.
read more β†’

SafePal data breach exposes nearly 40,000 orders

πŸ”’ SafePal reports a data breach affecting about 39,798 customers after an authorization flaw in an order-tracking plug-in was exploited to steal order information. The exposed data includes names, emails, shipping addresses, phone numbers, and purchase details for orders placed between March 2, 2025, and April 11, 2026. SafePal says sensitive wallet credentials, payment card numbers, and government IDs were not exposed and that it has fixed the vulnerability, notified affected customers, and launched a verification tool. A threat actor is now claiming to sell the stolen data on a cybercrime forum, and the company warns of targeted phishing and social engineering attempts.
read more β†’

Ukraine shuts down 94 fraudulent call centers

πŸ“’ Ukrainian authorities dismantled 94 fraudulent call centers in a coordinated raid involving the National Police, Security Service, the Prosecutor General’s Office, and German police. Law enforcement conducted 411 searches, seizing workstations, phones, SIM cards, cash, vehicles, and other equipment used to run investment and banking scams. Investigators found operations targeting both domestic residents and foreign victims via fake brokerage platforms and impersonation of bank staff, and 26 suspects have been identified.
read more β†’

Talos Threat Source: Phishing Frameworks and Trends

πŸ“° Cisco Talos highlights a newly discovered real-time phishing framework named JWR, likely related to The Outsider phishing-as-a-service. JWR uses WebSockets to capture live keystrokes and steer victims through fraudulent checkout and login flows, often delivered via SMS lures impersonating toll or postal authorities. Operators can harvest payment data, 2FA codes, identity documents, and device fingerprints, enabling MFA bypass and extensive follow-on fraud. Talos recommends user education on smishing, monitoring for unusual authentications, and adopting phishing-resistant MFA like FIDO2.
read more β†’

WhatsApp launches on-device scam alert beta

πŸ”” WhatsApp has started a limited beta for an optional Scam Alert that runs an on-device machine learning model to warn users of likely scam messages. The feature analyzes linguistic signals and conversational structure for messages from non-contacts, displaying a chat warning that suggests blocking, reporting, or continuing. No message content or the model leaves the device; users can mark chats as trusted or opt to share recent messages to improve accuracy. Scam Alert complements existing security updates aimed at preventing account takeover and spyware attacks.
read more β†’

Data Breach Impacts Ceva Logistics Supply Chain

πŸ›‘οΈ Ceva Logistics, part of CMA CGM Group, reported a breach affecting its European contract logistics operations, impacting eight warehouses. The company notified affected customers on August 1 after an incident that reportedly ran from July 29 to August 1. Client data potentially exposed included names, emails, addresses, phone numbers and order details, affecting customers such as Valve, Bol, De Bijenkorf, Ajax and ING. Vendors warn of follow-on phishing and impersonation risks and stress logistics firms are high-value attack targets.
read more β†’

Real emails and clipper attacks hijacked payments

πŸ›‘οΈ Gen Threat Labs examined two H1 2026 campaigns where attackers used legitimately compromised accounts and local system manipulation to intercept payments. The first campaign abused corporate mailboxes to deliver JavaScript droppers that progressed through PowerShell and shellcode to modify proxy and browser settings for banking fraud. The second used a Rust-based clipboard clipper that replaced copied crypto addresses and read C2 pointers from Binance Smart Chain smart-contract data.
read more β†’

Microsoft 365 AitM Phishing Targets Payroll Workflows

πŸ” Arctic Wolf Labs warns of a widespread email-driven phishing campaign using adversary-in-the-middle (AitM) techniques to seize Microsoft 365 sessions and harvest payroll and HR email. The campaign leverages residential proxies, multi-step redirections through trusted services, and fingerprinting scripts to evade filters and maintain compromised sessions at roughly eight-hour intervals. Affected sectors include healthcare, education, manufacturing, government, and professional services across the U.S., Canada, and Europe.
read more β†’

Common dangerous file extensions used in email attacks

πŸ›‘οΈ Cybercriminals frequently disguise malicious files as benign documents or archives to trick recipients into executing malware. Kaspersky researchers analyzed malicious email blasts from early 2026 to identify the 15 most abused extensions β€” from .exe, .dll and .scr to script, web, archive, and Office formats. The report explains how double extensions, hidden extensions, macros, embedded scripts, and password-protected archives are used to evade detection and deliver payloads. It emphasizes keeping software patched, disabling unnecessary macros and scripts, and using advanced security solutions to detect disguised threats.
read more β†’

ThreatsDay bulletin: weekly cyber risk roundup

πŸ“Œ This ThreatsDay bulletin summarizes a week of active cyber risks, including supply-chain npm packages, ClickOnce phishing chains, AI-driven attacks and new macOS and Samsung device exploits. It highlights research on coding-agent trust, AI-powered proxyjacking, and large-scale malicious npm campaigns, and notes policy and platform responses from Apple, Signal, and Microsoft. The report emphasizes common causes: exposed services, trusted defaults, recycled bugs, and poisoned agent instructions.
read more β†’

Phishing campaign installs ScreenConnect via fake audit

πŸ›‘οΈ Proofpoint has identified a phishing campaign impersonating COLDCARD that lures victims with a bogus "Hardware audit" notice tied to a recent wallet vulnerability and large Bitcoin theft. The scam directs targets to a clone site that downloads a batch file which escalates privileges, decodes embedded files, and installs a signed decoy plus a ConnectWise ScreenConnect remote access tool. Once connected to the actor-controlled ScreenConnect server, attackers can remotely access systems, steal data or cryptocurrency, and deploy additional malware or ransomware.
read more β†’

Kali365 Device-Code Phishing Threat to M365

πŸ”’ Kali365 is a device-code phishing kit that abuses Microsoft's legitimate device login to gain persistent access to Microsoft 365 resources. The campaign primarily targets US organizations using SharePoint- and OneDrive-themed lures that redirect victims to Microsoft's real authentication portal where they enter attacker-supplied codes. Once access and refresh tokens are issued, attackers can maintain access to email, documents, and cloud assets, increasing risks of fraud, data exposure, and operational disruption. ANY.RUN telemetry links dozens of weekly sessions to this campaign and emphasizes rapid detection and contextual intelligence to contain token abuse.
read more β†’

Phishing service spoofs RingCentral to steal Microsoft 365

πŸ“§ The Greatness phishing-as-a-service platform has expanded to adversary-in-the-middle and device-code phishing targeting Microsoft 365 users across several countries. Operators abused RingCentral to bypass filters by leveraging whitelisting and fraudulent verification banners to lower suspicion. Victims were routed to AiTM or device-code flows that captured MFA-approved tokens, enabling long-lived access to mailboxes, Teams, SharePoint, OneDrive, and more.
read more β†’

Fake Xeno script launcher infects Roblox players

πŸ›‘οΈ Bitdefender identified malicious installers posing as the Xeno Executor Roblox utility that deliver a multi-stage Java-based loader and a final RAT/infostealer. The campaign, active since early this year and spiking in March, lures gamers via forums, Discord, and compromised accounts with archives mimicking legitimate Xeno installations. Once executed, the malware extracts a Java runtime, registers victims with a C2, and deploys payloads that steal browsers, wallets, and account tokens while enabling surveillance and remote control.
read more β†’

PNLD breach exposes UK police and partner emails

πŸ”’ The Police National Legal Database (PNLD) confirmed that names, organisations and work email addresses for police officers, staff, criminal justice professionals, government partners and customers were compromised and published on the dark web. The incident, identified July 26, also included some Ask the Police submitter contact details, raising phishing risks. PNLD says no passwords or credentials are known to be exposed and is working with the ICO, NCA and cybersecurity specialists while notifying affected parties.
read more β†’

HollowFrame loader deploys Matryoshka backdoor

πŸ›‘οΈ Cybersecurity researchers disclosed a novel Go-based loader called HollowFrame and a Rust backdoor family named Matryoshka, revealed after a phishing intrusion against a law firm. The attack begins with an encrypted archive containing a malicious LNK that triggers a staged chain, uses DLL side-loading with a rogue python311.dll, weakens Defender, and establishes persistence via scheduled tasks. Matryoshka variants communicate over HTTP or via a GitHub-based C2 to receive commands, exfiltrate data, and deliver secondary payloads.
read more β†’

Why device code phishing became an industrial threat

πŸ”’ Device code phishing β€” the abuse of the OAuth 2.0 device authorization grant β€” has rapidly evolved from a niche red-team tactic into a widespread criminalized attack. Exploiting the authorization step after authentication, it defeats all forms of MFA and has been commercialized in phishing-as-a-service kits. Push Security researchers outline the attack mechanics, ecosystem growth, cross-platform risk, and detection challenges for defenders.
read more β†’