< ciso
brief />
Tag Banner

All news with #phishing tag

745 articles · page 2 of 38

Talos Threat Source: Q2 IR Trends and Insights

🧭 This edition of the Threat Source newsletter ties a challenging Old Rag hike to cybersecurity resilience and introduces the Talos Q2 2026 Incident Response Trends report. The report highlights spikes in authentication abuse and advanced phishing techniques, including QR-based lures and ARToken platforms, while noting ransomware groups abusing legitimate remote management tools. It recommends phishing-resistant MFA, behavior-based monitoring, centralized logging, and prioritized patching.
read more →

ThreatsDay: AI-Driven Attacks and Widespread Malware

🛡️ This week’s ThreatsDay Bulletin surveys a wide set of active campaigns and vulnerabilities, from phishing that delivers XWorm and LunaSpy to custom ransomware (GenieLocker) and crypto-focused stealers. Reports detail fileless WebDAV execution, supply-chain hardening by GitHub, a My Eicher fleet takeover flaw, and AI-agent-driven autonomous exploitation across multiple CVEs. Enterprise and consumer impacts include large data exposures and targeted SaaS account takeovers.
read more →

AiTM Phishing Now Leading Entry Point for Law Firms

🛡️ eSentire's legal sector report shows Adversary-in-the-Middle (AiTM) phishing is now the primary initial access vector for law firms, responsible for 28.57% of incidents and surpassing conventional credential theft. The firm also noted a 20% YoY rise in attacks against legal organizations, with credential and identity-focused threats comprising 56.3% of all activity. The report highlights specific services and lures—such as the Tycoon2FA platform, ClickFix fake browser-error campaigns, and Microsoft Teams abuse—and urges adoption of phishing-resistant MFA like FIDO2 and conditional access controls.
read more →

Why silent phone calls are a growing threat

📞 Silent phone calls — a brief ring followed by muted silence — are increasingly common and can come from benign sources like misconfigured devices or overloaded call centers as well as robocallers, AI dialers, debt collectors, stalkers, and outright scammers. These calls are often used to verify active numbers, harvest short voice samples, or test lines before follow-up contact. While a single silent ring rarely causes direct harm, repeated interactions can enable voice deepfakes and social-engineering attacks. The article explains motives, risks, and practical steps to reduce exposure.
read more →

LogoKit uses live site screenshots for phishing

🛡️ Barracuda researchers observed LogoKit phishing campaigns that build a unique login page for each victim in real time by pulling a live screenshot of the target organization’s website as the page background. The kit extracts the victim email from the URL, identifies the employer domain, and uses commercial services like Thum.io and Clearbit to assemble a convincing, per-victim page. Credential harvesting is routed via a Telegram bot, and victims are redirected to the genuine site, complicating detection and takedown.
read more →

Phishing Abuses Microsoft Trusted Login Flow

🛡️ Check Point researchers observed a widespread phishing campaign from June 25 through mid-July that impersonated Microsoft Teams notifications and directed recipients to genuine Microsoft sign-in pages. Victims were prompted to grant permissions to attacker-controlled applications, allowing abuse of the OAuth consent flow to access mail, files, Teams, SharePoint, OneDrive, and calendars. The campaign targeted roughly 120 organizations across multiple sectors and geographies before it ended.
read more →

How attackers bypass multifactor authentication risks

🔒 This article examines prevalent methods attackers use to bypass multifactor authentication (MFA), from MFA fatigue and social engineering to cookie theft and targeting weak or non‑MFA accounts. It summarizes survey findings on uneven MFA adoption, highlights real-world incidents (Okta, Uber), and notes industry guidance favoring phishing‑resistant and passwordless approaches. The piece concludes with concrete defensive steps such as adaptive authentication, tightening access rights, and reviewing password reset workflows.
read more →

Phishing Now Leading Initial Access in Incidents

📈 Analysis of incidents from March to June 2026 shows phishing was the initial entry vector in just over half of cases requiring remediation, up markedly from the prior quarter. Cisco Talos researchers highlight increasingly sophisticated campaigns, including QR code-based credential harvesting and use of trusted cloud hosting to evade detection. The report also warns that advanced Phishing-as-a-Service kits and post-compromise toolsets are expanding capabilities and recommends phishing-resistant MFA, logging, patching, and stricter email controls.
read more →

Talos IR Q2 2026 Incident Response Trends

📊 Q2 2026 Talos Incident Response (IR) engagements showed phishing as the primary initial access vector, with attackers increasingly using QR code PDFs and cloud-hosted links to bypass defenses. Authentication abuse spiked to 65% of engagements, with adversaries employing AitM proxies, session-token theft, and MFA fatigue. Ransomware activity remained significant, with Sinobi, Nitrogen, and Warlock observed leveraging trojanized RMM tools like MeshAgent and Zoho Assist. Talos recommends phishing-resistant MFA, strict control of administrative binaries, robust centralized logging, and behavior-based monitoring to detect misuse of legitimate management tools.
read more →

Insurance Phishing Evolves into Real-Time Account Hijacks

🔍 Recent research shows insurance-targeted phishing has shifted from credential harvesting to real-time session hijacking. Attackers use paid Google Ads and disposable hosting to lure victims to realistic portals and then relay OTPs and credentials to authenticate on the legitimate service while the victim is logged in. CTM360 identified a bespoke kit, InsureOTP Kit, and exposed backend infrastructure revealing live session management and operator workflows. Defenders must expand detection beyond malicious pages to include ad monitoring, infrastructure analysis, and attacker workflow intelligence.
read more →

Man sentenced for mass Snapchat account hacks

🔒 An Illinois man received a 76-month prison sentence and three years supervised release after admitting to social engineering attacks that compromised over 750 women's Snapchat accounts to steal and trade nude photos. Between May 2020 and February 2021, he targeted thousands of users while impersonating Snap Inc., accessed at least 517 accounts to download explicit images, and enabled two-factor authentication to lock victims out. Investigators also found hundreds of CSAM files in his cloud storage, and he advertised hacking services online, using Kik to communicate with clients including a former coach who was separately convicted for hiring hacks.
read more →

ChatGPT Enters Top 10 Most Impersonated Brands

🛡️ OpenAI’s ChatGPT has appeared in the top 10 most impersonated brands in phishing attacks for the first time in Q2 2026, according to Check Point. The report highlights a fake “ChatGPT Plus payment failed” email that mimicked an OpenAI billing notice to steal full credit card details. Microsoft remains the most impersonated brand, followed by LinkedIn, with Google, Apple and Amazon also in the top five. Check Point recommends inline phishing prevention, AI-powered detection and consolidated email/workspace protection to mitigate brand phishing.
read more →

Tycoon2FA takedown reshapes phishing landscape

🔎 Microsoft reports that disruption of the Tycoon2FA phishing-as-a-service platform drove a sharp decline in traditional phishing techniques, with platform-linked volume falling 92% from pre-takedown averages. The takedown reduced QR code and CAPTCHA-gated phishing and forced attackers to adapt, shifting to channels like Microsoft Teams and automated BEC campaigns. Microsoft recommends stronger email filtering and phishing-resistant authentication such as passkeys, FIDO keys, and multifactor protections to mitigate evolving threats.
read more →

AgentForger shows AI agents as persistent insider threats

🔒 Zenity Labs disclosed AgentForger, a phishing-based technique that creates autonomous AI agents inside OpenAI Workspaces that can access Outlook, Slack, SharePoint, Google Drive and more. Once installed by a single click, the agent can toggle approvals to act without human prompts, run on schedules, accept attacker task emails, harvest data and impersonate users. OpenAI patched the flaw quickly, but the finding highlights broader risks as agents gain autonomy and integration into enterprise workflows.
read more →

Email Threat Landscape Q2 2026: Key Findings

📊 Microsoft reports that Q2 2026 saw a sharp decline in phishing tied to the Tycoon2FA PhaaS disruption, while threat actors shifted tactics into Teams-based social engineering and vishing. Credential phishing remained the dominant payload objective, and notable campaigns demonstrated large-scale automation and multi-stage delivery chains. The post reviews QR code and CAPTCHA-gated phishing trends, BEC anomalies, and mitigation recommendations.
read more →

Q2 2026 Brand Phishing: Top Impersonated Companies

📊 Microsoft remained the most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts. The top five—Microsoft, LinkedIn, Google, Apple, and Amazon—accounted for over half of observed attacks, while ChatGPT entered the top ten for the first time. Technology, social networks, and banking were the most targeted industries, and common tells included distorted logos, dead buttons, and mismatched links.
read more →

AI Empowers More Convincing Ransomware Attacks

📈 A Proofpoint survey shows AI has materially increased ransomware effectiveness by enabling more convincing phishing, impersonation and credential-theft campaigns. The 2026 AI-Era Ransomware Report found AI involvement common across incidents and identified human interaction—malicious links, attachments and credential harvesting—as frequent entry points. Respondents cited legitimate-looking lures and control failures as key reasons attacks bypassed defences.
read more →

First-person identity theft and email risk

🛡️ Harrowing first-person account of identity theft highlights how a single mistake—sharing a two-factor authentication code—enabled a scammer to seize the victim's email. The piece underscores that many online accounts are effectively secured by email access, making email compromise catastrophic. It emphasizes practical lessons about account recovery, 2FA methods, and attacker behaviors.
read more →

Authorities dismantle major Kratos phishing infrastructure

🛡️ German and US law enforcement dismantled the core infrastructure of the Kratos phishing kit and arrested a developer in Indonesia. Investigators disabled over 200 servers; authorities estimate about 1,800 customers ran roughly 15,000 phishing campaigns per month. Kratos stole credentials and session cookies, enabling adversary-in-the-middle bypasses of MFA and persistent access to Microsoft 365 accounts.
read more →

ConsentFix: OAuth-based Microsoft 365 account hijacking

🛡️Researchers uncovered a new ClickFix variant called ConsentFix that tricks users into granting OAuth tokens, enabling attackers to access Microsoft 365 accounts without stealing passwords. Attackers use deceptive pages and social engineering—often via phishing emails imitating file-sharing services—to induce victims to drag a tokenized URL onto an attacker-controlled page. Once obtained, the OAuth token can expose Outlook, Teams, OneDrive, SharePoint and other services depending on the organization’s license and privileges, enabling data exfiltration, BEC and lateral movement. The technique is widely shared on cybercrime forums with tutorials and turnkey tools, increasing its prevalence and lowering the barrier for novice threat actors.
read more →