< ciso
brief />
Tag Banner

All news with #phishing tag

805 articles · page 2 of 41

Aviation’s lesson for security in the AI era

✈️ Aviation recognized the human vigilance limit and built machines that act decisively on clear, observable danger rather than asking fatigued humans to be perfect. AI shifts many knowledge workers into that high-load role, erasing obvious phishing cues and increasing opportunities for adversaries to exploit attention decay. Security must focus controls on high-consequence actions — payments, bank-detail changes, credential resets — using mechanisms that trigger on the act itself. The hard part remains earning trust in machines that must judge intent in adversarial contexts without generating prohibitive false alarms.
read more →

Placeholder domain abused to deliver ClickFix attacks

🛡️ The commonly used placeholder domain third-party.com is serving a fake Cloudflare verification page that attempts to trick Windows users into running PowerShell commands. The site copies a malicious command to the clipboard and instructs victims to paste and execute it, a technique known as ClickFix. Researchers found the domain referenced across public developer docs and confirmed the malicious behavior; the current payload host was not resolving during testing.
read more →

Chinese Hackers Exploit Chrome–Windows Zero‑Day Chain

🛡️ Volexity researchers observed UTA0565 exploiting a newly disclosed Google Chrome–Windows exploit chain on September 3–4, 2026, via fake websites. The actor chained two Chrome flaws (CVE-2026-85046, CVE-2026-87491) with a Windows ALPC vulnerability (CVE-2026-85880) to escape the browser sandbox and achieve remote code execution. Phishing lures impersonated media and NGOs, delivering a BlueMoon-based loader that fetched a CLEANGULP executable named "chrome_cleanup.exe". CLEANGULP provides remote shell, process listing, file upload/download, and BOF execution, and uses a spoofed C2 domain mimicking a legitimate outlet.
read more →

Microsoft disruption exposes AI-driven phishing-as-a-service

🔎 Microsoft says it disrupted EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 Microsoft 365 inboxes across more than 10,000 organizations. Launched in February 2026, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation behind a subscription dashboard and chatbot. The operation abused Microsoft’s OAuth 2.0 device-code flow to steal session tokens and used an AI analyst to scan mailboxes and craft business email compromise scams. Microsoft seized infrastructure via a US court order and partners arrested two suspects in the UK amid coordinated takedown efforts.
read more →

Fake AI subscription sites pose enterprise data risks

🛡️ Malwarebytes found polished websites impersonating reputable AI tools and selling subscriptions, using genuine Google authentication to appear legitimate. These sites request uploads of documents or recordings and charge from $10/month to $2,000/year while concealing real operator details. Researchers suspect a single kit and operator power multiple clones, and warn of shadow IT risk when departments buy without IT involvement.
read more →

Free Robux: What’s Real and What’s a Scam

🛡️ If your family uses Roblox, many offers for “free Robux” are scams aimed at stealing credentials or personal data. Roblox and trusted partners may run legitimate promotions or creators can earn Robux through monetization, but there is no true Robux generator. Be wary of phishing pages, fake giveaways, surveys, and requests for passwords or 2FA.
read more →

Revolut customers targeted in post-breach smishing wave

📱Malwarebytes reports that Revolut customers have been targeted by smishing campaigns following a data breach acknowledged by the firm. Messages mimicked legitimate Revolut texts and urged recipients to follow links to confirm identity, with some pages requesting camera access to perform fake liveness checks. The campaign may leverage breached data and has reportedly targeted several hundred accounts, particularly high-net-worth crypto users.
read more →

GhostCode device-code phishing targets Microsoft 365

🔒 Researchers at eSentire discovered GhostCode, a phishing kit that abuses Microsoft’s OAuth 2.0 device authorization flow to trick users into granting attacker-controlled devices access to Microsoft 365 accounts. Victims are lured via procurement-themed social engineering to enter device codes on legitimate Microsoft sign-in pages, completing MFA for the attacker’s session. Stolen tokens enabled automated device registration, Intune enrollment and acquisition of Primary Refresh Tokens (PRTs), persisting access even after token revocation. eSentire recommends restricting device-code flow via Conditional Access, monitoring device registrations and Python-based user agents, and auditing Entra ID for suspicious device patterns.
read more →

RatHat Android malware uses AI for adaptive control

🛡️ Zimperium zLabs discovered RatHat, an Android malware that leverages an AI-powered subsystem to remotely navigate compromised devices. Distributed via malvertising, SMS, and phishing sites hosting APKs, RatHat abuses Accessibility permissions to enable Developer Options and Wireless Debugging. It installs a Go-based agent for ADB-level commands, persistence, and self-restoration, and a second agent for persistent FRP reverse-proxy tunnels. The malware overlays HTML on banking and crypto apps, intercepts SMS and notifications, captures credentials and unlock patterns, and uses anti-analysis techniques to evade detection.
read more →

Scammers Exploit Airline Complaints to Impersonate Support

🛫 Check Point uncovered a coordinated social engineering campaign in which threat actors monitor public airline complaints on social media, impersonate customer support accounts, and move victims to private channels like WhatsApp to collect personal and payment information. Thousands of fake accounts were identified across X, Facebook, and Instagram, with hundreds more appearing daily. Researchers documented three scam variations promising refunds or compensation and observed growing use of tactics that could be scaled with generative AI. Organizations are advised to monitor brand impersonation, educate customers, and move sensitive interactions to secure channels.
read more →

Five Black Axe Members Extradited to US Courts

📰 Five alleged leaders of the Black Axe cybercrime syndicate were extradited from South Africa to the United States to face wire fraud, money laundering, and aggravated identity theft charges. Prosecutors allege the defendants ran romance and advance-fee scams targeting U.S. victims from Cape Town between 2011 and 2021, using aliases, social media, dating sites, and VoIP services to defraud and coerce victims. Arrested in 2021 at U.S. request, they face significant prison terms if convicted.
read more →

Threat Actors Use Passkey Phishing to Breach Cloud

🛡️ Microsoft disclosed two related campaigns: one sent over a million CEO-impersonation invoice scams in August 2026 to induce ACH transfers, and the other used passkey-themed social engineering since May 2026 to compromise cloud accounts. The fraud campaign leveraged generative AI, forged threads, and bogus domains to target enterprise finance teams. Cloud intrusions employed voice/SMS pretexts, counterfeit sign-in pages, AitM and device-code flows, and persistent MFA enrollment to enable extensive Microsoft Graph, SharePoint, OneDrive, and mailbox access.
read more →

Phishing Abuse of Microsoft 365 Direct Send Peaks in US Hours

📧 KnowBe4 researchers observed a large-scale phishing campaign abusing Microsoft 365’s Direct Send feature, with 29,785 confirmed malicious emails sent during July and August 2026. The campaign followed US Eastern business hours, peaking Monday–Tuesday just before noon and again around 2pm EST. Attackers used Direct Send to spoof trusted internal senders and bypass some gateway protections, often including malicious attachments and reply-to addresses directing responses to attackers. The report recommends monitoring the Exchange header "X-MS-Exchange-Organization-AuthAs: Anonymous," enforcing DMARC p=reject, restricting Exchange Online connectors to approved IPs, closing unneeded Direct Send pathways, and enabling DKIM signing.
read more →

Passkey-Themed Scams Hijacking Microsoft 365 Accounts

🔒 Microsoft Security Research has tracked a campaign since May where attackers pose as IT helpdesk staff to trick employees into updating or enrolling a passkey. Victims are redirected to AiTM phishing pages or legitimate Microsoft device-code flows, enabling attackers to capture credentials and session tokens or authorize attacker-controlled clients. Compromised identities allowed adversaries to register their own authentication methods, use Microsoft Graph to map tenants, and exfiltrate files and email from SharePoint, OneDrive, and Exchange.
read more →

Trezor customers targeted after Brevo email breach

📧 Trezor disclosed that phishing emails sent via a breached third-party provider targeted 347,000 opted-in newsletter addresses and prompted 2,500 recipients to click a malicious link. The messages falsely claimed a microcontroller vulnerability in STM32 chips and urged users to download an app to enter wallet backups. Trezor disabled the malicious domain within 20 minutes and suspended the Brevo account to halt further distribution. The company emphasized no other Trezor systems were accessed.
read more →

Detect and Disrupt AI-Themed Attacks with Defender

🛡️ Microsoft Threat Intelligence outlines how attackers are leveraging AI brands like ChatGPT and Copilot to craft convincing phishing, malvertising, and malware campaigns that exploit urgency and trust. Microsoft Defender provides layered defenses—anti-phishing, Safe Links, Safe Attachments, and post-delivery filtering—and correlates signals across email, identities, endpoints, and SaaS to detect and disrupt multi-stage attacks. Attack disruption has contained tens of thousands of compromises monthly, illustrating the value of connected prevention, detection, and response.
read more →

August 2026 Cyber Threat Landscape Overview

🔍 August 2026 saw rising cyber threats across multiple vectors, with weekly attacks per organization averaging 2,422 and ransomware incidents nearly doubling year over year. GenAI usage surged to 106 prompts per user, yet high-risk prompts persisted affecting 86% of GenAI-using organizations. Email phishing and regionally varied attack volumes further illustrate a broadening and intensifying risk environment that demands expanded governance and prevention.
read more →

Passkey-Themed Social Engineering Drives Cloud Identity Compromise

🔒 Microsoft Security Research describes coordinated intrusions beginning with passkey-themed social engineering and progressing to authentication persistence, cloud reconnaissance, and targeted data collection. The actors use phone and trusted internal messages to lure victims to convincing phishing sites or device-code flows, then add authentication methods and leverage Microsoft Graph, SharePoint, OneDrive, and Exchange to enumerate and collect data. Defenders are urged to investigate identity and Microsoft Graph signals, revoke sessions, and remove unauthorized auth methods.
read more →

Trezor supply-chain breach expands affected customers

📣 Trezor has revealed that a supply-chain breach at shipping partner ShipMonk exposed additional customer order data, expanding the impacted cohort by 67,000 users. The company updated its notification after discovering records from November 2019 to August 2021 were included, revising earlier timelines and increasing the victim count significantly. Trezor warned of heightened phishing and fraud risks and said it is considering legal action while pushing for anonymized delivery options.
read more →

BengalSEO campaign poisons Bing to deliver malware

🔍 Cybersecurity researchers disclosed a long-running SEO poisoning campaign, codenamed BengalSEO, which has been active since at least 2015 and operates out of Rajasthan, India. The group uses black hat SEO techniques, malicious lure pages, and a sophisticated traffic distribution system to deliver a custom malware called MayaBot or to funnel victims into tech-support scams. The campaign leverages legitimate hosting and analytics services to fingerprint visitors and evade detection before delivering payloads or social-engineering victims into calling scam call centers.
read more →