2026-09-08 13:48 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 15:20 UTC
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI
P0
2026-09-08 12:03 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-08 12:10 UTC
Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. [...]
P0
2026-09-08 12:00 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-09-09 12:10 UTC
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.
P0
2026-09-07 19:40 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-07 19:55 UTC
Condé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud and scams. A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a 5,000-record sample and concluded that it is consistent with genuine Condé […]
P0
2026-09-07 15:39 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-07 15:40 UTC
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]
P0
2026-09-07 11:36 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 13:00 UTC
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake
P0
2026-09-07 07:53 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 08:35 UTC
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a
P0
2026-09-06 14:23 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-06 14:40 UTC
Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters. [...]
P0
2026-09-05 07:31 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 07:45 UTC
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as
P30
2026-09-04 15:57 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 16:10 UTC
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The
P0
2026-09-04 12:00 UTC
Vendor Research
Rapid7 · Rapid7 Intelligence · indexed 2026-09-04 12:25 UTC
OverviewA new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engag…
P15
2026-09-03 18:02 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 19:15 UTC
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also
P0
2026-09-03 16:00 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Noam Kochavi and Sarah Wolstencroft · indexed 2026-09-03 16:45 UTC
Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog.
P0
2026-09-03 11:58 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 12:45 UTC
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses
P0
2026-09-03 07:02 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog provides a deep-dive into the phishing kit created by Chenlun known as the Outsider Phishing Kit. It is a well established kit in the Chinese community with over 267 ready-made phishing templates targeting over 54 countries worldwide.
P0
2026-09-02 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-08 13:30 UTC
An inside look at Knight Office, a newly discovered AiTM phishing kit featuring custom control panels, Cloudflare Turnstile, and M365 Token theft.
P0
2026-09-02 09:06 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-02 09:15 UTC
A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. [...]
P0
2026-09-01 20:53 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-01 20:55 UTC
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]
P0
2026-09-01 20:13 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-01 20:50 UTC
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
P0
2026-09-01 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-01 03:50 UTC
Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In thi…
P0
2026-08-31 21:00 UTC
Security Journalism
Huntress · indexed 2026-09-08 13:30 UTC
Bad actors are abusing Faronics Deploy in phishing campaigns to run PowerShell, deploy ScreenConnect, and evade detection by using trusted tools.
P0
2026-08-31 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Noam Sala · indexed 2026-08-31 10:15 UTC
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.
P0
2026-08-28 16:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users with Huntress SAT.
P0
2026-08-28 16:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Get ready for a phishing trip! Learn about the strategy behind phishing simulations and how it can help your organization build resilience against real phishing threats.
P0
2026-08-28 16:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn the essentials of phishing simulation training with our beginner's guide. Protect your organization by simulating real phishing attacks.
P0
2026-08-27 14:09 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-27 14:25 UTC
Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious code in open-source software and used it to steal data from thousands of organisations. “Two West […]
P0
2026-08-27 13:51 UTC
Vendor Research
Rapid7 · Alexandra Blia · indexed 2026-08-27 14:25 UTC
IntroductionDespite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social Security numbers (SSNs) represent a far more permanent and dangerous tier within th…
P0
2026-08-27 11:16 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-08-27 11:55 UTC
EU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp.
P0
2026-08-27 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · James Hodgkinson · indexed 2026-08-27 10:25 UTC
Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.
P0
2026-08-27 09:57 UTC
Community
SANS Internet Storm Center · indexed 2026-08-27 10:10 UTC
As I've mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center.
P0