2026-08-26 16:43 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Yash Gund and Sumith Maniath · indexed 2026-08-26 17:15 UTC
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Securing gateways and control points appeared first on Microsoft Security Blog.
P0
2026-08-26 13:44 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 14:20 UTC
Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that
P0
2026-08-26 11:33 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-08-26 13:20 UTC
The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.
P0
2026-08-26 09:00 UTC
Vendor Research
Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-26 13:15 UTC
A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication.It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a n…
P45
2026-08-26 05:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 07:10 UTC
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across
P0
2026-08-25 21:39 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-25 21:40 UTC
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]
P0
2026-08-25 20:25 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-25 20:35 UTC
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]
P0
2026-08-25 14:29 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB expone una operación mexicana de PhaaS dirigida a más de 20 instituciones financieras, con capacidades de phishing en tiempo real, vishing con IA y RAT para dispositivos móviles.
P0
2026-08-25 13:19 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 13:45 UTC
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023,
P0
2026-08-25 11:56 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based. Mirage2FA Campaign
P0
2026-08-25 11:52 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the
P0
2026-08-24 12:35 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 14:05 UTC
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha)
P15
2026-08-24 07:17 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-24 07:35 UTC
iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is […]
P0
2026-08-21 18:01 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-21 18:05 UTC
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
P0
2026-08-21 11:11 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-21 11:40 UTC
Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead. Threat actors target researchers, […]
P0
2026-08-20 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Kaseya · indexed 2026-08-20 14:20 UTC
AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past the inbox. [...]
P0
2026-08-20 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-20 14:40 UTC
Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an additio…
P0
2026-08-20 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Joey Chen · indexed 2026-08-20 10:15 UTC
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
P0
2026-08-20 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Bill Batchelor · indexed 2026-08-20 10:05 UTC
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.
P0
2026-08-19 16:58 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-08-19 17:15 UTC
A spear-phishing campaign by a China-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by the country's APTs.
P0
2026-08-19 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress researcher uncovers post-Black Hat & DEF CON phishing campaign using X DMs & malicious documents to deliver AMOS, NetSupport RAT, and other malware.
P0
2026-08-19 11:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 13:35 UTC
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person. From Bad Content to Bad Intent to AI on Both Sides Phishing 1.0 was bad
P0
2026-08-19 07:28 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB exposes a Mexican PhaaS operation targeting over 20 financial institutions with live phishing, AI vishing, and mobile RAT capabilities.
P0
2026-08-18 12:49 UTC
Vendor Research
Rapid7 · Rapid7 Labs · indexed 2026-08-18 15:35 UTC
You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive program…
P15
2026-08-18 07:18 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-18 07:50 UTC
Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a […]
P0
2026-08-17 15:44 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-08-17 16:25 UTC
The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.
P0
2026-08-17 12:00 UTC
Government
NIST Cybersecurity Insights · Julie Haney, Jody Jacobs · indexed 2026-08-17 12:40 UTC
When was the last time a cybersecurity process at work made you want to scream? Maybe it was a password requirement so complicated you had to write it down (defeating the purpose), a phishing simulation test that felt more like a trap than a lesson, or a confusing security warning pop-up that interrupted your work. Or maybe you’re on the other side of the equation, working as a cybersecurity professional who is wrangling a half dozen disconnected dashboards, drowning in alerts (all flagged "urg…
P0
2026-08-17 11:29 UTC
Vendor Research
Rapid7 · Anna Širokova · indexed 2026-08-18 15:35 UTC
Operation ASTERIX overviewRapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered …
P0
2026-08-17 09:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.
P0
2026-08-14 14:00 UTC
Security Journalism
BleepingComputer · Sponsored by Material Security · indexed 2026-08-15 14:33 UTC
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. [...]
P0