2026-05-29 14:19 UTC
Vendor Research
Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC
Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered a 1-click open redirection technique in Amazon Cognito that can be triggered by abusing the OAuth error-handling mechanism. The vulnerability stems from AWS's OAuth implementation validation sequence: if validation fails due to an unsupported scope, mismatched PKCE parameters, or an unsupported response type, the error handling processes the failure and automatically issues…
P0
2026-05-29 13:56 UTC
Vendor Research
Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC
Microsoft Entra ID 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered new techniques to trigger 1-click open redirection attacks in Microsoft Entra ID by abusing the OAuth error-handling mechanism. The attack relies on an initial setup phase where a threat actor registers an OAuth application in an actor-controlled tenant and configures its redirect_uri to point to an attacker-controlled domain. When a victim clicks on a specifically craf…
P0
2026-05-27 06:57 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
With the 2026 FIFA World Cup just weeks away, Group-IB researchers have uncovered six distinct fraud schemes, four independent threat actors, and over 4,300 fraudulent domains impersonating FIFA's official web presence — including a sophisticated phishing operation run by the Chinese-speaking threat actor GHOST STADIUM, whose campaign could cause losses reaching billions of dollars.
P0
2026-05-25 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that region. These services not only lower the barrier to entry for Chinese cyber criminals, but reveal …
P0
2026-05-15 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gain…
P0
2026-05-15 11:28 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Digital brand protection helps organizations detect and disrupt external threats, such as phishing sites, fake social profiles, counterfeit listings, and leaked credentials, before they become customer-facing fraud or reputational damage.
P0
2026-05-13 12:52 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This highly targeted scam scheme uses advanced phishing and social engineering cues, rely on brand recognition, event-based campaigns and emotional manipulation to defraud victims twice.
P0
2026-05-11 17:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Device code phishing doesn't need stolen passwords or malware—just a legitimate auth flow. Learn how EvilTokens weaponized AI to run this attack across 344 organizations.
P0
2026-05-01 17:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Social engineering has evolved. Device code phishing and AI lures bypass MFA and blend in. Build a cyber resilience strategy before the next attack lands.
P0
2026-04-29 06:54 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
While analyzing global smishing operations spanning APAC, LATAM, Europe, and MEA, Group-IB researchers uncovered the 'Phoenix System' administrative panel, a centralized Phishing-as-a-Service (PhaaS) platform with real-time victim monitoring, geofencing, and live-phishing interventions to bypass multi-factor authentication.
P0
2026-04-23 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC
Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim…
P0
2026-04-22 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Attackers are building workflows around AI—fake tools, spoofed answers, and machine-speed phishing. See how Huntress is tracking this shift and what it means for defenders.
P0
2026-04-16 06:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
The takedown of a global phishing-as-a-service ecosystem
P0
2026-04-01 10:32 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB researchers uncover an ongoing phishing campaign targeting major banks in the Philippines. This blog details how threat actors abuse trusted and legitimate platforms to deceive users and evade detection. It highlights a significant threat escalation with the successful hijacking of a legitimate domain to host malicious infrastructure, enabling threat actors to operate with even greater credibility and reduced detection.
P0
2026-03-31 06:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB shows how Business Email Protection blocked Phantom Stealer phishing emails across different campaign waves.
P0
2026-03-25 12:13 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Cómo GTFire abusa de Google Firebase y Google Translate para escalar campañas globales de phishing
P0
2026-03-23 21:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Railway PaaS is being weaponized as a clean token replay engine in an active AiTM and device code phishing campaign impacting 268+ M365 organizations and 100+ MSPs.
P0
2026-03-18 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress’ AI-Centric SOC recently stopped a MacSync infostealer attack on a macOS device. The malware attempted to scrape credentials, browser cookies, and crypto wallets, but Huntress contained the threat before any data was sent to the attacker. Learn how we did it.
P0
2026-03-16 21:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
From fake UPS shipping notifications to PayPal-themed callback phishing, here are the five top phishing techniques we’re seeing this year.
P0
2026-02-26 07:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
How GTFire abuses Google Firebase and Google Translate to scale global phishing campaigns
P0
2026-01-21 06:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
A deep dive into loan phishing scams in Peru and Latin America. Discover how scammers lure victims with fake loan offers, harvest sensitive banking credentials, and leverage advanced scripts to maximize fraud at scale.
P0
2026-01-20 06:12 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
P0
2025-12-23 08:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
From "React2Shell" exploitation to sophisticated "Living off Trusted Sites" phishing, Huntress experts break down the threats targeting both enterprises and families today.
P0
2025-12-04 10:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Identity is effectively the new network boundary. It must be protected at all costs.
P0
2025-11-26 08:22 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Since late June 2025, Group-IB analysts observed a surge in spear-phishing emails across Central Asia. The attackers impersonate government agencies to gain the trust of their victims. This blog describes the techniques, tools and ongoing activity of the threat group known as Bloody Wolf.
P0
2025-11-13 07:09 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB researchers uncovered a professional phishing framework that mimics trusted brands with remarkable precision. Using layered evasion, CAPTCHA filtering, and Telegram-based data exfiltration, attackers harvest credentials and bypass automated detection. The findings highlight how phishing-as-a-service operations are scaling through automation, lowering technical barriers for cybercriminals, and industrializing one of the oldest yet most effective forms of digital fraud.
P0
2025-11-13 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors are targeting the education sector with data breaches, phishing emails, ransomware hits, brute force RDP attacks, and more.
P15
2025-10-31 07:30 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how Group-IB’s Business Email Protection (BEP) could prevent an NPM supply chain compromise by detecting the initial phishing email that led to the developer’s infection.
P0
2025-10-22 07:01 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB Threat Intelligence has uncovered a sophisticated phishing campaign, attributed with high confidence to the Advanced Persistent Threat (APT) MuddyWater. The attack used a compromised mailbox to distribute Phoenix backdoor malware to international organizations and across the whole Middle East and North Africa region, targeting more than 100 government entities.
P0
2025-09-29 05:58 UTC
Other
Red Hunt Labs · Hariharan M · indexed 2026-09-07 17:30 UTC
In the rapidly evolving digital marketplace, e-commerce brands have become prime targets for cybercriminals. Beyond traditional data breaches, these brands now face sophisticated scams that exploit their reputation, deceive consumers, and erode trust. Drawing from investigations conducted by RedHunt Labs’ threat intelligence team, this blog delves into some of the most prevalent scams targeting e-commerce platforms and highlights how a Digital Risk Protection (DRP) solution can help fortify you…
P0