2025-09-03 07:49 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
AI in cybercrime is evolving fast, fueling AI phishing attacks, AI scam calls, AI voice cloning scams, and even AI deepfake scams. From Dark LLMs to next-gen AI phishing tactics, we break down how criminals exploit AI today and what you can do to stay protected.
P0
2025-08-26 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Hackers are using Google Gemini's email summaries to sneak in phishing attacks without links or attachments.
P0
2025-08-06 07:32 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how AI voice deepfake vishing exploits trust, drains millions, and learn practical steps to detect and stop voice‑based scams.
P0
2025-06-25 22:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A business email compromise (BEC) attack is a type of scam where bad actors impersonate a trusted source to obtain information from their targeted individual.
P0
2025-06-13 16:03 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Adam Gavish, Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or…
P0
2025-05-08 07:13 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Learn how attackers exploit Pluggable Authentication Modules (PAM) for credential harvesting—and discover defenses to harden Linux authentication.
P0
2025-04-24 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
As with many tactics within the MITRE ATT&CK framework, credential theft consists of a number of different techniques. Showing what many of them look like on an endpoint helps other security professionals understand what to look for and how to detect and respond to similar activity.
P0
2025-04-23 07:05 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover the latest phishing campaign targeting a major toll road service provider, where cybercriminals use sophisticated evasion techniques to bypass security detections. This in-depth blog reveals how threat actors exploit legitimate platforms and deploy cloaking methods to disguise malicious links, allowing them to evade detection by security solutions. Discover how these sophisticated tactics create highly convincing phishing pages designed to steal victims’ card information, and how to sa…
P0
2025-03-28 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how to lock down common endpoint vulnerabilities like weak passwords and unpatched software to secure your systems against threats like phishing and malware.
P0
2025-03-04 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore 2024's top cyber threats, including ransomware trends, advanced phishing tactics, and targeted industries. Stay ahead—download the Huntress 2025 Cyber Threat Report now!
P15
2025-02-11 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress’ 2025 Cyber Threat Report is here! Explore the year's biggest threats—RATs, phishing, ransomware—and how evolving tactics demand smarter defense.
P15
2025-02-06 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
All OAuth 2.0 implementations are equal. Some are just more equal than others. This blog covers device code phishing and compares OAuth implementations between Google and Azure. Does OAuth implementation impact the efficacy of hacker tradecraft? Find out here!
P0
2025-01-02 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Smishing (or SMS phishing) is far more frequent during the holidays. Learn to recognize the signs of a smish and how to avoid falling victim to one.
P0
2024-12-11 07:11 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Explore the advanced tactics employed in recent email phishing campaigns targeting employees from over 30 companies across 12 industries and 15 jurisdictions. This blog unveils sophisticated techniques used to outsmart Secure Email Gateways (SEGs) and exploit trusted platforms, creating highly convincing schemes to deceive victims and steal their credentials.
P0
2024-10-30 05:44 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Explore our latest findings on the surge of cyberattacks in the Balkan region, focusing on threats to financial institutions and critical infrastructure. Discover how phishing scams impersonating postal services are targeting citizens in Croatia, Romania, Serbia, and Slovenia, and learn about the implications for public safety and security. Stay informed and protected against the rising tide of cybercrime.
P0
2024-10-09 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in GitLab Pages allowed attackers to take over dangling custom domains pointing to 'instanceX.gitlab.io'. The issue occured when adding an unverified custom domain to GitLab Pages, which serves content for 7 days before disabling. This could lead to cookie stealing, phishing campaigns, and bypassing of Content-Security Policies and CORS.
P0
2024-10-08 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how to prevent business email compromise attacks and learn how to communicate this emerging cyber threat to your employees.
P0
2024-10-02 05:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
In this article, Group-IB specialists uncovered a large-scale fraud campaign involving fake trading apps targeting Apple iOS and Android users across multiple regions through the UniApp framework, and distributed through official app stores and phishing sites.
P0
2024-09-03 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Join Huntress team members as they walk through some of the most malicious phishing techniques, presented from the attacker's perspective.
P0
2024-08-21 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover how our new Unwanted Access capability strengthens your defenses against session hijacking and credential theft. Dive in and learn how to minimize risks and protect your business-critical assets from evolving cyber threats.
P0
2024-07-25 05:58 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Specializing in AI-powered phishing-as-a-service and Android malware capable of intercepting OTP codes, the GXC Team targets Spanish bank users and 30 institutions worldwide
P0
2024-06-12 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Get to know Phishing Defense Coaching, the latest addition to Huntress SAT. This personalized feature helps teach learners how phishing simulations tricked them so they can better identify potential threats.
P0
2024-04-18 11:09 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB takes part in a global operation to cripple Canadian Phishing-as-a-Service provider LabHost
P0
2023-12-23 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Read about our newest addition to Huntress Managed SAT, Managed Phishing, offering you expert-backed, hassle-free simulated phishing campaigns.
P0
2023-10-18 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore the art of phishing, learn how to spot common phishing scams and red flags, and understand the importance of security awareness training.
P0
2023-10-16 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Read up on how and why Huntress built its Managed ITDR (formerly MDR for Microsoft 365) solution to help combat the growing threat of business email compromise (BEC).
P0
2023-08-17 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Get an inside look at how threat actors use phishing and social engineering tactics to target users and infiltrate organizations.
P0
2023-08-09 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover how Huntress caught an attempted business email compromise (BEC) scam that would have cost the company more than $100,000 had it gone undetected.
P0
2023-07-27 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore how Huntress stopped a massive business email compromise (BEC) attack targeting multiple user accounts within a single organization.
P0
2023-07-13 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, explore how Huntress caught an attempt at financial fraud through business email compromise (BEC) in Microsoft 365.
P0