Latest updates for Calphishing

Fresh curated links around CalPhishing are collected here so marketers can spot useful updates and turn timely ideas into posts faster.

Recent items include:

  • 2 PhaaS 2 Furious: The Evolution of Chinese-language Phishing Services
  • CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions
  • From Tax Refund to Total Compromise: IRS-Themed Phishing Email Drives Full-Stack Financial Fraud

Post angles to try

Share the most useful takeaway for your audience.
Turn one article into a quick practical checklist.
Ask your audience how this shift affects their work.
Turn angles into scheduled posts

Fresh articles and ideas

Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.

cloud.google.com /5 days ago

2 PhaaS 2 Furious: The Evolution of Chinese-language Phishing Services

While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language under...

Read source
hackread.com /2 weeks ago

CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions

Hackers are exploiting Outlook calendar invites and device code phishing to steal M365 session tokens, bypass MFA and breach enterprise accounts.

Read source
cofense.com /1 month ago

From Tax Refund to Total Compromise: IRS-Themed Phishing Email Drives Full-Stack Financial Fraud

This blog describes a phishing campaign that impersonates the IRS and Elon Musk to lure victims with a fake $5000 tax refund, ultimately redirecting them to credential harvesting w...

Read source
natlawreview.com /1 month ago

Privacy Tip #488 – Account Change Phishing Alerts from “Apple” Are Tricking Users

A new, yet old, scheme has been quite successful and users should beware. If you get an account change message from Apple, be on high alert that it is fake and malicious. According...

Read source
infosecurity-magazine.com /1 month ago

FBI Dismantles $20m Phishing Operation W3LL

The W3LL phishing kit has been associated with fraud attempts totaling $20m

Read source
savingadvice.com /4 days ago

California Seniors Warned About New ‘Verification’ Scam Targeting Social Security Accounts

Older Californians are once again being targeted by scammers, but this latest trick is especially convincing because it plays directly into fears about identity theft...

Read source
crypto.news /1 month ago

Ripple’s CTO  flags phishing emails targeting Robinhood users

Ripple’s former CTO David Schwartz has warned that a targeted phishing campaign has begun exploiting Robinhood users through seemingly legitimate emails ahead of the firm’s earning...

Read source
theregister.com /1 week ago

FBI warns Kali365 phishing kit is stealing Microsoft OAuth tokens at scale

MFA? No problem, says crimeware that tricks users into handing attackers the keys to M365

Read source
jdsupra.com /4 weeks ago

Phishing Now Top Method for Initial Unauthorized Network Access

According to Cisco Talus researchers, phishing is the primary method threat actors use to gain unauthorized access to networks, accounting for more than one-third of all incidents...

Read source
gbhackers.com /1 month ago

Trusted Platforms Exploited to Steal Philippine Banking Credentials

Hackers are increasingly exploiting trusted online platforms to launch sophisticated phishing campaigns targeting bank users in the Philippines. Despite ongoing improvements in ema...

Read source
thehackernews.com /1 month ago

Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud

Cybersecurity researchers have disclosed details of a telecommunications fraud campaign that uses fake CAPTCHA verification tricks to dupe unsuspecting users into sending internati...

Read source
gbhackers.com /1 month ago

Chinese-Backed Smishing Rings Scale Credential Theft via SMS and OTT Apps

Chinese-language phishing-as-a-service (PhaaS) platforms are rapidly expanding their global reach by leveraging SMS and over-the-top (OTT) messaging channels such as iMessage and R...

Read source
macworld.com /1 month ago

New iPhone phishing scam involves email sent from Apple servers

Macworld A new report from BleepingComputer details a phishing scam targeting Apple users. The suspicious emails are actually sent from Apple servers, making them seem convin...

Read source
hackread.com /1 week ago

FBI Warns of Kali365 Phishing Service Targeting Microsoft 365 Account

FBI warns of Kali365, a PaaS scam kit that lets cybercriminals bypass MFA and hijack Microsoft 365 accounts without passwords.

Read source
conservativedailynews.com /1 month ago

Califraudia

by Tom Stiglich at CDN - Click to read the rest HERE-> Califraudia first posted at Conservative Daily News

Read source
blog.knowbe4.com /4 weeks ago

Alert: Payroll-Hijacking Attacks Are Targeting Canadian Employees

Microsoft warns that a new criminal threat actor dubbed “Storm-2755” is launching payroll-pirate attacks against Canadian users. These attacks use social engineering to compromise...

Read source
cnet.com /1 month ago

The Feds Took Down a 'Full-Service Cybercrime Platform' Behind $20M in Phishing

The W3LL phishing kit helped criminals steal tens of thousands of account credentials, primarily targeting Microsoft 365 accounts.

Read source
tovima.gr /1 month ago

Phishing: Τα «έξυπνα» μηνύματα που αδειάζουν λογαριασμούς – Τι πρέπει να προσέξετε

Oι επιθέσεις phishing έχουν γίνει πιο στοχευμένες και πιο «καλοδουλεμένες»

Read source
infosecurity-magazine.com /5 days ago

FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens

The Kali365 phishing-as-a-service platform lowers the barrier of entry for cybercriminals, said the FBI

Read source
cofense.com /3 weeks ago

Steal Smarter, Not Harder: Malicious use of Vercel for Credential Phishing

Threat actors are increasingly using Generative AI tools like Vercel to rapidly create highly convincing phishing websites that mimic legitimate brands, significantly lowering the...

Read source
gbhackers.com /3 weeks ago

Phishing Attack Weaponizes Calendar Invites to Steal Login Credentials

A new large-scale phishing campaign is abusing fake event invitations to compromise U.S. organizations, combining credential theft, OTP interception, and the deployment of remote m...

Read source
techcrunch.com /1 month ago

FBI announces takedown of phishing operation that targeted thousands of victims

Cybercriminals allegedly used the W3LL phishing kit to target more than 17,000 victims worldwide, stealing their passwords and multi-factor authentication codes.

Read source
blog.knowbe4.com /1 month ago

Phishing Campaign Impersonates Palo Alto Networks Recruiters

Threat actors are impersonating Palo Alto Networks recruiters to target job seekers, according to researchers with Palo Alto’s Unit 42 security team. “These attacks specifically ta...

Read source
kauainownews.com /1 month ago

Phishing stories to be presented during final cybersecurity clinic in University of Hawaiʻi Maui College series

"Phishing remains the most effective attack method in 2026 because it targets the one element that can't be easily patched: people," said University of Hawaiʻi Chief Information O...

Read source

Turn fresh research into a full content calendar

Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.

Sources covering Calphishing

macworld.com

Recent coverage from public sources
Public source

blog.knowbe4.com

Recent coverage from public sources
Public source

cloudblog.withgoogle.com

Recent coverage from public sources
Public source

cofense.com

Recent coverage from public sources
Public source

crypto.news

Recent coverage from public sources
Public source

feeds.feedburner.com

Recent coverage from public sources
Public source