Latest updates for Phishing

Fresh curated links around Phishing are collected here so marketers can spot useful updates and turn timely ideas into posts faster.

Recent items include:

  • Inside the OS-Aware Phishing Kit Profiling Your Device
  • Phishing attacks don’t look fake anymore: Watch for these 7 scams
  • UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

Post angles to try

Share the most useful takeaway for your audience.
Turn one article into a quick practical checklist.
Ask your audience how this shift affects their work.
Turn angles into scheduled posts

Fresh articles and ideas

Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.

blog.knowbe4.com /1 month ago

Inside the OS-Aware Phishing Kit Profiling Your Device

Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal The lure email has been received. This is a fabricated iCloud sign-in alert designed to feel like an official sec...

Read source
pcworld.com /1 month ago

Phishing attacks don’t look fake anymore: Watch for these 7 scams

There have been two major changes in phishing attacks in recent years: Criminals are using generative AI to create emails that are linguistically almost perfect, and which are now...

Read source
thehackernews.com /1 month ago

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. "UNC6671 continues...

Read source
infosecurity-magazine.com /1 month ago

Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques

Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise

Read source
thehackernews.com /1 month ago

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the crede...

Read source
gbhackers.com /1 week ago

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page for virtually every request, undermining detection approache...

Read source
cofense.com /4 weeks ago

You're Invited to get Phished! Why Invitation-themed Emails Remain Effective

By: Micah DeHarty, Intelligence TeamThreat actors are weaponizing party invitation-themed emails to steal credentials and install malware on victims’ machines. Cofense Intelligence...

Read source
blog.knowbe4.com /6 days ago

Recruitment-Themed Phishing Campaign Targets Enterprise Users

Researchers at Zimperium are tracking widespread phishing campaigns that use Browser-in-the-Browser (BitB) attacks to trick users into handing over their enterprise credentials. Th...

Read source
infosecurity-magazine.com /2 weeks ago

Fake Recruiter Scams Target Corporate Credentials on Mobile

RecruitTrap campaigns use mobile-optimized phishing pages to target enterprise credentials

Read source
blog.knowbe4.com /1 week ago

Voice Phishing Attacks Target Hedge Fund Employees

Google’s Threat Intelligence Group (GTIG) is tracking a voice phishing (vishing) campaign that’s targeting hedge funds and financial firms. The researchers attribute the attacks to...

Read source
infosecurity-magazine.com /1 week ago

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

A large-scale phishing campaign used fake voicemail SVG attachments to bypass email defenses, targeting 5527 organizations with over 26,000 malicious messages

Read source
thehackernews.com /1 month ago

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of M...

Read source
theregister.com /2 weeks ago

$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts

Seller's demos show a browser-in-the-middle attack adding credentials seconds after authentication

Read source
thehackernews.com /1 month ago

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial int...

Read source
cybersecuritynews.com /3 weeks ago

JWR Phishing Framework Uses Real-Time WebSocket Control and AES Encryption to Steal Banking Credentials

JWR is a phishing framework built for live fraud. It turns a fake payment or bank page into a live channel that lets criminals watch details arrive as they are typed. The campaign...

Read source
kashmirreader.com /1 month ago

Fake ‘Vote for Me’ links on X target users in new phishing campaign

Srinagar: A cyber security expert on Monday warned users of a phishing campaign spreading rapidly on social media platform X, where hackers are using compromised accounts to send f...

Read source
gbhackers.com /1 month ago

Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials

A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials...

Read source
thehackernews.com /3 weeks ago

CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps

Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) wind...

Read source
cofense.com /3 weeks ago

Phonescams: Casting a Wide Net in an Orchard of Low-Hanging Fruit

The blog explains how phone scams have become a highly scalable phishing tactic, with attackers impersonating trusted brands like Amazon, Microsoft, Apple, and others to trick reci...

Read source
editorialge.com /2 weeks ago

What Is Phishing and How to Spot It in Emails and Texts

A Microsoft 365 alert, a package redelivery text, an urgent message from your boss—phishing scams rely on speed and panic to make you act before thinking. So, what is phishing and...

Read source
cybersecuritynews.com /5 days ago

Hackers Use QR Codes in Phishing Emails to Steal Login Credentials

Hackers are putting QR codes in phishing emails to steal login credentials. Known as quishing, the method hides a dangerous web address inside a square and persuades recipients to...

Read source
infosecurity-magazine.com /2 weeks ago

Def Con Attendees Targeted by Persistent Phishing Campaign

Huntress researcher explains how they were targeted by an elaborate and persistent phishing scam following Def Con

Read source
cybersecuritynews.com /3 weeks ago

Hackers Leveraging GoogleWorkspace Accounts to Send Phishing and Scam Emails

Hackers are turning compromised Google Workspace accounts into tools for phishing and scam emails. The messages can look ordinary because they come from real organizational domains...

Read source
bleepingcomputer.com /1 month ago

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accou...

Read source

Turn fresh research into a full content calendar

Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.

Sources covering Phishing

blog.knowbe4.com

Recent coverage from public sources
Public source

cofense.com

Recent coverage from public sources
Public source

cybersecuritynews.com

Recent coverage from public sources
Public source

editorialge.com

Recent coverage from public sources
Public source

feeds.feedburner.com

Recent coverage from public sources
Public source

gbhackers.com

Recent coverage from public sources
Public source