Inside the OS-Aware Phishing Kit Profiling Your Device
Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal The lure email has been received. This is a fabricated iCloud sign-in alert designed to feel like an official sec...
Search fresh public links, source activity, and ready-to-use post angles for Phishing.
Fresh curated links around Phishing are collected here so marketers can spot useful updates and turn timely ideas into posts faster.
Recent items include:
Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.
Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal The lure email has been received. This is a fabricated iCloud sign-in alert designed to feel like an official sec...
There have been two major changes in phishing attacks in recent years: Criminals are using generative AI to create emails that are linguistically almost perfect, and which are now...
A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. "UNC6671 continues...
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the crede...
A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page for virtually every request, undermining detection approache...
By: Micah DeHarty, Intelligence TeamThreat actors are weaponizing party invitation-themed emails to steal credentials and install malware on victims’ machines. Cofense Intelligence...
Researchers at Zimperium are tracking widespread phishing campaigns that use Browser-in-the-Browser (BitB) attacks to trick users into handing over their enterprise credentials. Th...
RecruitTrap campaigns use mobile-optimized phishing pages to target enterprise credentials
Google’s Threat Intelligence Group (GTIG) is tracking a voice phishing (vishing) campaign that’s targeting hedge funds and financial firms. The researchers attribute the attacks to...
A large-scale phishing campaign used fake voicemail SVG attachments to bypass email defenses, targeting 5527 organizations with over 26,000 malicious messages
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of M...
Seller's demos show a browser-in-the-middle attack adding credentials seconds after authentication
A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial int...
JWR is a phishing framework built for live fraud. It turns a fake payment or bank page into a live channel that lets criminals watch details arrive as they are typed. The campaign...
Srinagar: A cyber security expert on Monday warned users of a phishing campaign spreading rapidly on social media platform X, where hackers are using compromised accounts to send f...
A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials...
Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) wind...
The blog explains how phone scams have become a highly scalable phishing tactic, with attackers impersonating trusted brands like Amazon, Microsoft, Apple, and others to trick reci...
A Microsoft 365 alert, a package redelivery text, an urgent message from your boss—phishing scams rely on speed and panic to make you act before thinking. So, what is phishing and...
Hackers are putting QR codes in phishing emails to steal login credentials. Known as quishing, the method hides a dangerous web address inside a square and persuades recipients to...
Huntress researcher explains how they were targeted by an elaborate and persistent phishing scam following Def Con
Hackers are turning compromised Google Workspace accounts into tools for phishing and scam emails. The messages can look ordinary because they come from real organizational domains...
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accou...
Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.