Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks.
Tag: phishing
Microsoft Tracks Cloud Intrusion Campaign Using Passkey Phishing and Graph API Abuse
Microsoft Security Research published a report on September 9, 2026, detailing active cloud-based intrusions spanning multiple accounts, in which unusual…
August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges as a New Enterprise Risk as Attacks, Phishing, and Ransomware Accelerate
Key takeaways GenAI usage continued to grow, with the average user generating 106 prompts in August, up from 95 in July and around 78 in June, while…
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails
Trezor, BitBox users targeted in phishing campaign
Trezor and BitBox, two major cryptocurrency hardware wallet manufacturers, have issued urgent warnings after attackers compromised their shared email…
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.
Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools
Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to…
BigBear 2.0 phishing campaign hijacks M365 sessions
A large-scale phishing operation has compromised thousands of Microsoft 365 accounts by stealing authenticated session cookies that remain valid even…
Companies may be measuring phishing resilience the wrong way
Companies that judge phishing simulation programs by how often employees click simulated attack emails may be overlooking more important indicators of…
Phishing in 2026. Latest statistics and analysis
“You’ve been gifted a voucher!”. “Your account will be closed unless you act now”. “Late payment demand. Invoice # 207”. Phishing scams come in many…
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too…
Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections. The campaign…
Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
A new phishing campaign is moving fake login pages into victims’ browsers. Rather than sending people to a malicious website, its operators use…
BigBear phishing crew nets thousands of Microsoft 365 credentials
Researchers got inside the crooks’ admin panel and found 5,137 stolen records tied to 461 organizations
New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary…
Cybercriminals are building phishing pages that exist only inside victims’ browsers
A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside…
Hackers Route Phishing Through Google to Steal Microsoft Credentials
KnowBe4 found hackers abusing trusted Google services to hide phishing pages that steal Microsoft credentials and enable persistent ScreenConnect remote…
August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges as a New Enterprise Risk as Attacks, Phishing, and Ransomware Accelerate
Key takeaways GenAI usage continued to grow, with the average user generating 106 prompts in August, up from 95 in July and around 78 in June, while…
Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools
Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to…
BigBear 2.0 phishing campaign hijacks M365 sessions
A large-scale phishing operation has compromised thousands of Microsoft 365 accounts by stealing authenticated session cookies that remain valid even…