A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too…
Tag: phishing
Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections. The campaign…
Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
A new phishing campaign is moving fake login pages into victims’ browsers. Rather than sending people to a malicious website, its operators use…
BigBear phishing crew nets thousands of Microsoft 365 credentials
Researchers got inside the crooks’ admin panel and found 5,137 stolen records tied to 461 organizations
New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary…
Cybercriminals are building phishing pages that exist only inside victims’ browsers
A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside…
Hackers Route Phishing Through Google to Steal Microsoft Credentials
KnowBe4 found hackers abusing trusted Google services to hide phishing pages that steal Microsoft credentials and enable persistent ScreenConnect remote…
August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges as a New Enterprise Risk as Attacks, Phishing, and Ransomware Accelerate
Key takeaways GenAI usage continued to grow, with the average user generating 106 prompts in August, up from 95 in July and around 78 in June, while…
Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools
Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to…
BigBear 2.0 phishing campaign hijacks M365 sessions
A large-scale phishing operation has compromised thousands of Microsoft 365 accounts by stealing authenticated session cookies that remain valid even…
New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or…
Phishing Powers 80% of Attacks on US Companies: How SOCs Can Detect It Early
Phishing remains one of the most effective ways for attackers to gain access to corporate environments. From 2013-2023, the FBI recorded 158,436 US…
Phishing in 2026. Latest statistics and analysis
“You’ve been gifted a voucher!”. “Your account will be closed unless you act now”. “Late payment demand. Invoice # 207”. Phishing scams come in many…
BigBear phishing crew nets thousands of Microsoft 365 credentials
Researchers got inside the crooks’ admin panel and found 5,137 stolen records tied to 461 organizations
Trezor customers hit with phishing calls and letters after shipping-partner breach
Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names,…
BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
BigBear 2.0 is a phishing operation designed to steal proof that a user has already passed multi-factor authentication. It targets Microsoft 365 accounts…
Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks
Criminals are using trusted Google services as cover for a wide phishing campaign that steals corporate credentials and, in some cases, installs…
Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials
A large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly…
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a “high-volume phishing campaign” that’s using invisible Unicode tag characters to bypass email filters. “Instead of using these…
Hackers Use Invisible Unicode Characters to Evade Phishing Detection in Millions of Emails
Attackers are using invisible Unicode characters to make phishing emails appear harmless while disrupting the security systems built to spot suspicious…
