Cybersecurity executives are already familiar with the idea of phishing prevention. For years, CISOs have trained staff to be suspicious of and…
Tag: phishing
LogoKit Phishing Kit Screenshots Victim Sites in Real Time
LogoKit now builds per-victim phishing pages using live screenshots of the target’s real website
Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon
Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing…
Attackers abuse Microsoft auth for phishing
Cybercriminals have shifted tactics in phishing campaigns by exploiting Microsoft’s legitimate authentication infrastructure rather than deploying fake…
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing – the abuse of the OAuth 2.0 device authorization grant to steal access tokens – has evolved from a niche red-team technique to an…
BCON Collective uncovers shared phishing infrastructure linked to ShinyHunters
Bridewell’s BCON Collective has uncovered an active phishing infrastructure spanning more than 100 malicious domains after investigating what initially…
AiTM Phishing Becomes Top Initial Access Threat to Law Firms
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats
ChatGPT Joins Most Faked Brands Ranking in Phishing, Check Point Says
ChatGPT entered Check Point’s top 10 phishing brand ranking as fake ChatGPT Plus payment failure emails targeted users’ credit card details.
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Talos IR’s Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn…
Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages
Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate…
Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks
Attackers are moving away from fake Microsoft login pages in favor of abusing Microsoft’s own authentication system, letting phishing campaigns slip past…
What to know about deepfake phishing simulation software
Cybersecurity executives are already familiar with the idea of phishing prevention. For years, CISOs have trained staff to be suspicious of and…
AI-Generated Phishing No Longer Needs Malware: It Can Steal Your Session Inside the Browser
AI-generated phishing campaigns are rapidly evolving beyond traditional malware delivery, shifting the battleground directly into the web browser where…
LogoKit Phishing Kit Screenshots Victim Sites in Real Time
LogoKit now builds per-victim phishing pages using live screenshots of the target’s real website
Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon
Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing…
ChatGPT Joins Most Faked Brands Ranking in Phishing, Check Point Says
ChatGPT entered Check Point’s top 10 phishing brand ranking as fake ChatGPT Plus payment failure emails targeted users’ credit card details.
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
Global phishing-as-a-service (PhaaS) activity surged to 7,295 tracked uploads during the week of July 20-26, 2026, driven overwhelmingly by OAuth…
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise
Dismantled Kratos Phishing Kits Acting as Blueprint for Others to Attack Microsoft 365 Users
Kratos is a phishing service built to steal Microsoft 365 credentials at scale. It evolved from the Sneaky2FA kit and gave affiliates ready-made login…