#phishing
172 stories taggedphishing.

Fake IT helpdesk calls are opening the door to Microsoft 365 accounts
Microsoft says attackers are ringing staff on personal phones, walking them through passkey 'updates', then pulling SharePoint and OneDrive files.

Microsoft says Defender missed 221 high-severity emails per thousand users and still won its own benchmark
The vendor's fifth quarterly scorecard shows missed-threat rates climbing across the industry as AI-written phishing gets harder to catch.

GhostCode Phishing Kit Turns Microsoft's Own Login Flow Against You
A new tool called GhostCode abuses a legitimate Microsoft sign-in mechanism to steal account access, register attacker-controlled devices, and survive password resets, all in under 90 seconds.

Fake Student Finance Texts Are Targeting New Students Right Before Their Loan Drops
Criminals are sending convincing fake messages about bank-detail changes to students waiting on their first maintenance loan payment. Here is what is actually going on.

Phishing Pages Built Inside Your Browser: How Attackers Are Using Microsoft's Own Tools Against You
A new phishing technique assembles fake login pages directly inside the victim's browser, using legitimate Microsoft services so there is no suspicious website for security tools to find and block.

Trezor's email system hijacked to send fake 'security alert' phishing to customers
Criminals used a breached third-party email provider to send phishing from a real Trezor address, weeks after a separate shipping-partner breach ballooned to 81,000 customers.

The Longitude Problem: Why Ground Truth Beats Guesswork in the AI Age
For centuries, sailors died because they could estimate their position but not confirm it. Attackers targeting your company today face the same gap, and your best defence is the same one that finally solved navigation.

Half of All Real Attacks Now Target Logins, Says Prophet Security Review
A quarter of investigating every alert across customer environments shows identity abuse, help-desk trickery and old-school phishing still doing most of the damage.

The Week's Security Mess: Why Did Any of This Work in the First Place?
From greedy browser extensions to phishing pages built inside trusted services, this week's incidents share one uncomfortable answer.

Invisible Characters, SIM Swap Jail Time, and a $10 Million Bounty: This Week's Security Briefing
A trick that hides malicious text from spam filters, a phone-hijacking criminal now behind bars, and a US government reward for help catching an Iranian hacking official.

2.47 Million Simulated Attacks Suggest We're Measuring the Wrong Things in Phishing Training
New research points out a gap between what most companies track (who clicked a fake link) and what actually matters (whether stolen passwords are being spotted and staff are reporting suspicious emails).

Rogue AI Agents, a WeChat Worm and PaperCut Attacks Say Something About Basic Security
Attackers are pushing AI into more of their workflow, and old bugs are still doing most of the damage.

CenterPoint Energy Confirms Customer Data Stolen After Hacker Posts 7.5 Million Records Online
A Houston electricity and gas supplier serving 7 million households has told federal regulators that an outsider broke into one of its internet-facing systems and walked off with customer personal information.

Fake iPhone 18 Deal Sites Are Stealing Money From Shoppers
Criminals are setting up convincing fake shops to target anyone searching for a cheaper price on Apple's new iPhone 18 Pro and foldable Duo. If you pay, the phone never arrives.

N0va phishing kit hunts logins across US and EU businesses
A phishing toolkit called N0va is tricking staff into handing over working accounts, then quietly walking through the front door.