Tag

#phishing

172 stories taggedphishing.

Full-frame edge-to-edge photoreal editorial shot of a smartphone lying face-up on a dark office desk, screen showing a generic unknown-caller interface glowing
Identity & Access

Fake IT helpdesk calls are opening the door to Microsoft 365 accounts

Microsoft says attackers are ringing staff on personal phones, walking them through passkey 'updates', then pulling SharePoint and OneDrive files.

4 min read
Full-frame edge-to-edge photoreal editorial shot of a cluttered corporate mail sorting facility at dusk, thousands of pale envelopes moving along a conveyor wit
Threat Intelligence

Microsoft says Defender missed 221 high-severity emails per thousand users and still won its own benchmark

The vendor's fifth quarterly scorecard shows missed-threat rates climbing across the industry as AI-written phishing gets harder to catch.

4 min read
A glowing blue padlock made of translucent code fragments slowly dissolving into streams of light against a dark server room background, with rows of blinking r
Identity & Access

GhostCode Phishing Kit Turns Microsoft's Own Login Flow Against You

A new tool called GhostCode abuses a legitimate Microsoft sign-in mechanism to steal account access, register attacker-controlled devices, and survive password resets, all in under 90 seconds.

4 min read
A smartphone screen showing an SMS message about student finance updates positioned next to a legitimate bank message, both displayed side-by-side to show the s
Identity & Access

Fake Student Finance Texts Are Targeting New Students Right Before Their Loan Drops

Criminals are sending convincing fake messages about bank-detail changes to students waiting on their first maintenance loan payment. Here is what is actually going on.

3 min read
A laptop screen displaying a login form overlaid with transparent code and data structures, suggesting layers of legitimate services being repurposed for decept
Threat Intelligence

Phishing Pages Built Inside Your Browser: How Attackers Are Using Microsoft's Own Tools Against You

A new phishing technique assembles fake login pages directly inside the victim's browser, using legitimate Microsoft services so there is no suspicious website for security tools to find and block.

3 min read
A phishing email in an inbox with a spoofed Trezor security alert subject line, security warning indicators, and behind it visible records of a breached third-p
Breaches

Trezor's email system hijacked to send fake 'security alert' phishing to customers

Criminals used a breached third-party email provider to send phishing from a real Trezor address, weeks after a separate shipping-partner breach ballooned to 81,000 customers.

4 min read
A ship's navigation table with historical sextant and maps, modern cybersecurity threat visualization overlaid, showing how precise positioning and ground truth
AI Security

The Longitude Problem: Why Ground Truth Beats Guesswork in the AI Age

For centuries, sailors died because they could estimate their position but not confirm it. Attackers targeting your company today face the same gap, and your best defence is the same one that finally solved navigation.

4 min read
A security analyst's workstation displaying a real-time threat dashboard with login attempts, phishing emails, and identity abuse alerts covering the screens, w
Threat Intelligence

Half of All Real Attacks Now Target Logins, Says Prophet Security Review

A quarter of investigating every alert across customer environments shows identity abuse, help-desk trickery and old-school phishing still doing most of the damage.

4 min read
A security incident montage showing overlapping vulnerabilities from the week—malicious browser extensions installing, phishing pages inside legitimate platform
Threat Intelligence

The Week's Security Mess: Why Did Any of This Work in the First Place?

From greedy browser extensions to phishing pages built inside trusted services, this week's incidents share one uncomfortable answer.

4 min read
A security operations center with multiple monitors displaying alert systems, one showing a SIM card symbol with warning indicators, another with an internation
Threat Intelligence

Invisible Characters, SIM Swap Jail Time, and a $10 Million Bounty: This Week's Security Briefing

A trick that hides malicious text from spam filters, a phone-hijacking criminal now behind bars, and a US government reward for help catching an Iranian hacking official.

3 min read
A corporate training session with employees on computers taking a simulated phishing test, with research charts and data analysis visible on a presentation scre
Identity & Access

2.47 Million Simulated Attacks Suggest We're Measuring the Wrong Things in Phishing Training

New research points out a gap between what most companies track (who clicked a fake link) and what actually matters (whether stolen passwords are being spotted and staff are reporting suspicious emails).

3 min read
A layered split-screen showing AI agent automation workflows on the left, WeChat interface with suspicious forwarding patterns in the center, and legacy securit
Threat Intelligence

Rogue AI Agents, a WeChat Worm and PaperCut Attacks Say Something About Basic Security

Attackers are pushing AI into more of their workflow, and old bugs are still doing most of the damage.

4 min read
A power substation or electrical utility facility at night with transformer equipment illuminated, a computer terminal showing access logs in an office area, an
Breaches

CenterPoint Energy Confirms Customer Data Stolen After Hacker Posts 7.5 Million Records Online

A Houston electricity and gas supplier serving 7 million households has told federal regulators that an outsider broke into one of its internet-facing systems and walked off with customer personal information.

3 min read
A laptop displaying a counterfeit e-commerce checkout page designed to mimic Apple's official store, with iPhone 18 Pro imagery and payment forms, while a curso
Threat Intelligence

Fake iPhone 18 Deal Sites Are Stealing Money From Shoppers

Criminals are setting up convincing fake shops to target anyone searching for a cheaper price on Apple's new iPhone 18 Pro and foldable Duo. If you pay, the phone never arrives.

3 min read
A corporate office worker at a desk, illuminated by monitor light, typing credentials into a login form on their screen while unaware of malicious intent, with
Identity & Access

N0va phishing kit hunts logins across US and EU businesses

A phishing toolkit called N0va is tricking staff into handing over working accounts, then quietly walking through the front door.

4 min read
© 2026 Threat Vectr