Tag

#phishing

172 stories taggedphishing · page 11 of 12.

Aerial 16:9 editorial photograph of an offshore oil and gas drilling platform at dusk, surrounded by calm dark ocean water, small warning lights glowing amber o
Threat Intelligence

Chinese Spy Group Lures Energy Workers With Fake Australian News Site — Then Steals Everything They Type

A state-linked hacking group spent two months tricking employees at offshore energy companies into visiting a bogus news website that silently recorded their keystrokes.

3 min read
A close-up photoreal shot of a smartphone screen at night showing a generic green messaging app icon with a red notification badge, sitting on a dark wooden des
Threat Intelligence

US warns Russian spies are still hunting your WhatsApp and Signal accounts

CISA and the FBI say Russian intelligence officers are running fresh phishing campaigns to hijack accounts on messaging apps used by journalists, officials and activists.

3 min read
Aerial 16:9 editorial photograph of a busy international airport terminal, shot from above at dusk, warm amber lighting illuminating rows of empty check-in desk
Threat Intelligence

TA558 Is Back, Targeting Hotels and Airlines With Fake Booking Emails

A criminal group that has quietly stolen travel-industry data since 2018 has dramatically ramped up its fake-reservation campaigns, now using compressed file tricks to sneak spying software onto victims' computers.

3 min read
A digital illustration showing a phishing attack with a fake login page on a smartphone screen, depicting a large network of connected corporate logos in the ba
Identity & Access

0ktapus Phishing Campaign Hits 130 Companies, Compromising Nearly 10,000 Accounts

A phishing campaign exploiting Okta's authentication system has breached 9,931 accounts across 130 organizations, with Twilio, Cloudflare and DoorDash among the victims.

3 min read
Photoreal editorial close-up of a laptop screen showing a generic blurred cloud sign-in prompt, a translucent glowing link being dragged across the screen by a
Identity & Access

Drag, Drop, Hijacked: How 'ConsentFix' Steals Microsoft 365 Sessions in Seconds

A new twist on the ClickFix trick turns Microsoft's own sign-in prompts into a session-theft machine, and a step-by-step guide is now circulating on a Russian crime forum.

4 min read
A computer screen displaying a warning message about data breach, in an office environment, with student loan documents scattered on a desk in the foreground
Identity & Access

Nelnet Data Breach Exposes 2.5 Million Student Loan Records

A vulnerability in Nelnet's loan servicing system exposed personal data for millions of borrowers. What happened, and what should you do now.

3 min read
Threat Intelligence

Ousaban Resurfaces in Iberia, Hiding Bank-Stealer Payloads Inside Images

A Brazilian trojan pivots to Spanish and Portuguese banking customers, using geofenced PDF lures and steganography to bury its real payload.

3 min read
Threat Intelligence

Phantom Squatting: When Attackers Camp on the Domains LLMs Hallucinate

Unit 42 documents a pre-positioning tactic where actors register non-existent domains that AI assistants keep suggesting, then wait for the traffic to arrive.

3 min read
Threat Intelligence

FIFA 2026 Fraud Infrastructure Was Pre-Staged Months Before Kickoff, Researchers Say

A Check Point exposure report documents pre-positioned phishing kits, lookalike domains and multilingual scam pages built well ahead of the June 11 opening match.

3 min read
Threat Intelligence

236,000 Sites Run Pig-Butchering Templates Built on DCloud Uni-App

Infoblox researchers tie a sprawling fake-exchange and wallet-drainer ecosystem to a legitimate Chinese cross-platform dev framework.

3 min read
Identity & Access

BEC Keeps Winning Because It Looks Exactly Like Normal Work

The phishing payload is gone. The pretext is the payload now, and your SEG was never built for that.

3 min read
Threat Intelligence

Russia's Signal Phishing Now Targets the Backup Recovery Key — and the Key Doesn't Expire

An FBI/CISA update says GRU-linked operators are coaxing victims into surrendering their Signal Backup Recovery Key, which yields full message history and durable account access.

3 min read
Threat Intelligence

Hotel Front Desks Hit by Photo-ZIP Phishing Dropping Node.js Implant

Microsoft flags an unattributed campaign active since April 2026 against hospitality targets in Europe and Asia.

3 min read
Threat Intelligence

The Week in Cheap Crime: Stale Creds, Trusted Apps, and Phishing Through the Front Door

Not elite. Not cinematic. Just effective, and that's the problem.

3 min read
AI Security

Email security teams are buried in alerts. Behavioral AI vendors say they have an answer.

Phishing, BEC and account takeover noise keeps SOC teams busy. A new webinar pitches behavioral detection as the way to cut through it.

3 min read
© 2026 Threat Vectr