#phishing
139 stories taggedphishing · page 2 of 10.

AI Is Making Data Breaches More Expensive. Here's What the Numbers Actually Say.
A new IBM report puts the average global cost of a data breach at $6 million for 2026, up 35% in a year, and for the first time, AI-powered attacks account for one in four of those incidents.

Fake COLDCARD 'Security Audit' Emails Push Remote Access Tool After $88M Bitcoin Theft
Phishing campaign impersonates the hardware wallet maker, tricks owners into installing ScreenConnect, and hands attackers full control of the victim's PC.

Why Blocklists Can't Keep Up With AI-Built Phishing Sites
Attackers are spinning up throwaway phishing pages faster than defenders can list them. Researchers at Push Security argue the fix is watching what a page does, not where it lives.

Kali365 Phishing Kit Turns Microsoft's Own Login Page Against US Firms
A new criminal toolkit tricks staff into approving attacker device codes on genuine Microsoft screens, handing over long-lived access to email and cloud files.

Greatness Phishing Kit Adds a New Trick to Steal Logins Without Passwords
The rented phishing toolkit now abuses Microsoft's own login flow to walk around multi-factor authentication.

Your Email AI Assistant Could Be Turned Against You, Researchers Warn
Security researchers have shown how the AI chatbots built into modern email platforms can be hijacked to impersonate colleagues, steal account access, and set up financial fraud, all without sending a single suspicious link.

When Anyone Can Hack: How AI Is Turning Beginners Into Capable Attackers
The old ranking of hackers by skill is breaking down as chatbots hand novices tools that used to take years to learn.

Fake RingGo Texts Are Tricking Drivers Into Handing Over Bank Details
Scammers are sending fraudulent parking-fee demands that impersonate the RingGo app, banking on the fact that most drivers genuinely can't remember every parking session they've paid for.

Fake Amazon Login Pages Hide a Chinese iPhone Hacking Campaign
Researchers say a Chinese group is running more than 100 lookalike sign-in sites to attack iPhones with a leaked hacking kit called DarkSword.

Cybersecurity Then and Now: What Actually Changed (and What Didn't)
A look at how the threats facing ordinary people and the businesses they deal with have shifted over the decades, and why some of the oldest tricks still work best.

Cyber-attack on England's Department for Education exposes 607,000 records
Contact details for individuals and organisations were taken in a breach affecting two government education portals. No bank details were stolen, but the incident lands as UK school and college cyber-attacks hit record frequency.

Device Code Phishing: The Login Trick That Blew Up in 2026
A login flow built for smart TVs is now one of the fastest-growing routes into corporate accounts, and identity teams are struggling to keep up.

This Week's Security Roundup: Trust, Trickery, and the Weak Seams Attackers Keep Finding
From reused passwords to fake install guides and abused recruiter calls, the past week's incidents share a pattern: attackers exploited the moments people expect a screen to behave normally.

Amazon Traces September npm Hijack of Debug and Chalk to North Korean Hackers
What looked like a wallet-draining crypto heist ten months ago now points to Pyongyang, according to fresh analysis from Amazon.

The Four Ways Criminals Beat Multi-Factor Authentication (And What You Can Do About It)
Multi-factor authentication was supposed to be the lock that hackers couldn't pick. It turns out there are at least four reliable ways through it, and most organisations are leaving at least one door wide open.