#phishing
172 stories taggedphishing · page 3 of 12.

ClickFix: The Attack That Talks You Into Hacking Yourself
Microsoft says the fake 'prove you're not a robot' trick was the single most common way criminals broke into companies last year. The clever bit is that the victim does the hard work.

Microsoft Makes Passkeys the Default Login for Business Accounts. Passwords Aren't Dead Yet.
From September 2025, Microsoft's business identity system defaults to passkeys instead of passwords. But the shift will take years, and most companies will run both systems side by side for a long time.

Bank Impersonation Scams: How One Target Wasted the Fraudsters' Time for Hours
A reader who received a fake Barclays automated call decided not to hang up. What followed is a useful case study in how these scams work and what you can do when one lands in your lap.

Brave Rolls Out Email Aliases to Cut Off a Common Path to Phishing
Version 1.94 of the Brave browser lets users mask their real inbox behind disposable addresses, aiming to blunt data-broker resale and post-breach phishing.

Your AI email assistant can be fed a fake message while you read a real one
Researchers hid nearly 500 characters of secret instructions inside an ordinary-looking email. The AI summariser obeyed them every single time.

NovaCookies Phishing Kit Rents Microsoft 365 Session Theft for $320 a Month
A new subscription phishing service abuses genuine Docusign emails to slip past multi-factor authentication and steal live Microsoft 365 logins.

UK Homebuyers Lose Hundreds of Thousands to 'Friday Afternoon' Email Fraud
Criminals hijack email chains between buyers, solicitors and estate agents to redirect house-purchase deposits into fake bank accounts. One victim lost £300,000.

AnonyMousKIT: the phishing kit that turns stolen iPhones back into cash
A subscription service is helping thieves trick iPhone owners into handing over the codes needed to disable device locks, with AI-powered phone calls doing much of the work.

New 'SynkLoader' Malware Could Be the Opening Move in Future Ransomware Attacks
Researchers at Expel found a modular malicious program that tricks employees into handing over their passwords, hides from security tools, and looks built to prepare corporate networks for ransomware.

Two SOCs, Same Attack: CISA Red Team Walks Through One Network, Gets Caught in the Other
CISA ran identical red team drills against a government agency and a water utility. One let the attackers roam for weeks. The other spotted them within hours.

Criminals Turn npm Into Free Hosting for Fake Cloudflare Login Traps
Researchers found 24 packages on the npm registry being used not to poison developers, but as free web hosting for phishing pages that pretend to be Cloudflare's human-check screen.

Seven Ways AI Is Changing How Companies Defend Themselves
Security experts say artificial intelligence is giving overstretched security teams a fighting chance, but only if organisations deploy it carefully and with realistic expectations.

Three Banking Trojans Are Quietly Draining Accounts Across Two Continents
Manic, Grandoreiro, and ToxicPanda 2.0 are targeting bank customers in Latin America and Europe. Here is what each one does and what ordinary people should watch for.

SynkLoader: The Fake IT Help Desk Trick Hiding Behind a Phony Windows Lock Screen
Attackers posing as internal IT are pushing a new modular malware through Microsoft Teams, complete with a convincing fake login prompt built to steal Windows passwords.

New Phishing Toolkit Registers Attacker Passkeys to Survive Password Resets
A tool called iAuthFlow V2 lets criminals plant a login credential they control inside your account, so changing your password does nothing to lock them out.