#phishing
140 stories taggedphishing · page 5 of 10.

Over a Million Phishing Emails Used Hidden Text to Fool AI Security Filters
Researchers found that criminals are hiding innocent words inside malicious emails to confuse both traditional and AI-powered spam filters, and the technique is working.

AI Can Build a Dossier on Your CEO in Ten Minutes. Most Companies Have No Answer for That.
Artificial intelligence tools have turned the slow, skilled work of researching a target executive into a task anyone with a browser can do. Security teams have not caught up.

Fake Emails Now Beat Software Flaws as the Number-One Way Ransomware Gets In
A Sophos survey of more than 2,000 organisations hit by ransomware finds that phishing and malicious emails now cause half of all attacks, while stolen passwords are defeating even multi-factor authentication at an alarming rate.

US Charges Three Russians for Running 'Bulletproof' Hosting That Powered Ransomware and Phishing Attacks on 42 American Organisations
A grand jury indictment unsealed this week names Aleksandr Volosovik, Kirill Zatolokin, and Yulia Pankova as the operators behind two companies that rented out hidden, hard-to-shut-down internet infrastructure to criminals worldwide.

Cybersecurity Spends Billions Spotting Attacks. It Should Be Stopping Them.
Detection tools now dominate the security market, but faster alerts have not cut breach rates. A growing chorus of security professionals says the industry has the balance badly wrong.

What separates a good security engineer from a great one in 2025
New research and industry voices spell out exactly what companies should demand when hiring the people who keep their systems safe, and why the old checklist of certifications no longer cuts it.

Microsoft Is Killing SMS Login for Millions of Business Accounts. Here Is What Replaces It.
Starting September 2026, Microsoft will push passkeys as the default way to prove your identity in its business login system. By February 2027, the old text-message codes go dark entirely.

Fake LastPass and Bitwarden emails send users to bogus DocuSign pages
Criminals are impersonating two of the biggest password managers with polished 'policy update' emails that push a malicious file download.

Microsoft is killing SMS logins for business accounts. Passkeys take over in September 2026.
Entra ID, the sign-in system used by millions of companies, will switch to passkeys by default. Text-message codes get shut off in February 2027.

Fake Guardian Articles Are Tricking People Into Scam Investment Sites
Criminals are building convincing copies of trusted news websites, complete with fake celebrity stories, to push victims toward fraudulent trading platforms.

ScamBuster Turns Phishing Emails Into Intelligence by Pretending to Be the Victim
A French engineer built an AI system that replies to scam emails, plays along long enough to extract bank details and phone numbers, then hands the data to investigators.

Lidl Customers in Three Countries Warned After Supplier Breach Exposes Personal Data
The German discount chain says a file at an outside IT provider was raided, spilling names, phone numbers and dates of birth for online shoppers in Germany, Belgium and the Netherlands.

A Phishing Crew Forgot to Lock Its Own Front Door
A single sloppy command in a shell history file handed French researchers the full toolkit behind three live Microsoft 365 phishing operations.

Argentina's Football Association Says Its Email Account May Have Been Hacked After World Cup Win
Someone sent journalists messages from the AFA's official inbox claiming Argentina's victory over Egypt was fixed. The association says it didn't send them.

Criminals Are Calling Your Staff and Stealing Microsoft 365 Logins in Real Time
A hacking group is phoning employees, sending them to fake Microsoft login pages, and quietly locking themselves into corporate accounts before anyone notices. Okta has the details.