Tag

#phishing

172 stories taggedphishing · page 6 of 12.

An email inbox showing a phishing message with COLDCARD hardware wallet branding, an installation dialog in the background, and subtle indicators of the ScreenC
Threat Intelligence

Fake COLDCARD 'Security Audit' Emails Push Remote Access Tool After $88M Bitcoin Theft

A phishing campaign impersonates the hardware wallet maker, tricks owners into installing ScreenConnect, and hands attackers full control of the victim's PC.

4 min read
Multiple fake login pages loading rapidly across browser tabs, with blocklist databases shown as outdated in the taskbar
Threat Intelligence

Why Blocklists Can't Keep Up With AI-Built Phishing Sites

Attackers are spinning up throwaway phishing pages faster than defenders can list them. Researchers at Push Security argue the fix is watching what a page does, not where it lives.

4 min read
A Windows login screen being displayed on a corporate office computer, with device approval prompts visible and attacker control indicators in the system tray
Identity & Access

Kali365 Phishing Kit Turns Microsoft's Own Login Page Against US Firms

A criminal toolkit tricks staff into approving attacker device codes on genuine Microsoft screens, handing over long-lived access to email and cloud files.

3 min read
A login screen on a computer monitor showing a Microsoft authentication interface with MFA prompts, while a shadow or overlay suggests an attacker's toolkit int
Identity & Access

Greatness Phishing Kit Adds a New Trick to Steal Logins Without Passwords

The rented phishing toolkit now abuses Microsoft's own login flow to walk around multi-factor authentication.

4 min read
An email platform window on a monitor showing an AI assistant panel, while below it displayed messages appear to impersonate colleagues and contain financial re
AI Security

Your Email AI Assistant Could Be Turned Against You, Researchers Warn

Security researchers have shown how the AI chatbots built into modern email platforms can be hijacked to impersonate colleagues, steal account access, and set up financial fraud, all without a single suspicious link.

4 min read
A person's hands on a keyboard with an AI chatbot interface visible on the monitor, showing how easy-to-use prompts are generating sophisticated attack code and
AI Security

When Anyone Can Hack: How AI Is Turning Beginners Into Capable Attackers

The old ranking of hackers by skill is breaking down as chatbots hand novices tools that used to take years to learn.

4 min read
Driver sitting in parked car looking at a suspicious text message on phone screen, parking meter and street setting visible in background, expression of confusi
Threat Intelligence

Fake RingGo Texts Are Tricking Drivers Into Handing Over Bank Details

Scammers are sending fraudulent parking-fee demands that impersonate the RingGo app, banking on the fact that most drivers genuinely can't remember every parking session they've paid for.

3 min read
A smartphone screen showing a fake Amazon login page overlaid with warning symbols and a map showing geographic origin points of the attack campaign
Threat Intelligence

Fake Amazon Login Pages Hide a Chinese iPhone Hacking Campaign

Researchers say a Chinese group is running more than 100 lookalike sign-in sites to attack iPhones with a leaked hacking kit called DarkSword.

4 min read
A split timeline view showing cybersecurity threats from decades past and present side-by-side, vintage computer terminals evolving into modern networks, same a
Opinion

Cybersecurity Then and Now: What Actually Changed (and What Didn't)

How the threats facing ordinary people and the businesses they deal with have shifted over the decades, and why some of the oldest tricks still work best.

3 min read
A UK government building's entrance at dusk with security barriers visible, data streams flowing across glass windows in digital visualization, suggesting data
Breaches

Cyber-attack on England's Department for Education exposes 607,000 records

Contact details for individuals and organisations were taken in a breach affecting two government education portals. No bank details were stolen, but the incident lands as UK school and college cyber-attacks hit record frequency.

3 min read
A smart TV setup with a device code login screen displayed, corporate office network architecture visible in the background, breach pathways illustrated through
Identity & Access

Device Code Phishing: The Login Trick That Blew Up in 2026

A login flow built for smart TVs is now one of the fastest-growing routes into corporate accounts, and identity teams are struggling to keep up.

4 min read
A composite image showing multiple computer screens in an office with reused password prompts, fake software installation windows, and phone calls on Teams, all
Threat Intelligence

This Week's Security Roundup: Trust, Trickery, and the Weak Seams Attackers Keep Finding

From reused passwords to fake install guides and abused recruiter calls, this week's incidents share a pattern: attackers exploited the moments people expect a screen to behave normally.

3 min read
An npm package repository screen showing the hijacked 'Debug' and 'Chalk' packages with suspicious version uploads and download statistics, with attribution mar
Threat Intelligence

Amazon Traces September npm Hijack of Debug and Chalk to North Korean Hackers

What looked like a wallet-draining crypto heist ten months ago now points to Pyongyang, according to fresh analysis from Amazon.

3 min read
Four different authentication bypass scenarios displayed across a split-screen interface, each showing a different vector of attack against multi-factor authent
Identity & Access

The Four Ways Criminals Beat Multi-Factor Authentication (And What You Can Do About It)

Multi-factor authentication was supposed to be the lock that hackers couldn't pick. It turns out there are at least four reliable routes through it, and most organisations are leaving at least one wide open.

5 min read
An email inbox with a fake Spotify payment failure notice prominently displayed, the user clicking through to a copycat login page, credit card input fields vis
Identity & Access

Fake Spotify Payment Emails Are Stealing Card Details From Real Subscribers

Criminals are sending convincing payment-failure notices that lead Spotify users to copycat websites designed to harvest login credentials and credit card numbers.

3 min read
© 2026 Threat Vectr