#phishing
172 stories taggedphishing · page 9 of 12.

What separates a good security engineer from a great one in 2025
New research and industry voices spell out what companies should demand when hiring the people who keep their systems safe, and why a checklist of certifications no longer cuts it.

Fake LastPass and Bitwarden emails send users to bogus DocuSign pages
Criminals are impersonating two of the biggest password managers with polished 'policy update' emails that push a malicious file download.

Microsoft is killing SMS logins for business accounts. Passkeys take over in September 2026.
Entra ID, the sign-in system used by millions of companies, will switch to passkeys by default. Text-message codes get shut off in February 2027.

Fake Guardian Articles Are Tricking People Into Scam Investment Sites
Criminals are building convincing copies of trusted news websites, complete with fake celebrity stories, to push victims toward fraudulent trading platforms.

ScamBuster Turns Phishing Emails Into Intelligence by Pretending to Be the Victim
A French engineer built an AI system that replies to scam emails, plays along long enough to extract bank details and phone numbers, then hands the data to investigators.

Lidl Customers in Three Countries Warned After Supplier Breach Exposes Personal Data
The German discount chain says a file at an outside IT provider was raided, spilling names, phone numbers and dates of birth for online shoppers in Germany, Belgium and the Netherlands.

A Phishing Crew Forgot to Lock Its Own Front Door
A single sloppy command in a shell history file handed French researchers the full toolkit behind three live Microsoft 365 phishing operations.

Argentina's Football Association Says Its Email Account May Have Been Hacked After World Cup Win
Someone sent journalists messages from the AFA's official inbox claiming Argentina's victory over Egypt was fixed. The association says it didn't send them.

Criminals Are Calling Your Staff and Stealing Microsoft 365 Logins in Real Time
A hacking group is phoning employees, sending them to fake Microsoft Entra ID login pages, and quietly registering their own passkeys before anyone notices. Okta has the details.

AI Is a Force Multiplier for Defenders and Attackers Both, Says Check Point CTO
Jonathan Zanger says every AI platform his team examined over the past year had serious security flaws. The fix isn't to avoid AI. It's to build security in from the start.

Forg365: the new phishing kit built to hoover up Microsoft 365 logins
A fresh phishing-as-a-service operation uses AI to write the bait and a browser extension to keep the door open long after the theft.

When Attacks Take Minutes, Not Days: The AI Speed Problem Defenders Now Face
Criminals using AI models can now write phishing bait, pick targets and hop between machines faster than most security teams can read the first alert.

'Ghost Phishing' Campaign Slips Past Email Filters by Hiding Until It Reaches the Victim
The EvilTokens operation is hitting companies across the US and Europe with pages that stay encrypted in transit and only unlock inside the target's browser.

Blocking Phishing Emails Is Not Enough. Here Is Why the Attack Carries On Anyway.
Filtering a malicious email out of your inbox stops one message, not the criminal behind it. A live webinar on 8 July 2026 sets out what disrupting a phishing campaign at its source actually requires.

Fake Tax Emails Are Planting Two Separate Spying Tools on Indian Taxpayers' Computers
A campaign timed to India's tax filing season tricks people into downloading what looks like an official government utility, and inside are two hidden programs that give criminals full remote control of the victim's machine.