#phishing
139 stories taggedphishing · page 9 of 10.

AI Agents in Phishing Tests: Risks and Failures Exposed
Autonomous AI agents can be tricked into leaking sensitive data, highlighting configuration issues in security frameworks.

Attackers Are Wrapping Old Phishing Tricks in AI Branding. It's Working.
Microsoft and Google both dropped advisories this week documenting how threat actors are dressing up familiar credential theft and malware campaigns as ChatGPT, Copilot, and DeepSeek experiences. The technique is not new. The success rate is.

AI-Generated Phishing Is Drowning SOC Queues. The Policy Response Is Lagging.
Tier 1 analysts face a volume problem that existing disclosure and reporting regimes were not built to absorb.

World Cup 2026 Phishing Infrastructure Is Already Stood Up
Lookalike FIFA domains, trojanized streaming apps, and credential harvesters are live weeks before kickoff. The pattern is familiar; the scale isn't.

TA4922 Broadens Phishing Sweep Into U.K., Germany, Italy and South Africa
The China-linked crew is rotating through ValleyRAT, Atlas RAT and freshly minted payloads at a pace researchers describe as unusually fast.

DesckVB RAT Campaign Routes Phishing Lures Through Google's DoubleClick Domain
Attackers are bouncing victims off a Google-owned ad redirect before landing them on attacker infrastructure — a trick that buys cover from filters trained to trust doubleclick.net.

ChatGPhish: When ChatGPT's Markdown Renderer Becomes a Phishing Vector
Permiso researchers show how implicit trust in Markdown links and images inside ChatGPT responses turns the assistant into a credible delivery surface for prompt injection and credential theft.

Three Stories You Probably Missed: Trump Mobile Leak, FIFA Phishing, and CISA's Supply Chain Cleanup
A customer data exposure, a tournament-themed phishing campaign, and a federal agency scrambling to respond to upstream compromise — a busy week for the incidents no one headlined.

MokN Banks $15M to Turn Phishing Infrastructure Against Attackers
The startup's decoy access-point platform tries to catch credential thieves in the act — before stolen logins get used.

GreyVibe's AI Playbook: What Russia-Linked Operators Are Actually Doing With ChatGPT and Gemini
A threat actor researchers are calling GreyVibe is reportedly weaving commercial AI tools into its attack workflow. The real story isn't the hype — it's the operational specifics.

AI's Role in the Battle of Stolen Credentials
Security teams grapple with AI-driven credential abuse, leaving many playing catch-up.

Grandoreiro Hits Spain Again, BTMOB Spreads on Android in Brazil
Two parallel banking trojan campaigns are pulling in victims across Iberia, Mexico, and Brazilian Android users. The lures are mundane. The payloads are not.

SOC Teams Are Running Out of Road Without AI, Manchester Panel Warns
Security practitioners gathered at DTX Manchester to debate machine-versus-machine warfare, alert fatigue, and why the fundamentals still matter before any AI switch gets flipped.

Kali365 Phishing Kit Hijacks Microsoft OAuth Tokens to Silently Bypass MFA
The FBI has flagged a device-code phishing campaign powered by Kali365, a toolkit that steals OAuth tokens tied to Microsoft 365 accounts without ever touching a user's password.

Kali365 and EvilTokens: The New Phishing-as-a-Service Threat
Professional phishing kits lower barriers for attackers, bypassing MFA with ease.