Phishing

New MessiahGPT AI Model Fueling Automated Ransomware and Phishing Attacks

A criminal AI service called MessiahGPT is being marketed on BreachForums as an uncensored platform for creating ransomware, phishing kits,…

2 weeks ago

Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

Three distinct Phishing-as-a-Service (PhaaS) platforms, Sneaky 2FA, EvilTokens, and EvilProxy, are actively targeting US organizations to steal Microsoft 365 (M365) credentials and…

3 weeks ago

AI-Generated Phishing No Longer Needs Malware: It Can Steal Your Session Inside the Browser

AI-generated phishing campaigns are rapidly evolving beyond traditional malware delivery, shifting the battleground directly into the web browser where attackers…

1 month ago

Authorities Shut Down Phishing Empire Launching 15,000 Attacks Every Month

Authorities dismantled Kratos, a major phishing-as-a-service operation behind around 15,000 monthly phishing campaigns, shutting down a global infrastructure used for…

1 month ago

Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accounts

Forg365 is a phishing-as-a-service platform that targets Microsoft accounts, combining AI-powered phishing, session theft, and post-compromise mailbox access in a…

2 months ago

SPF, DKIM, DMARC Passed. Malicious Link Passes Every Authentication Check, But CyberCheck360 Caught It

A $12 domain, 72 hours of patience, and your finance team's credentials — why authentication tells you who sent the…

3 months ago

FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA

The FBI has issued a new cybersecurity warning about a rapidly emerging phishing-as-a-service (PhaaS) platform named Kali365, which is actively…

3 months ago

Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace

Threat actors are rapidly shifting their intrusion tradecraft toward high-speed, SaaS-centric attacks that completely bypass traditional endpoint security. Since October…

4 months ago

Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign

A sophisticated cybercriminal operation dubbed "AccountDumpling" has compromised approximately 30,000 Facebook accounts worldwide. Discovered by Guardio Labs, this Vietnamese-linked campaign…

4 months ago

Attackers Hijacking Legitimate Websites to Attack Microsoft Teams users

A multi-vector phishing campaign using compromised WordPress sites to steal login credentials from Microsoft Teams and Xfinity users. By hijacking…

5 months ago