Cybersecurity researchers at Infoblox Threat Intel have uncovered a highly sophisticated phishing campaign that exploits the foundational plumbing of the internet to bypass enterprise security controls.
In a novel evasion tactic, threat actors are weaponizing the .arpa top-level domain (TLD) and...
Microsoft Defender researchers have exposed a sophisticated adversary-in-the-middle (AiTM) phishing campaign targeting energy sector organizations through SharePoint file-sharing abuse.
The multi-stage attack compromised multiple user accounts and evolved into widespread business email compromise (BEC) operations across several organisations.
Initial Compromise...
Analysts have numerous options for probing phishing attacks, but a single malware analysis sandbox often suffices.
Blending static and dynamic analysis, these tools excel against even the most elusive phishing threats. Discover five top sandbox solutions to elevate your...
March 2026 delivered a surge in cyber threats targeting users and organizations alike from banking apps hijacked to siphon personal data, to trusted domains exploited for phishing redirects.
Cybercriminals unleashed increasingly cunning and perilous tactics. Here's a breakdown of...
Cybersecurity researchers have uncovered a dangerous new phishing campaign that tricks users into surrendering their credentials by impersonating legitimate Google support and notifications.
The attack combines vishing (voice phishing), spoofed domains, and Google's own trusted infrastructure to achieve exceptional success...
Anti-phishing tools deliver critical protection by detecting and thwarting phishing campaigns in real time. They block deceptive emails, malicious websites, and messages seeking credentials, credit card details, or personal data.
Leveraging machine learning, advanced algorithms, and threat intelligence, these...
Hackers have launched a sophisticated phishing campaign exploiting Google Tasks notifications to target over 3,000 organizations worldwide, primarily in the manufacturing sector.
The December 2025 attacks signal a dangerous shift in email-based threats, in which attackers abuse legitimate Google infrastructure...
A sophisticated new phishing attack technique called "ConsentFix" that combines OAuth consent phishing with ClickFix-style prompts to compromise Microsoft accounts without requiring passwords or multi-factor authentication.
The attack leverages the Azure CLI app to gain unauthorized access to victim accounts.
The...
The National Cyber Security Centre (NCSC) has unveiled a new pilot program designed to help organizations identify and fix security weaknesses before malicious actors can exploit them.
Known as the Proactive Notifications Service, this initiative responsibly reports vulnerabilities directly to system...
Threat actors are leveraging Microsoft Azure Blob Storage to craft highly convincing phishing sites that mimic legitimate Office 365 login portals, putting Microsoft 365 users at severe risk of credential theft.
This method exploits trusted Microsoft infrastructure, making the attacks...