A sophisticated new cybercrime toolkit named SpamGPT is enabling hackers to launch massive and highly effective phishing campaigns by combining artificial intelligence with the capabilities of professional email marketing platforms.
Marketed on the dark web as a "spam-as-a-service" platform,...
A sophisticated new phishing campaign targeting Gmail users through a multi-layered attack that uses legitimate Microsoft Dynamics infrastructure to bypass security measures and steal login credentials.
The attack begins with deceptive "New Voice Notification" emails that appear to come from...
If you think phishing is just clicking a bad link and landing on a fake login page, Tycoon2FA will prove you wrong. This new wave of phishing-as-a-service isn’t playing the old game anymore; it’s running a 7-stage obstacle course...
SSL certificates are used everywhere from websites and APIs to mobile apps, internal tools and CI/CD pipelines. While most teams know they’re important, they often don’t manage them well.
Certificates are usually forgotten until something breaks. If they expire, get...
Fourteen individuals have been arrested in a coordinated international operation targeting a sophisticated cybercriminal network responsible for large-scale tax fraud through phishing attacks and fraudulent benefit claims.
The arrests represent a significant breakthrough in combating cross-border financial cybercrime affecting thousands...
GitPhish represents a significant advancement in automated social engineering tools, specifically targeting GitHub's OAuth 2.0 Device Authorization Grant implementation.
This open-source tool streamlines the traditionally complex process of executing device code phishing attacks, addressing critical operational challenges faced by security...
Phishing kits are evolving fast. Threat actors behind toolkits like Tycoon2FA, EvilProxy, and Sneaky2FA are getting smarter, setting up infrastructure that bypasses 2FA and mimics trusted platforms like Microsoft 365 and Cloudflare to steal user credentials without raising red...
The popular artificial intelligence tools, including GPT models and Perplexity AI, are inadvertently directing users to phishing websites instead of legitimate login pages.
The study found that when users ask these AI systems for official website URLs, over one-third of...
Summary
1. Microsoft Defender for Office 365 is introducing large language model (LLM) technology to provide clear, human-readable explanations for why emails are classified as spam, phishing, or clean.
2. The feature will deploy automatically worldwide from late June to mid-July...
Phishing remains one of the most effective ways attackers infiltrate corporate environments. Today’s phishing campaigns are no longer just poorly written emails with obvious red flags.
They’re sophisticated, well-disguised, and tailored to exploit trust in everyday tools your teams...