Friday, August 28, 2026
Follow on LinkedIn

Phishing

SpamGPT – AI-powered Attack Tool Used By Hackers For Massive Phishing Attack

A sophisticated new cybercrime toolkit named SpamGPT is enabling hackers to launch massive and highly effective phishing campaigns by combining artificial intelligence with the capabilities of professional email marketing platforms. Marketed on the dark web as a "spam-as-a-service" platform,...

New Gmail Phishing Attack With Weaponized Login Flow Steals Credentials

A sophisticated new phishing campaign targeting Gmail users through a multi-layered attack that uses legitimate Microsoft Dynamics infrastructure to bypass security measures and steal login credentials. The attack begins with deceptive "New Voice Notification" emails that appear to come from...

New Multi-Stage Tycoon2FA Phishing Attack Now Beats Top Security Systems

If you think phishing is just clicking a bad link and landing on a fake login page, Tycoon2FA will prove you wrong. This new wave of phishing-as-a-service isn’t playing the old game anymore; it’s running a 7-stage obstacle course...

How Certificate Mismanagement Opens The Door For Phishing And MITM Attacks

SSL certificates are used everywhere from websites and APIs to mobile apps, internal tools and CI/CD pipelines. While most teams know they’re important, they often don’t manage them well. Certificates are usually forgotten until something breaks. If they expire, get...

Authorities Arrested 14 Hackers in Connection With Large-Scale Tax Fraud Operation

Fourteen individuals have been arrested in a coordinated international operation targeting a sophisticated cybercriminal network responsible for large-scale tax fraud through phishing attacks and fraudulent benefit claims.  The arrests represent a significant breakthrough in combating cross-border financial cybercrime affecting thousands...

GitPhish – A New Tool that Automates GitHub Device Code Phishing Attack

GitPhish represents a significant advancement in automated social engineering tools, specifically targeting GitHub's OAuth 2.0 Device Authorization Grant implementation.  This open-source tool streamlines the traditionally complex process of executing device code phishing attacks, addressing critical operational challenges faced by security...

Tycoon2FA, EvilProxy, Sneaky2FA: How To Defend Against These Phishing Kit Attacks 

Phishing kits are evolving fast. Threat actors behind toolkits like Tycoon2FA, EvilProxy, and Sneaky2FA are getting smarter, setting up infrastructure that bypasses 2FA and mimics trusted platforms like Microsoft 365 and Cloudflare to steal user credentials without raising red...

AI Tools Like GPT Direct Users to Phishing Sites Instead of Legitimate Ones

The popular artificial intelligence tools, including GPT models and Perplexity AI, are inadvertently directing users to phishing websites instead of legitimate login pages.  The study found that when users ask these AI systems for official website URLs, over one-third of...

Microsoft Defender for Office 365 to Provide Detailed Results for Spam, Phishing or Clean Emails

Summary 1. Microsoft Defender for Office 365 is introducing large language model (LLM) technology to provide clear, human-readable explanations for why emails are classified as spam, phishing, or clean. 2. The feature will deploy automatically worldwide from late June to mid-July...

5 New Trends In Phishing Attacks On Businesses – Must Aware Threats

Phishing remains one of the most effective ways attackers infiltrate corporate environments. Today’s phishing campaigns are no longer just poorly written emails with obvious red flags. They’re sophisticated, well-disguised, and tailored to exploit trust in everyday tools your teams...

Latest News

Latest News