phishing
120 stories on phishing, newest first, from 132 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting. Where several outlets covered the same event, the rest sit under it as extra coverage.
- New Lunex Stealer Uses Fake CAPTCHA Pages and a Vulnerable AMD Driver to Blind Security Tools
- Voice Phishing Scam Impersonates Google Security Team, Recruiter Ad Blunders Expose the Trick
-
New Android Trojan 'RemControl' Hijacks Devices to Steal Banking Details
Also covered by The Hacker News
- Researchers Spot AliExpress Phishing Domains Weeks Before They Went Live
- 'Salesbleed' Flaw Shows How AI Agents Can Be Tricked Into Launching Phishing Attacks
- Beware the '$300 Consultation': How Fake Job Offers Are Used to Steal Corporate Secrets
- Fake Logistics Apps Hide 'Corp MDM' Spyware That Steals SMS and Hijacks Calls
- Hackers Are Poisoning AI Chatbot Answers to Spread Phishing Links
-
Cloudflare and Microsoft Take Down AI-Powered Phishing Service Targeting Australian Businesses
Also covered by The Register
- Microsoft Takes Down Major Phishing Service Targeting Microsoft 365 Accounts
- Another China-Linked Hacking Group Caught Exploiting Chrome and Windows Zero-Days
- Microsoft and UK Police Dismantle AI-Powered 'EvilTokens' Cybercrime Platform
- Microsoft Dismantles 'EvilTokens' AI-Powered Fraud Platform Linked to 12,000 Hacked Inboxes
- Businesses Rush to Adopt AI Security Tools, But Few Have a Plan for AI-Related Incidents
- Nearly Half of CISOs Report Deepfake Attacks: Time to Update Your Response Plan
- New 'Exvicy' ClickFix Toolkit Spreads Malware Through Hacked WordPress Sites
- New TASK#STOMP Malware Campaign Steals Documents, Wi-Fi Passwords and Clipboard Data
- Scammers Exploit Revolut Data Breach with Fake Identity-Check Texts
- Russia Claims Thousands of Cyberattacks Hit Its Election Systems, but Evidence Is Thin
- New Android Malware 'RatHat' Uses AI and Debug Tools to Keep Control After Uninstall
- New 'RatHat' Android Malware Uses AI to Steal Banking Details
- New Phishing Kit 'N0va' Hijacks Logins by Abusing Real Authentication Systems
- China-Linked Hackers Chain Chrome and Windows Zero-Days to Deploy New Backdoor
- Revolut Breach: Hackers Impersonating Government Agency Leak Customer Data, Demand Huge Ransom
- Chinese-Language 'Guarantee Marketplaces' Fuel Phishing and Money Laundering Networks
- Swiss Bitcoin Pay Takes Servers Offline After Customer Data Breach
- Fake Government Websites Used to Scam Users in Central Asia
-
Revolut Breach Shows How Fake Government Requests Can Trick Even Fintechs
Also covered by Cryptonews
- UK Government Rolls Out Passkeys to 23 Million Users, Ditching Passwords for Good
- Underground Forum Advertises 'Uncensored' AI Tool Built for Cybercrime
- Microsoft Warns of AI-Powered CEO Fraud and Passkey Phishing Targeting Cloud Accounts
- Brevo Email Platform Breach Sparks Phishing Warnings Across Crypto Industry
- LHC Group Data Breach Exposes Patient Records, Legal Scrutiny Follows
- AI Lets Scammers Send 1 Million Personalized Fraud Emails in Days
- Why AI Chatbots Are Becoming Dangerously Good at Scamming People
- Russian State-Backed Hackers Used Claude AI to Automatically Rebuild Detected Malware
- Phishing Campaign Exploits Microsoft 365 Direct Send Feature, Mimics Business Hours
- Fake Browser Extensions Caught Stealing Crypto Wallet Data and Login Tokens
- Fake Trezor 'Security Alert' Email Is a Phishing Scam, Not a Real Bug
- Trezor Warns of Phishing Emails Sent Through Hacked Email Provider
- BlueMoon Exploit Kit Spreads Across Multiple State-Backed Spy Groups
- Phishing Scam Hides Behind Trusted Google Links to Steal Credentials
- ClickFix Scams Evolve: Attackers Abuse Trusted Services to Stay Hidden
- Chinese-Language Hackers Hijack Government Servers to Power Gambling Phishing Network
- New Phishing Service 'BigBear 2.0' Bypasses MFA, Steals Over 5,000 Microsoft Logins
- Trezor Data Breach Grows Nearly Fivefold to 81,000 Affected Customers
- Fake IT Help Desk Calls Used to Steal Microsoft 365 Logins and Extort Executives
- Worm-Like Attack Turns ScreenConnect Into a Malware Delivery Chain
- Trezor Reveals Further 67,000 Customers Affected by ShipMonk Data Breach
- Phishing Campaign Uses Invisible Characters to Slip Past Email Filters
- Phishing Kits, Dropbox Breach and OAuth Tricks: Weekly Threat Roundup
- Phishing-as-a-Service Operation Rebounds Days After Global Takedown
- Global Phishing Campaign Abuses Remote Access Tools — US Now the Top Target
-
Russian National Extradited Over Malware Scheme Targeting Freelance Platform Users
Also covered by The Hacker News
-
Chinese-Speaking Hackers Hijack Brazilian Government Sites for Gambling SEO Scam
Also covered by Check Point Research
- Voice Phishing Scam Uses Microsoft Teams to Break Into Business Networks
- AI Is Supercharging Cyberattacks — Here's What Small Businesses Can Do Now
- Weekly Threat Roundup: Massive IoT Botnet, Water System Attacks, and Fake Software Traps SMBs Should Know About
- Russian State-Backed Hackers Target EU Officials Through Signal and WhatsApp
- New Malware Campaign Disables Security Software Using a Trusted Driver
- Hidden Code, Hidden Danger: How Attackers Use JavaScript Obfuscation to Power Phishing Kits
- Russian State Hackers Target European Diplomats with New Backdoor Malware
- New Phishing Toolkit 'NovaCookies' Hijacks Microsoft 365 Logins via Fake Docusign Alerts
- 'NovaCookies' Phishing Kit Lets Criminals Hijack Microsoft 365 Accounts for $320 a Month
- AI Voice Scam Targets Stolen iPhone Owners to Bypass Apple's Security Lock
- AI Email Summaries Can Be Manipulated by Hidden Malicious Code
- Phishing Kit 'Mirage2FA' Bypasses Two-Factor Authentication, Hits 4,500 Companies
- Fake npm Packages Used to Host Phishing CAPTCHA Scams
- Cybersecurity Firm ReliaQuest Hit by Phishing Attack, Says Damage Was Contained
- New Malware Loaders WordlistLoader and SynkLoader Target Windows Users
- Chinese Hackers Use Fake Graduation Invites to Breach Myanmar Government Systems
-
SafePal Breach Exposes Data of Nearly 40,000 Customers
Also covered by Crypto Economy, Bitcoin, Cryptopolitan, The Block, Crypto news, Bitcoin Magazine
- New Phishing Toolkit Turns Passkeys Against You—Even After You Reset Your Password
- Expired Website Domain Used to Steal Over $1,000 ETH in Tornado Cash Phishing Attack
- Suspected Russian Hackers Exploit Google and WhatsApp Login Features to Hijack Accounts
- Russian State-Linked Hackers Exploit Login Systems to Target High-Profile Individuals
- Hackers Are Hijacking Trusted Work Chat Tools to Steal Logins
- 40 Fake Firefox Extensions Found Stealing Cryptocurrency Wallet Data
- Phishing Scam Drains Over $1,000 ETH from Cryptocurrency User
- Unfiltered AI Tool 'Kriminal' Raises Alarms as Cybercrime Enabler
- Phishing 3.0: When AI Attackers Meet AI Defenders
- Massive Credential Theft Targets Microsoft Entra Users: What SMBs Need to Know
- SafePal Breach Exposes 39,000 Users, Fueling Phishing Fears
- SafePal Crypto Wallet Data Exposure Puts 40,000 Users at Phishing Risk
- Crypto Wallet Maker SafePal Confirms Data Breach Affecting 40,000 Customers
- French Tax Data Breach Exposes 678,000 Individuals and Businesses, Raising Bitcoin-Theft Fears
- Cybercriminals Spend Millions Buying Expired Domains to Spread Scams and Malware
- French Tax Data Breach Puts 678,000 Taxpayers at Risk of Scams
- Fake Google Ad Costs Crypto Trader $550,000 in Phishing Scam
- Fake Job Interview Pages Used to Steal Google and Facebook Logins in Global Phishing Campaign
- RingCentral Data Breach May Have Exposed 1.6 Million Users' Personal Information
- Trezor Warns 14,000 Customers After Data Breach at Shipping Partner ShipMonk
-
Fake Google Ad Scams Crypto User Out of $550,000
Also covered by The Block
- Crypto Investor Loses $550,000 to Fake Google Ad Phishing Scam
- New Phishing Toolkit Mimics Popular Checkout and Login Pages
- What Sherlock Holmes Can Teach Us About Social Engineering
- North Korean Hackers Go Offline with Custom AI to Supercharge Cyberattacks
- Levi Strauss Confirms Data Theft After Social Engineering Attack
- Hidden CSS Tricks in Emails Can Steal Passwords Across Major Webmail Platforms
- New Mac Malware Uses Fake 'Fix It' Prompts to Steal Crypto and Passwords
- Fake IT Help Desk Calls Used to Steal Corporate Cloud Data, Researchers Warn
- Weekly Roundup: Low-Quality AI Bug Reports, Port Cyberattacks, and Wall Street Targeted by Hackers
- Bitcoin Users Targeted: Trezor Phishing Ad and BTCPay Server Flaw Under Active Attack
- Hackers Use Fake CAPTCHAs and Blockchain Tricks to Spread Malware
- Fake CAPTCHA Scam Uses Blockchain to Deliver Malware
- Phishing Attack Hijacks Microsoft 365 Accounts to Spy on Payroll and Finance Emails
- North Korean Hackers Hijack Telegram Accounts to Target Crypto Professionals
- Fake XRP Airdrop Scams Target Crypto Investors, Foundation Warns
- Google Warns of Hackers Using Phone Calls and Fake Websites to Target Financial Firms
- Same Scammers, New Names: Vishing Extortion Gang Rebrands to Evade Detection
- Fake 'ClickFix' Sites Now Screen Visitors Before Delivering Mac Malware
- New Phishing Kit 'Kali365' Tricks Users Into Approving Attacker Logins on Real Microsoft Pages
- Popular Phishing Toolkit Now Bypasses MFA Using a New Trick
- Beware Fake Adobe and Zoom Update Pop-Ups Hiding Remote Access Malware
- AI 'Vibe Hacking': How Cybercriminals Are Using AI as a Built-In Hacking Assistant
- New Russian 'DOUBLECUP' Malware Service Hides Malicious Code in Cached Images
- Device Code Phishing Surges 1,500% as Attackers Bypass Traditional Security Controls
- Fake XRP Staking Sites Drain Millions from Cryptocurrency Investors
- Phishing Scam Targets XRP Cryptocurrency Users with Fake Websites
- Russian State-Backed Hackers Target Zimbra Email Users in Phishing Campaign