-
Threat actors are increasingly impersonating OpenAI’s ChatGPT service in credential-phishing campaigns, exploiting the growing use of generative AI across both enterprise and personal environments. A recently observed campaign uses a fraudulent subscri…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale SMS phishing campaign is impersonating T-Mobile and warning recipients that their “rewards points” are about to expire, using fabricated balances, urgent deadlines, and lookalike redemption links to steal sensitive information. Security r…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale SMS phishing campaign linked to the Smishing Triad is using a sophisticated phishing kit dubbed JWR to harvest payment-card data, one-time passwords, online-banking credentials, identity information, and digital-wallet logins. Group-IB at…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Phishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated domains, and multi-stage URL cloaking designed to defeat conventional email inspection. The continuously running VBSpam…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The UK government has started implementing passkey authentication for GOV. UK One Login,UK One Login, providing over 23 million users with a faster and more secure way to access public services. This initiative aims to reduce reliance on passwords and …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and dis…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly personalized credential-harvesting pages, and, in some cases, install ScreenConnect remote-access so…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help organizations reduce phishing and fraud risks associated with malicious QR code campaigns. Listed under Micr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather than placing clickable links directly in emails. The shift is helping attackers bypass tradition…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
QR-code phishing, commonly known as quishing, is evolving beyond image-based payloads. Threat actors are now rendering scannable QR codes directly from HTML tables or text within email bodies, leaving no image attachment, embedded bitmap, or <img&#…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


