Phishing
Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked.
Hi, what are you looking for?
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets.
Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked.
Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations.
The attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages.
The decentralized prediction market said hackers targeted some of its users through a compromise of a third-party vendor.
The platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses.
MokN's platform deploys realistic decoy access points to lure attackers into revealing compromised credentials, enabling organizations to respond before abuse occurs.
Victims span across the aviation, critical infrastructure, energy, logistics, public administration, and technology sectors.
The malicious emails claim to contain a conduct report and lure victims to a Microsoft phishing website that leverages AitM.
Still under development, Bluekit provides users with automated domain registration and an AI Assistant.
Legitimate-looking emails coming from Robinhood systems lured recipients to phishing websites.
New analysis from Abnormal AI reveals how attackers have abandoned technical exploits to weaponize routine workflows and internal trust.
Threat actors are reusing Tycoon 2FA tools across other phishing kits following the platform’s disruption.
Attack volumes are back to pre-disruption levels, and the adversary tactics have remained unchanged.
Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser.
The attackers used a DKIM-signed phishing email, trusted redirect infrastructure, compromised servers, and Cloudflare-protected phishing pages, but the attack was unsuccessful.
Starbucks said the incident involved phishing attacks targeting an employee portal, affecting hundreds.