Phishing Attack

Threat Actors Target PayPal Users with New Account Profile Setup Scam

A new and sophisticated phishing campaign is currently targeting PayPal users, exploiting deceptive emails titled “Set up your account profile” to compromise accounts through a clever secondary user addition scheme. This scam uses advanced email spoofing and psychological manipulation to bypass traditional security measures, marking a notable evolution in online financial fraud. The fraudulent emails […]

Threat Actors Target PayPal Users with New Account Profile Setup Scam Read More »

add a heading

Hackers Exploit SendGrid Service to Steal User Login Credentials

A highly advanced phishing operation has been detected, abusing the trusted reputation of SendGrid to harvest user credentials. Attackers are using SendGrid’s legitimate cloud-based email service to distribute phishing emails that evade traditional email security filters. Campaign Overview This campaign relies on psychological manipulation and urgency tactics, with three crafted email themes designed to pressure

Hackers Exploit SendGrid Service to Steal User Login Credentials Read More »

add a heading (14)

AI Prompt Injection Powers New Gmail Phishing Attack to Bypass Security

Phishing has always relied on tricking people, but this latest campaign goes a step further. Instead of only targeting users, attackers are now attempting to manipulate AI-powered defenses as well. This operation builds on the Gmail phishing chain reported last week. That earlier campaign used urgency and link redirects, while this one introduces a new

AI Prompt Injection Powers New Gmail Phishing Attack to Bypass Security Read More »

add a heading (23)

Hackers Exploit ADFS and Office.com to Steal Microsoft 365 Credentials

A new and highly deceptive phishing campaign is targeting Microsoft 365 accounts by abusing Microsoft’s own Active Directory Federation Services (ADFS). The attackers redirect users from legitimate office.com links to malicious login pages, making the scam exceptionally hard to detect. Evolution of Phishing Attacks Researchers at cybersecurity firm Push Security revealed this tactic, describing it

Hackers Exploit ADFS and Office.com to Steal Microsoft 365 Credentials Read More »

add a heading (21)

Threat Actors Use GenAI to Craft Realistic Phishing Content

Cybercriminals are increasingly taking advantage of generative AI platforms to create advanced phishing campaigns that are much harder for traditional security systems to detect. The rapid growth of GenAI services has built an environment where attackers can easily generate realistic phishing emails, mimic trusted organizations, and scale attacks with very little technical skill required. Modern

Threat Actors Use GenAI to Craft Realistic Phishing Content Read More »

add a heading (4)

Back-to-School Shopping Scams Trick Users Into Fake Sites

Back-to-School Shopping Scams Surge as Cybercriminals Exploit Seasonal Rush As families nationwide gear up for the school season, cybercriminals are taking advantage of the increased demand for online shopping with a wave of advanced scams. Rising Online Threats During Seasonal Spending Criminals are leveraging higher shopping activity to launch malicious campaigns that target individuals searching

Back-to-School Shopping Scams Trick Users Into Fake Sites Read More »

add a heading (16)

New Gmail Phishing Attack Steals Credentials via Login Flow

A sophisticated phishing campaign is actively targeting Gmail users by exploiting legitimate Microsoft Dynamics infrastructure to bypass security protections and steal user credentials. The scam begins with deceptive “New Voice Notification” emails, appearing to come from trusted voicemail services. These messages include spoofed sender details and prominent “Listen to Voicemail” buttons that redirect victims through

New Gmail Phishing Attack Steals Credentials via Login Flow Read More »

add a heading (3)

AI Fuels New Trends in Phishing Attacks

AI-Powered Phishing and Scams Transforming the Cybersecurity Landscape The cybersecurity landscape is undergoing a major shift as artificial intelligence becomes a powerful tool for cybercriminals, reshaping traditional phishing and scam tactics. Unlike earlier phishing campaigns, which often contained obvious errors and warning signs, modern AI-driven attacks are sophisticated and challenging even for vigilant users to

AI Fuels New Trends in Phishing Attacks Read More »

add a heading (1)

Hackers Use Phishlet for FIDO Downgrade Attacks

FIDO Passkeys Face New Downgrade Attack Threat A new and highly sophisticated cyber threat has surfaced, targeting one of the most trusted authentication technologies in modern cybersecurity. FIDO-based passkeys, widely regarded as the gold standard for phishing-resistant authentication, are now vulnerable to an advanced downgrade attack. This technique forces users to abandon strong FIDO authentication

Hackers Use Phishlet for FIDO Downgrade Attacks Read More »

ClickTok Campaign Uses 10,000+ Malicious Domains to Target TikTok Shop Users

A new large-scale cybercrime operation known as ClickTok has surfaced, aiming at TikTok Shop users through a complex mix of phishing and malware distribution. Security researchers have discovered over 10,000 malicious domains involved in stealing login credentials and deploying spyware. The campaign marks a significant rise in e-commerce cyberattacks, leveraging the popularity of TikTok’s in-app

ClickTok Campaign Uses 10,000+ Malicious Domains to Target TikTok Shop Users Read More »