❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayHacking and InfoSec

FBI Alert: OAuth Consent Phishing is Targeting Users of Messaging Apps

11 September 2026 at 16:00

The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting β€œprominent victims, their family members, and personal acquaintances.”

OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.

Survey: Companies Cite Phishing as their Top AI-Enabled Fraud Concern

11 September 2026 at 12:00

A recent survey from Experian found that 60% of companies report fraud losses that are β€œsomewhat or significantly higher” than in previous years, with a majority of respondents citing AI-generated phishing attacks as their top AI-related fraud concern.

Phishing Campaign Targets Employees with Malicious SVG Files

11 September 2026 at 09:00

Researchers at INKY observed a major phishing campaign that used SVG (Scalable Vector Graphics) image files to deliver malicious JavaScript. While abuse of SVG files isn’t new, INKY says their use in phishing campaigns has exploded over the past year.

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

10 September 2026 at 06:57

A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and disrupted, this campaign delivers malicious content assembled only after a user follows the attack chain. A blob URL is a […]

The post New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials

7 September 2026 at 07:59

A large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly personalized credential-harvesting pages, and, in some cases, install ScreenConnect remote-access software. The campaign’s central advantage is that it presents trusted Google-owned domains at nearly every point a gateway, proxy, or analyst is likely to […]

The post Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud

By: Divya
4 September 2026 at 07:32

Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help organizations reduce phishing and fraud risks associated with malicious QR code campaigns. Listed under Microsoft 365 Roadmap ID 570439, this feature is currently in development and is scheduled for rollout in […]

The post Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes

3 September 2026 at 08:12

QR code phishing, widely known as β€œquishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather than placing clickable links directly in emails. The shift is helping attackers bypass traditional secure email gateways and move victims from managed corporate devices to less-protected smartphones. The company recorded an average of […]

The post QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning

3 September 2026 at 07:14

QR-code phishing, commonly known as quishing, is evolving beyond image-based payloads. Threat actors are now rendering scannable QR codes directly from HTML tables or text within email bodies, leaving no image attachment, embedded bitmap, or <img> element for traditional email scanners to inspect. The technique targets a structural blind spot in Secure Email Gateways (SEGs). […]

The post HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Recruitment-Themed Phishing Campaign Targets Enterprise Users

2 September 2026 at 16:30

Researchers at Zimperium are tracking widespread phishing campaigns that use Browser-in-the-Browser (BitB) attacks to trick users into handing over their enterprise credentials. The attackers impersonate real HR employees at major companies and target job seekers with extremely realistic interview processes.

New Phishing Kit Uses AI to Fully Automate Vishing Attacks

2 September 2026 at 12:00

A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB.

The phishing platform, called β€œBalonx,” includes a module dubbed β€œCallFlow” that the researchers say β€œrepresents a fundamental evolution” in the phishing-as-a-service market. This module uses four commercial AI services to conduct the attacks: OpenAI’s GPT-4o-mini, ElevenLabs’s AI voice generator, OpenAI Voice, and OpenAI Whisper.

Hacking the Healers: New KnowBe4 Whitepaper Highlights Record Security Breaches in Healthcare

2 September 2026 at 07:00

When an organization has a security breach, it can cause significant financial, reputationalΒ and logistical damage. But in healthcare, where patient lives are on the line, the consequences can be much more catastrophic.

KnowBe4’s latest whitepaper on healthcare cybersecurity, β€œHacking the Healers: How the Digital Workforce Became Cybersecurity's Frontline,” examines how decentralized clinical operations, remote staff and autonomous AI agents have dissolved traditional network perimeters, leaving healthcare organizations and patient safety vulnerable to targeted cyberattacks.

Warning: Replying to a β€œWrong Number” Text Marks You as a Target for Scams

28 August 2026 at 16:00

Attackers are using β€œwrong-number” texts to identify potential targets for scams, according to researchers at Malwarebytes.

These texts appear to be harmless messages meant for another person, such as β€œAre we still on for dinner tomorrow?” or β€œWhere’s the PowerPoint?” Recipients often try to be helpful by replying to let the person know they’ve got the wrong number. This reply, however, informs the threat actor that the phone number is active and marks it for future scams.

❌
❌