❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayIT Security

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

11 September 2026 at 08:48

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek.

Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools

9 September 2026 at 10:20

Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victims’ devices.

Both incidents, observed in August, began with phishing messages directing victims to attacker-controlled websites. The attackers then used a browser-in-the-browser (BiTB) technique to create what appeared to be a legitimate Adobe webpage, before convincing victims to download malicious software disguised as an Adobe Reader update.

Rather than deploying conventional malware, the attackers installed rogue instances of ScreenConnect, legitimate remote monitoring and management (RMM) software, giving them continued remote access to compromised endpoints.

Fake browser makes phishing harder to spot

BiTB attacks create a fake browser window inside a webpage using HTML, CSS and JavaScript. The window can replicate familiar features including an address bar, padlock and legitimate-looking URL, making traditional advice such as checking the web address less effective.

In the first attack, detected on 25 August, a victim clicked a link in a phishing email and was taken to a fake CAPTCHA page. They were subsequently presented with blurred documents and told they needed to download Adobe PDF Reader to view them.

The fake browser page appeared to show Adobe’s legitimate get.adobe.com address. However, the supposed Reader installer was actually ScreenConnect.

Once installed, the attackers deployed two rogue ScreenConnect clients, providing redundant routes for maintaining access. They then executed HideCursor.exe, a defence-evasion tool designed to conceal on-screen activity. Huntress intervened before the attack could progress further.

Second attack follows same playbook

Huntress identified another incident on 31 August involving the same Adobe Reader lure.

This time, the victim interacted with a malicious link delivered through AT&T Office@Hand, a legitimate communications service powered by RingCentral. The attackers again disguised ScreenConnect as an Adobe Reader update and installed two unauthorised instances.

The second ScreenConnect session was used to execute another defence-evasion binary, HideUL.exe. Microsoft Defender detected part of the activity, but the rogue ScreenConnect client still completed its installation before Huntress shut down the attack.

Legitimate tools remain attractive to attackers

The attacks demonstrate how threat actors can combine familiar phishing techniques with trusted software to make malicious activity harder to identify.

RMM abuse is a growing problem. Huntress’ 2026 Cyber Threat Report found RMM abuse increased 277% year on year and appeared in nearly a quarter of the incidents investigated by the company.

Huntress recommends organisations restrict who can install remote management tools, maintain an approved inventory of RMM software and monitor for new or unauthorised ScreenConnect clients. Employees should also be wary of unexpected software updates or file-viewing prompts, even when a webpage appears to display a legitimate address.

Read the full research here.Β 

The post Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools appeared first on IT Security Guru.

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

9 September 2026 at 06:00

Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block.

The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek.

Post-DEF CON phishing campaign delivered AMOS and NetSupport malware

24 August 2026 at 03:42
A phishing campaign targeting attendees of Black Hat and DEF CON conferences involved distributing information-stealing malware and remote access malware via a malicious Google Doc and fake DocSend installers for macOS and Windows. The Huntress team learned about the phishing attack after one of its researchers received a direct message on X on August 9. [...]

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

21 August 2026 at 10:22

Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked.

The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek.

Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave

28 July 2026 at 20:00
Between January and June 2026, TrendAIβ„’ tracked more than 35,000 fake sites exploiting the 2026 FIFA World Cup, spanning counterfeit merchandise shops, cloned ticket pages, and bogus free-streaming sites, which together drew roughly 1.48 million visits from Japan.

13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan

22 July 2026 at 20:00
We analyzed a sustained tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets.

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass

Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement.

Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards

14 July 2026 at 12:28

New research from Forescout has uncovered a sophisticated phishing campaign that uses fake seasonal eCard invitations to trick victims into installing legitimate remote management software, giving attackers long-term access to compromised devices.

The campaign, dubbed SeasonalInvite by Forescout Research’s Vedere Labs, has been active since at least January 2026 and demonstrates how cybercriminals are increasingly combining social engineering, trusted enterprise software, and AI assisted development techniques to evade traditional security defences.

The full research is available here: SeasonalInvite research

Fake eCards lure victims

According to the report, the attackers use phishing emails disguised as seasonal eCard invitations to persuade users to install legitimate Remote Monitoring and Management (RMM) tools.

Rather than deploying traditional malware, the campaign abuses commercially available software that is commonly used by IT administrators for remote support. Once installed, the tools provide attackers with persistent remote access to compromised systems.

The campaign targets both Windows and macOS users.

During its investigation, Forescout confirmed the abuse of four legitimate RMM platforms:

  • ConnectWise ScreenConnect
  • LogMeIn Resolve
  • Kaseya
  • O&O Syspectr

Because these applications are widely trusted within enterprise environments, they are less likely to trigger traditional security controls.

Hundreds of phishing domains identified

Researchers identified a large infrastructure supporting the campaign, including 959 domains themed around electronic greeting cards.

The attackers also operated a sophisticated Traffic Distribution System (TDS) consisting of 2,658 gate pages. The infrastructure was designed to direct legitimate victims to phishing websites while preventing automated security scanners from detecting malicious content.

According to Forescout, this approach makes the campaign significantly harder for security researchers and automated detection systems to identify.

Evidence points to AI generated phishing pages

One of the report’s most notable findings is evidence suggesting the phishing kit itself was created with the assistance of artificial intelligence.

Researchers found indicators that the phishing pages contained AI generated code, leading them to believe the threat actor used a large language model to build delivery pages and quickly adapt the campaign over time.

The findings reflect a growing trend of cybercriminals using AI to accelerate phishing operations, reduce development time, and rapidly generate convincing attack infrastructure.

Trusted software becomes the attack vector

Forescout said SeasonalInvite demonstrates how attackers are shifting away from custom malware in favour of abusing legitimate enterprise tools that organisations already trust.

By combining social engineering with legitimate remote management software and AI assisted development, threat actors can bypass many traditional endpoint security controls while maintaining long-term access to victim devices.

The researchers warn that organisations should not rely solely on malware detection to identify these attacks. Instead, they recommend monitoring for the unauthorised installation and use of remote management tools, strengthening phishing awareness training, and implementing controls that can detect suspicious behaviour rather than simply malicious files.

As attackers continue to refine their techniques, campaigns like SeasonalInvite highlight how trusted software and artificial intelligence are becoming powerful tools in the modern cybercriminal’s arsenal.

The post Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards appeared first on IT Security Guru.

❌
❌