Cloaked SEO poisoning attacks surged by 40% in the second quarter of 2026, according to researchers at Fortra. This tactic, also known as βChameleon SEO poisoning,β uses cloaked search engine results to spread phishing sites.
Normal view
Warning: Chameleon SEO Poisoning Spreads Phishing Pages
The .vu Surge: How Threat Actors Are Exploiting Vanuatu's Domain Extension
New Phishing Kit Gives Threat Actors Live View Into Attacks
A new phishing platform called βJWRβ gives attackers real-time control over social engineering attacks, according to researchers at Cisco Talos. The kit livestreams the phishing page to the attacker as the victim is entering information, allowing the attacker to steer the victimβs experience and maximize the damage.
Voice Phishing Attacks Target Hedge Fund Employees
Googleβs Threat Intelligence Group (GTIG) is tracking a voice phishing (vishing) campaign thatβs targeting hedge funds and financial firms. The researchers attribute the attacks to βUNC6671,β an extortion group formerly known as βBlackFile.β The attackers pose as IT staff informing employees of urgent, mandatory migrations.
Warning: Malicious AI Tools Are Spreading in the Criminal Underground
Report: Phishing Remains the Primary Initial Access Vector
Phishing is still the top initial access vector, accounting for more than half of cyberattacks observed during Q2 2026, according to a new report from Cisco Talos.
Report: Vishing and Device Code Phishing Are Surging
Social engineering remains a central part of modern cyberattacks, according to a new report from CrowdStrike. Attackers are increasingly turning to voice phishing because it bypasses traditional security controls and leaves little forensic evidence, since the social engineering takes place over the phone.
North Korean Hackers Target LinkedIn Users With Fake Job Offers
Microsoft Observed 7.6 Billion Phishing Emails in Q2 2026
Researchers at Microsoft warn that phishing emails are still the top initial access vector, with more than 2 billion phishing threats detected each month during the second quarter of 2026.
Warning: Compromised Hotel Routers Send Users to Phishing Sites
Attackers are using compromised hotel Wi-Fi routers to redirect users to Microsoft 365 phishing sites, according to researchers at ReliaQuest. The attacks were observed in multiple U.S. cities, as well as across India and Saudi Arabia. These types of DNS poisoning attacks can send users to phishing sites with very little evidence that something suspicious has taken place.
Iranian APT Launches AI-Assisted Spear Phishing Attacks
The Iran-linked threat actor APT42 is using AI-assisted phishing attacks to target U.S. organizations amidst the Iran-US war, according to researchers at DarkAtlas.
Why You Canβt Arrest Your Way Out of Youth Cybercrime
The Blind Spot: How βBulletproofβ Phishing Redirectors Slip Past SEGs
By Shikhar Dalela and Jeewan Singh Jalal
The operators named the kit themselves.
Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called β/.bulletproofβ, and the PHP session cookie the kit sets on every visitor is named βbp_redir_sess.β The βbpβ stands for bulletproof, which is an unusual degree of candor from a threat actor whose entire design philosophy is concealment.
Inside the OS-Aware Phishing Kit Profiling Your Device
-
KnowBe4 Security
- Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation
Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation
Security operations teams face a constant balancing act: stopping sophisticated email threats, maintaining visibility across their attack surface and keeping administrative workflows running smoothly. When security tools operate in silos or rely on rigid, manual processes, friction builds up quickly. This friction consumes valuable time that analysts could spend on higher-priority initiatives.
New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication
Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called βJalisco,β is a device code phishing platform that pairs with AI-powered phishing-as-a-service platforms like EvilTokens to provide fresh OAuth codes in real time.
Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo
Scammers can use AI tools to find your location in photos you post to social media, according to researchers at McAfee. This information can then be used in targeted social engineering attacks. The researchers found that free AI models can correctly identify a photoβs location with around 90% accuracy.