❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 15 September 2026KnowBe4 Security

Phishing Emails Use New Technique to Bypass Microsoft 365 Security Filters

15 September 2026 at 12:00

Threat actors are using phishing emails with blank SMTP sender fields to bypass Microsoft 365 security filters, according to researchers at ReliaQuest.

Microsoft 365 Exchange Online uses a feature called β€œRejectDirectSend” to block unauthenticated Direct Send emails from an organization’s trusted domain. If an attacker omits the domain field from these emails, however, RejectDirectSend will no longer block the messages. Attackers can therefore exploit this technique to impersonate internal users.

Yesterday β€” 14 September 2026KnowBe4 Security

Social Engineering Campaign Uses Phony NDAs to Avoid Detection

14 September 2026 at 12:00

Researchers at Gen Digital are tracking a sophisticated social engineering campaign that’s using phony NDA documents to trick employees into moving the conversation to WhatsApp and personal email accounts. The attackers targeted an employee at Gen itself, but the employee recognized that it was a scam and played along to see what the attackers would do.

Warning: β€œSlop Squatting” Directs AI Users to Phishing Pages

14 September 2026 at 09:00

Threat actors are increasingly leveraging AI hallucinations to plant phishing links and other malicious content in AI output, IEEE Spectrum reports. Large language models (LLMs) sometimes fabricate information, including web domains, when answering users’ questions. Attackers are registering these hallucinated web domains to host phishing pages.

Before yesterdayKnowBe4 Security

New Phishing Kit Gives Threat Actors Live View Into Attacks

28 August 2026 at 09:00

A new phishing platform called β€œJWR” gives attackers real-time control over social engineering attacks, according to researchers at Cisco Talos. The kit livestreams the phishing page to the attacker as the victim is entering information, allowing the attacker to steer the victim’s experience and maximize the damage.

Voice Phishing Attacks Target Hedge Fund Employees

27 August 2026 at 17:00

Google’s Threat Intelligence Group (GTIG) is tracking a voice phishing (vishing) campaign that’s targeting hedge funds and financial firms. The researchers attribute the attacks to β€œUNC6671,” an extortion group formerly known as β€œBlackFile.” The attackers pose as IT staff informing employees of urgent, mandatory migrations.

Report: Vishing and Device Code Phishing Are Surging

21 August 2026 at 09:00

Social engineering remains a central part of modern cyberattacks, according to a new report from CrowdStrike. Attackers are increasingly turning to voice phishing because it bypasses traditional security controls and leaves little forensic evidence, since the social engineering takes place over the phone.

Warning: Compromised Hotel Routers Send Users to Phishing Sites

14 August 2026 at 16:00

Attackers are using compromised hotel Wi-Fi routers to redirect users to Microsoft 365 phishing sites, according to researchers at ReliaQuest. The attacks were observed in multiple U.S. cities, as well as across India and Saudi Arabia. These types of DNS poisoning attacks can send users to phishing sites with very little evidence that something suspicious has taken place.

The Blind Spot: How β€œBulletproof” Phishing Redirectors Slip Past SEGs

10 August 2026 at 12:00

By Shikhar Dalela and Jeewan Singh Jalal

The operators named the kit themselves.

Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called β€œ/.bulletproof”, and the PHP session cookie the kit sets on every visitor is named β€œbp_redir_sess.” The β€œbp” stands for bulletproof, which is an unusual degree of candor from a threat actor whose entire design philosophy is concealment.

Inside the OS-Aware Phishing Kit Profiling Your Device

30 July 2026 at 09:00

Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal

Most phishing attacks pick a target and commit to a tactic. This one picks the tactic based on the target, which happens dynamically, per device, in milliseconds, without the victim ever knowing a decision was made.

Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation

23 July 2026 at 17:00

Security operations teams face a constant balancing act: stopping sophisticated email threats, maintaining visibility across their attack surface and keeping administrative workflows running smoothly. When security tools operate in silos or rely on rigid, manual processes, friction builds up quickly. This friction consumes valuable time that analysts could spend on higher-priority initiatives.

❌
❌