❌

Reading view

There are new articles available, click to refresh the page.

Attackers Exploit AI Hallucinations to Send Users to Phishing Sites

Threat actors are using a new technique called β€œphantom squatting” to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networks’ Unit 42.

Since AI models frequently hallucinate phony information, they sometimes point users to websites that don’t exist. Threat actors are now registering these AI-hallucinated domains and using them to host phishing sites.

Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers

Authorities from Germany, the United States, and Indonesia have dismantled the central infrastructure of Kratos, a major phishing-as-a-service (PhaaS) platform that enabled cybercriminals worldwide to conduct large-scale credential-harvesting campaigns. The operation, announced by Germany’s Federal Criminal Police Office (BKA) and the Frankfurt am Main Public Prosecutor’s Office’s Central Office for Combating Internet Crime (ZIT), resulted […]

The post Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials

Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather than just endpoints. Recent activity shows tightly integrated social engineering, cloud abuse, and fileless PowerShell tradecraft that significantly complicate detection and response. APT42, also tracked as TA453 in some reporting, is […]

The post Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Kratos PhaaS Targets Microsoft 365 Users With SharePoint Links and Cloudflare Anti-Bot Checks

Kratos, a subscription-based phishing-as-a-service platform, is targeting Microsoft 365 users in the United States, Europe, and other regions through campaigns designed to blend into ordinary document-sharing workflows. The operation abuses trusted services, including Microsoft SharePoint, OneDrive, Microsoft Forms, Canva, Tilda, and systeme.io, to deliver links that ultimately redirect recipients to credential-harvesting pages. Only 156 sessions […]

The post Kratos PhaaS Targets Microsoft 365 Users With SharePoint Links and Cloudflare Anti-Bot Checks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Report: Social Engineering Remains a Central Part of AI-assisted Attacks

Threat actors continue to rely on social engineering as AI is incorporated into their attacks, according to ESET’s Threat Report for the first half of 2026.

ESET’s Director of Threat Prevention Labs, JiΕ™Γ­ KropÑč, stated, β€œRather than relying on entirely new methods and tools, attackers are quickly adapting established techniques to new platforms, technologies, and user behaviors. The number of AI skills within this new ecosystem is growing rapidly as we speak, further expanding the attack surface.”

❌