Reading view

There are new articles available, click to refresh the page.

FBI Alert: OAuth Consent Phishing is Targeting Users of Messaging Apps

The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting “prominent victims, their family members, and personal acquaintances.”

OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and disrupted, this campaign delivers malicious content assembled only after a user follows the attack chain. A blob URL is a […]

The post New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools

Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victims’ devices.

Both incidents, observed in August, began with phishing messages directing victims to attacker-controlled websites. The attackers then used a browser-in-the-browser (BiTB) technique to create what appeared to be a legitimate Adobe webpage, before convincing victims to download malicious software disguised as an Adobe Reader update.

Rather than deploying conventional malware, the attackers installed rogue instances of ScreenConnect, legitimate remote monitoring and management (RMM) software, giving them continued remote access to compromised endpoints.

Fake browser makes phishing harder to spot

BiTB attacks create a fake browser window inside a webpage using HTML, CSS and JavaScript. The window can replicate familiar features including an address bar, padlock and legitimate-looking URL, making traditional advice such as checking the web address less effective.

In the first attack, detected on 25 August, a victim clicked a link in a phishing email and was taken to a fake CAPTCHA page. They were subsequently presented with blurred documents and told they needed to download Adobe PDF Reader to view them.

The fake browser page appeared to show Adobe’s legitimate get.adobe.com address. However, the supposed Reader installer was actually ScreenConnect.

Once installed, the attackers deployed two rogue ScreenConnect clients, providing redundant routes for maintaining access. They then executed HideCursor.exe, a defence-evasion tool designed to conceal on-screen activity. Huntress intervened before the attack could progress further.

Second attack follows same playbook

Huntress identified another incident on 31 August involving the same Adobe Reader lure.

This time, the victim interacted with a malicious link delivered through AT&T Office@Hand, a legitimate communications service powered by RingCentral. The attackers again disguised ScreenConnect as an Adobe Reader update and installed two unauthorised instances.

The second ScreenConnect session was used to execute another defence-evasion binary, HideUL.exe. Microsoft Defender detected part of the activity, but the rogue ScreenConnect client still completed its installation before Huntress shut down the attack.

Legitimate tools remain attractive to attackers

The attacks demonstrate how threat actors can combine familiar phishing techniques with trusted software to make malicious activity harder to identify.

RMM abuse is a growing problem. Huntress’ 2026 Cyber Threat Report found RMM abuse increased 277% year on year and appeared in nearly a quarter of the incidents investigated by the company.

Huntress recommends organisations restrict who can install remote management tools, maintain an approved inventory of RMM software and monitor for new or unauthorised ScreenConnect clients. Employees should also be wary of unexpected software updates or file-viewing prompts, even when a webpage appears to display a legitimate address.

Read the full research here. 

The post Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools appeared first on IT Security Guru.

Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials

A large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly personalized credential-harvesting pages, and, in some cases, install ScreenConnect remote-access software. The campaign’s central advantage is that it presents trusted Google-owned domains at nearly every point a gateway, proxy, or analyst is likely to […]

The post Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud

Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help organizations reduce phishing and fraud risks associated with malicious QR code campaigns. Listed under Microsoft 365 Roadmap ID 570439, this feature is currently in development and is scheduled for rollout in […]

The post Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes

QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather than placing clickable links directly in emails. The shift is helping attackers bypass traditional secure email gateways and move victims from managed corporate devices to less-protected smartphones. The company recorded an average of […]

The post QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning

QR-code phishing, commonly known as quishing, is evolving beyond image-based payloads. Threat actors are now rendering scannable QR codes directly from HTML tables or text within email bodies, leaving no image attachment, embedded bitmap, or <img> element for traditional email scanners to inspect. The technique targets a structural blind spot in Secure Email Gateways (SEGs). […]

The post HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New Phishing Kit Uses AI to Fully Automate Vishing Attacks

A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB.

The phishing platform, called “Balonx,” includes a module dubbed “CallFlow” that the researchers say “represents a fundamental evolution” in the phishing-as-a-service market. This module uses four commercial AI services to conduct the attacks: OpenAI’s GPT-4o-mini, ElevenLabs’s AI voice generator, OpenAI Voice, and OpenAI Whisper.

Hacking the Healers: New KnowBe4 Whitepaper Highlights Record Security Breaches in Healthcare

When an organization has a security breach, it can cause significant financial, reputational and logistical damage. But in healthcare, where patient lives are on the line, the consequences can be much more catastrophic.

KnowBe4’s latest whitepaper on healthcare cybersecurity, “Hacking the Healers: How the Digital Workforce Became Cybersecurity's Frontline,” examines how decentralized clinical operations, remote staff and autonomous AI agents have dissolved traditional network perimeters, leaving healthcare organizations and patient safety vulnerable to targeted cyberattacks.

❌