❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

FBI Alert: OAuth Consent Phishing is Targeting Users of Messaging Apps

11 September 2026 at 16:00

The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting β€œprominent victims, their family members, and personal acquaintances.”

OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.

Survey: Companies Cite Phishing as their Top AI-Enabled Fraud Concern

11 September 2026 at 12:00

A recent survey from Experian found that 60% of companies report fraud losses that are β€œsomewhat or significantly higher” than in previous years, with a majority of respondents citing AI-generated phishing attacks as their top AI-related fraud concern.

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

11 September 2026 at 10:19

Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY.

The post In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review appeared first on SecurityWeek.

CrowdStrike Disrupts Sality Botnet After More Than 20 Years

3 September 2026 at 17:36

Cybersecurity expert Ken Underhill reports from CrowdStrike on the disruption of the 20-year-old Sality botnet and what security teams need to know.

The post CrowdStrike Disrupts Sality Botnet After More Than 20 Years appeared first on TechRepublic.

CrowdStrike Disrupts Sality Botnet After More Than 20 Years

3 September 2026 at 17:36

Cybersecurity expert Ken Underhill reports from CrowdStrike on the disruption of the 20-year-old Sality botnet and what security teams need to know.

The post CrowdStrike Disrupts Sality Botnet After More Than 20 Years appeared first on TechRepublic.

Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

3 September 2026 at 11:35

Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys.

The post Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal appeared first on SecurityWeek.

New Phishing Kit Uses AI to Fully Automate Vishing Attacks

2 September 2026 at 12:00

A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB.

The phishing platform, called β€œBalonx,” includes a module dubbed β€œCallFlow” that the researchers say β€œrepresents a fundamental evolution” in the phishing-as-a-service market. This module uses four commercial AI services to conduct the attacks: OpenAI’s GPT-4o-mini, ElevenLabs’s AI voice generator, OpenAI Voice, and OpenAI Whisper.

New Phishing Kit Gives Threat Actors Live View Into Attacks

28 August 2026 at 09:00

A new phishing platform called β€œJWR” gives attackers real-time control over social engineering attacks, according to researchers at Cisco Talos. The kit livestreams the phishing page to the attacker as the victim is entering information, allowing the attacker to steer the victim’s experience and maximize the damage.

❌
❌