❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 22 July 2026Main stream

Attackers Exploit AI Hallucinations to Send Users to Phishing Sites

22 July 2026 at 16:00

Threat actors are using a new technique called β€œphantom squatting” to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networks’ Unit 42.

Since AI models frequently hallucinate phony information, they sometimes point users to websites that don’t exist. Threat actors are now registering these AI-hallucinated domains and using them to host phishing sites.

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass

Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement.

New Data Shows Suno Breach Affected 55M Accounts

22 July 2026 at 11:53

New data shows 55.3 million Suno accounts were affected in a breach exposing contact details, purchases, and partial payment card information.

The post New Data Shows Suno Breach Affected 55M Accounts appeared first on TechRepublic.

New Data Shows Suno Breach Affected 55M Accounts

22 July 2026 at 11:53

New data shows 55.3 million Suno accounts were affected in a breach exposing contact details, purchases, and partial payment card information.

The post New Data Shows Suno Breach Affected 55M Accounts appeared first on TechRepublic.

Warning: ARToken Phishing Kit Automates BEC Attacks

22 July 2026 at 12:00

Researchers at Cisco Talos are tracking a sophisticated phishing-as-a-service operator panel called β€œARToken” that’s built on the EvilTokens phishing platform. ARToken focuses on targeted social engineering attacks, allowing operators to customize phishing attempts for each victim.

Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers

By: Divya
22 July 2026 at 02:41

Authorities from Germany, the United States, and Indonesia have dismantled the central infrastructure of Kratos, a major phishing-as-a-service (PhaaS) platform that enabled cybercriminals worldwide to conduct large-scale credential-harvesting campaigns. The operation, announced by Germany’s Federal Criminal Police Office (BKA) and the Frankfurt am Main Public Prosecutor’s Office’s Central Office for Combating Internet Crime (ZIT), resulted […]

The post Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Yesterday β€” 21 July 2026Main stream

Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials

21 July 2026 at 04:40

Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather than just endpoints. Recent activity shows tightly integrated social engineering, cloud abuse, and fileless PowerShell tradecraft that significantly complicate detection and response. APT42, also tracked as TA453 in some reporting, is […]

The post Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Before yesterdayMain stream

Kratos PhaaS Targets Microsoft 365 Users With SharePoint Links and Cloudflare Anti-Bot Checks

16 July 2026 at 02:36

Kratos, a subscription-based phishing-as-a-service platform, is targeting Microsoft 365 users in the United States, Europe, and other regions through campaigns designed to blend into ordinary document-sharing workflows. The operation abuses trusted services, including Microsoft SharePoint, OneDrive, Microsoft Forms, Canva, Tilda, and systeme.io, to deliver links that ultimately redirect recipients to credential-harvesting pages. Only 156 sessions […]

The post Kratos PhaaS Targets Microsoft 365 Users With SharePoint Links and Cloudflare Anti-Bot Checks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Report: Social Engineering Remains a Central Part of AI-assisted Attacks

15 July 2026 at 09:00

Threat actors continue to rely on social engineering as AI is incorporated into their attacks, according to ESET’s Threat Report for the first half of 2026.

ESET’s Director of Threat Prevention Labs, JiΕ™Γ­ KropÑč, stated, β€œRather than relying on entirely new methods and tools, attackers are quickly adapting established techniques to new platforms, technologies, and user behaviors. The number of AI skills within this new ecosystem is growing rapidly as we speak, further expanding the attack surface.”

❌
❌