Educational breakdown of modern phishing tradecraft evolution. What's changed: attackers now use AI to generate fluent, localized content removing the 'bad grammar' tell. Common vectors include urgenc…
Category: Research & Analysis / Social Engineering
#phishing#social-engineering#credential-harvesting#ai-enabled-threats#ato
Google published research showing Android's AI-driven scam protections outperform iOS. What's interesting: YouGov survey of 5,000 users found Android users 58% more likely to report zero scam texts vs…
Category: Research & Analysis / Mobile Security
#mobile-security#android#ios#scam-protection#ai-security#phishing#google
Researchers at Datadog Security Labs discovered a new phishing method dubbed 'CoPhish' that abuses Microsoft Copilot Studio agents to deliver malicious OAuth consent requests. The attack leverages leg…
Category: Phishing / Cloud Security / Phishing
#phishing#oauth#microsoft#copilot#cloud
Unit 42 researchers have attributed over 194,000 malicious domains to a China-linked group known as the Smishing Triad. The campaign leverages disposable infrastructure hosted primarily on U.S. cloud …
Category: Threats / Mobile Security / Phishing
#phishing#smishing#mobile#china#unit42
SentinelLabs uncovered the PhantomCaptcha campaign targeting humanitarian and government organizations involved in Ukraine relief efforts. Attackers impersonated the Ukrainian President’s Office using…
Category: Threat Alerts / Threat Intelligence / Phishing & Espionage Campaigns
#APT#Ukraine#phishing#SentinelLabs#espionage
Cofense researchers analyzed a sophisticated phishing campaign leveraging randomized .org domains and dynamic page replacement to bypass Secure Email Gateways (SEGs). The phishing script uses dual UUI…
Category: Threat Alerts / Threat Intelligence / Phishing & Credential Theft
#phishing#JavaScript#Cofense#credential theft
Cofense warns that major outages—such as AWS disruptions—are routinely exploited for phishing, spoofed helpdesks, QR scams, and fake patch downloads. Case studies from 2024–2025 show rapid lure adapta…
Category: Threat Alerts / Threat Intelligence / Threat Intelligence
#aws#outage#phishing#qr#mfa-fatigue
Microsoft’s Digital Defense Report highlights the dominance of financially motivated threats, with over half of investigated incidents tied to extortion/ransomware and a surge in identity attacks driv…
Category: Industry News / Research & Tools / Research & Tools
#microsoft#digital-defense-report#ransomware#phishing#identity
Cyber Defense Magazine examines AI‑enabled threats against India’s BFSI sector, citing surges in phishing (+175%), deepfake fraud (+550% since 2019), and high breach costs (US$6.08M avg for finance). …
Category: Industry News / Business & Industry Impact / Business & Industry Impact
#bfsi#ai#phishing#deepfakes#india
Unit 42 researchers uncovered a global phishing campaign deploying PhantomVAI Loader to deliver multiple infostealers, including AsyncRAT, XWorm, and FormBook. The malware leverages steganography, obf…
Category: Threat Intelligence / Malware / Malware
#malware#infostealer#phishing#paloalto#phantomvai
Health-ISAC’s Q3 2025 Quarterly Threat Insights highlights intensifying threats to healthcare. Notable trends include the Shai-Hulud worm spreading via malicious npm packages that embed into developer…
Category: Threat Alerts / Threat Intelligence / Threat Intelligence
#healthcare#supply-chain#phishing#netscaler#cisco-asa#sbom
Ongoing smishing targets New Yorkers with fake 'Inflation Refund' messages impersonating NY Taxation & Finance, phishing for SSNs and personal data; Governor Hochul warned on Sep 28.
Category: Threat Alerts / Incident Response & DFIR / Incident Response & DFIR
#phishing#smishing#PII#New York#fraud