Phishing Security News

Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.

Phishing remains the most common way attackers get an initial foothold, tricking users into handing over credentials or running malicious code through convincing emails, texts or fake login pages. Here: newly reported campaigns, the brands and platforms being impersonated, and the kits and infrastructure behind them.

Recent Phishing items

Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data https://gbhackers.com/ai-tools-for-attack/
@PentestingNews · Sep 28, 2026
Ledger Phishing Ads Turn a Fake Device Check Into a Seed-Phrase Trap A fake Ledger device check did not need to break a hardware wallet. It needed its owner to type the wallet’s recovery words into a…
@topcybersecurity · Sep 27, 2026
CVE-2026-100523 Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft m…
@cveNotify · Sep 26, 2026
CVE-2025-66307 This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeration and…
@cveNotify · Sep 26, 2026
CVE-2025-66306 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege users…
@cveNotify · Sep 26, 2026
Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing https://www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishing
@secharvester · Sep 25, 2026
Cyber Alert ‼️ 🇮🇹 Italy - Fake WhatsApp Message and AI Voice Scam Leave €36 Million Missing at Fideuram In February 2026, Fideuram – Intesa Sanpaolo Private Banking was hit by a sophisticated AI-assis…
@hackmanac_cybernews · Sep 25, 2026
Fake Journalist phishing scam targeting tech founders https://casco.com/blog/how-my-unicorn-founder-friend-was-phished
@secharvester · Sep 25, 2026
Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing https://ift.tt/oUW483X
@ctinow · Sep 24, 2026
CVE-2026-77707 Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM).This issue affects Liman Render Engine: from 1.0 before 1.2-75.…
@cveNotify · Sep 24, 2026
CVE-2026-77703 Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM).This issue affects Liman Render Engine: from 1.0 befo…
@cveNotify · Sep 24, 2026
CVE-2026-84151 The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributo…
@cveNotify · Sep 24, 2026
Across five key US industries, leading phishing threats increasingly target authentication sessions and access tokens. Email is only the beginning of the attack chain: links, redirects, archives, PDFs…
@anyrun_app · Sep 24, 2026
CVE-2026-84151 The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributo…
@cveNotify · Sep 24, 2026
CVE-2026-84151 The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributo…
@cveNotify · Sep 24, 2026
CVE-2026-94183 Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker…
@cveNotify · Sep 23, 2026
How device code phishing gives scammers access to your account https://ift.tt/P6xV8oU
@ctinow · Sep 23, 2026
CVE-2026-18505 IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (` HostHeaderFilter.java:151 `). An unauthenticated attacker ca…
@cveNotify · Sep 23, 2026
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign https://ift.tt/t7lsTX9
@ctinow · Sep 23, 2026
Fake Claude Max giveaway hides a Google account phishing trap https://ift.tt/vRnkHpc
@ctinow · Sep 23, 2026
Microsoft Warns of EvilTokens AI Phishing Service Hijacking Thousands of Accounts https://gbhackers.com/eviltokens-ai-phishing/
@PentestingNews · Sep 23, 2026
AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft https://ift.tt/BTmA09c
@ctinow · Sep 23, 2026
A $320/month phishing kit can steal Microsoft 365 sessions after MFA succeeds.NovaCookies relays the login in real time and captures the authenticated session, while the sign-in itself can look ordina…
@thehackernews · Sep 23, 2026
Microsoft Disrupts EvilTokens Device Code Phishing Service https://ift.tt/kwGUt0o
@ctinow · Sep 22, 2026
Unmasking EvilTokens: Getting to the root of device code phishing https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/
@PentestingNews · Sep 22, 2026
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises https://ift.tt/GYX85Pi
@ctinow · Sep 22, 2026
Unmasking EvilTokens: Getting to the root of device code phishing https://ift.tt/0f41s8u
@ctinow · Sep 22, 2026
15 Cyber Threat Trends Security Leaders Need to Watch in 2026 SOC teams are under pressure to move faster, but more attacks now hide inside trusted platforms, legitimate login flows, and everyday busi…
@Cyber_Security_Channel · Sep 22, 2026
Phishing activity in the past 7 days 🐟 👉 Track latest phishing threats in TI Lookup #TopPhishingThreats
@anyrun_app · Sep 22, 2026
CVE-2026-54915 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /auth/redirect endpoint in plexpy/ webauth.py removes forward slashes…
@cveNotify · Sep 21, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.