Phishing Security News

Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.

Phishing remains the most common way attackers gain an initial foothold, tricking users into handing over credentials or running malicious code via convincing emails, texts or fake login pages. This feed tracks newly reported campaigns, the brands and platforms being impersonated, and the kits and infrastructure behind them. Recognizing current lures is one of the cheapest defenses an organization can deploy.

Recent Phishing items

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters https://ift.tt/a5YiEXK
@ctinow · Sep 4, 2026
An invisible-Unicode phishing campaign peaked at an estimated 2.37 million emails in one day.Attackers split financial terms like “funding” with hidden tag characters, breaking literal keyword matches…
@thehackernews · Sep 4, 2026
CVE-2026-85676 Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attackers can appen…
@cveNotify · Sep 4, 2026
Hackers Abuse AI-Era ASCII Smuggling to Hide Phishing Content in Millions of Emails https://gbhackers.com/ai-era-ascii-smuggling/
@PentestingNews · Sep 4, 2026
ASCII smuggling crosses over from AI prompt injection to phishing evasion https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-eva…
@PentestingNews · Sep 4, 2026
CVE-2026-68860 Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vu…
@cveNotify · Sep 4, 2026
CVE-2026-49456 Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.tsx:156–161)…
@cveNotify · Sep 3, 2026
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories https://ift.tt/8lxGB9S
@ctinow · Sep 3, 2026
This week’s ThreatsDay... 🧰 Real tools, wrong hands 🎣 Phishing for sale 🔗 Old access stays open 🤖 AI points to bad packages ⌨️ Typos open doors 🪪 ID data stolen 💥 Access becomes ransomware ⚙️ Weak set…
@thehackernews · Sep 3, 2026
ASCII smuggling crosses over from AI prompt injection to phishing evasion https://ift.tt/UJ8s7hA
@ctinow · Sep 3, 2026
An RMM phishing campaign first tied to Canada spans 46 countries.ANYRUN linked 601 cases to the operation, with 45% of observed activity associated with the U.S. Fake tax, shipping, and invoice lures…
@thehackernews · Sep 3, 2026
QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes https://gbhackers.com/qr-codes-attack/
@PentestingNews · Sep 3, 2026
HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning https://gbhackers.com/html-rendered-qr-phishing/
@PentestingNews · Sep 3, 2026
CVE-2026-78000 Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - Four task handlers accepted a base64-e…
@cveNotify · Sep 3, 2026
Spring Ring’ Vishing Attack Uses Fake IT Calls on Microsoft Teams to Install Malware https://ift.tt/lkXrn0g
@ctinow · Sep 3, 2026
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries https://ift.tt/7FMJWpm
@ctinow · Sep 3, 2026
New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password https://ift.tt/75Pktlb
@ctinow · Sep 2, 2026
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users https://ift.tt/cU1gNCa
@ctinow · Sep 2, 2026
AI-powered phishing is here — and it's more convincing than ever.The 2026 Kaseya Email Security Report breaks down the latest threats and what you can do about them. 🛡️ 📥 Get the report → https://thn.…
@thehackernews · Sep 2, 2026
FBI raises alarm over deceptive phishing campaign targeting prominent people https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/
@PentestingNews · Sep 2, 2026
FBI raises alarm over deceptive phishing campaign targeting prominent people https://ift.tt/Y27WgOT
@ctinow · Sep 1, 2026
CVE-2026-82853 Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly int…
@cveNotify · Aug 31, 2026
CVE-2026-41226 Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an…
@cveNotify · Aug 31, 2026
Simple Router DNS Tweak Blocks Malware and Phishing Across All Connected Devices https://gbhackers.com/simple-router-dns-tweak-blocks-malware-and-phishing/
@PentestingNews · Aug 31, 2026
Hackers’ Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure https://ift.tt/wIpajqi
@ctinow · Aug 31, 2026
CVE-2025-7365 A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequen…
@cveNotify · Aug 31, 2026
CVE-2026-82647 WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing…
@cveNotify · Aug 30, 2026
CVE-2026-81733 WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that…
@cveNotify · Aug 29, 2026
Chinese Hackers Deploy PackClient RAT via Tax-Themed Phishing Attacks to Steal Data https://gbhackers.com/chinese-hackers-deploy-packclient-rat/
@PentestingNews · Aug 29, 2026
Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit https://gbhackers.com/polymorphic-phishing-attack/
@PentestingNews · Aug 28, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.