Phishing Security News

Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.

Phishing remains the most common way attackers gain an initial foothold, tricking users into handing over credentials or running malicious code via convincing emails, texts or fake login pages. This feed tracks newly reported campaigns, the brands and platforms being impersonated, and the kits and infrastructure behind them. Recognizing current lures is one of the cheapest defenses an organization can deploy.

Recent Phishing items

CVE-2026-49826Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse…
@cveNotify · Aug 14, 2026
Fake job interviews are stealing Google and Facebook credentials.CTM360 uncovered RecruitTrap across 3,000+ phishing URLs posing as recruiter and interview pages. Some fake logins relay MFA prompts in…
@thehackernews · Aug 14, 2026
CVE-2026-73671Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST…
@cveNotify · Aug 13, 2026
AI has fundamentally changed email attacks.See how attackers create convincing AI-powered phishing campaigns, why traditional email security struggles to stop them, and how AI-native detection catches…
@thehackernews · Aug 13, 2026
Dissecting the JWR phishing frameworkhttps://ift.tt/oHdUQBD
@ctinow · Aug 13, 2026
Dissecting the JWR phishing frameworkhttps://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/
@PentestingNews · Aug 13, 2026
Dissecting the JWR phishing frameworkCisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login…
@malwr · Aug 13, 2026
Fake VPN Extensions Put Operators in Adversary-in-the-Middle Position Over Chrome Traffichttps://gbhackers.com/fake-vpn-extensions/
@PentestingNews · Aug 12, 2026
DEF CON Attendees Allegedly Jam Plane Wi‑Fi, Launch ‘Evil Twin’ Phishing Attackhttps://gbhackers.com/def-con-attendees-allegedly-jam-plane-wi-fi/
@PentestingNews · Aug 12, 2026
CVE-2026-72561A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/SSO set…
@cveNotify · Aug 11, 2026
Rogue AI • Metabase 0-day • Spectre bypass • Webmail attacks • Router backdoors • MCP supply-chain malware • 440 poisoned packages • AI token jacking • Device-code phishing • $30M crypto attacks • 26…
@thehackernews · Aug 10, 2026
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Developmenthttps://ift.tt/evU137O
@ctinow · Aug 10, 2026
Phishing can succeed in under a minute.Median click: 21 seconds. Data entry: 28 seconds later.Blocking the email isn’t enough if the attacker’s domains and links stay live.See what email security is s…
@thehackernews · Aug 10, 2026
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Datahttps://securityaffairs.com/196890/cyber-crime/u-s-defense-manufacturer-ieh-hit-by-phishing-attack-expo…
@PentestingNews · Aug 10, 2026
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Datahttps://ift.tt/S0A57X2
@ctinow · Aug 9, 2026
CVE-2025-7365A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequent…
@cveNotify · Aug 8, 2026
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Datahttps://ift.tt/auMwDYP
@ctinow · Aug 7, 2026
UNC6671 is calling employees on their personal phones, posing as IT help desk staff.One successful vishing call can expose credentials and MFA tokens, giving attackers access to Microsoft 365, Okta, a…
@thehackernews · Aug 7, 2026
CVE-2026-54215Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the applic…
@cveNotify · Aug 7, 2026
Vishing Extortion Group UNC6671 Rebrands After Making Millionshttps://ift.tt/TYvKxta
@ctinow · Aug 7, 2026
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emailshttps://ift.tt/JkOFRhv
@ctinow · Aug 7, 2026
Microsoft 365 accounts are being hijacked and quietly kept alive.A widespread AitM phishing campaign steals credentials and MFA codes, then uses rotating residential proxies to refresh sessions every…
@thehackernews · Aug 7, 2026
Point72 Among Major Hedge Funds Targeted in Cyberattack on Wall Street Through Voice Phishing Campaignhttps://thecyberexpress.com/point72-cyberattack-on-wall-street/
@PentestingNews · Aug 7, 2026
CVE-2026-71555PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages…
@cveNotify · Aug 6, 2026
For some, Thursday is winding down. For others, it has just begun. For us, it means 30 more cybersecurity stories for this week’s #ThreatsDay Bulletin:• Odysseus RCE• Samsung takeover• AI proxyjacking…
@thehackernews · Aug 6, 2026
CVE-2026-14547The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauth…
@cveNotify · Aug 6, 2026
CVE-2021-43890We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by usi…
@cveNotify · Aug 5, 2026
COLDCARD security audit phishing attack installs remote access toolhttps://ift.tt/vOqSexY
@ctinow · Aug 5, 2026
Stolen Greatness Tokens Provide Microsoft 365 Access More Than Two Weeks After Phishinghttps://gbhackers.com/stolen-greatness-authentication-tokens/
@PentestingNews · Aug 5, 2026
Kali365 turns Microsoft's real device login page into a phishing trap.Victims enter an attacker-controlled code, which may give attackers continued access to Microsoft 365 email and files.AnyRun recor…
@thehackernews · Aug 5, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.