Advertisement
TikTok for Business Phishing Campaign Evades Security Bots
A new TikTok for Business phishing campaign uses sophisticated bot-evasion techniques to steal corporate credentials and hijack advertising assets.
Bubble Platform Abuse: Credential Phishing Targets Microsoft Accounts
Threat actors are abusing the Bubble no-code platform to host sophisticated phishing campaigns, bypassing traditional detection and targeting Microsoft account…
Underground Markets Pivot to Premium AI Account Trading
Cybercriminals are increasingly trading stolen premium AI accounts to enhance social engineering, automate malware creation, and bypass safety filters.
SVG-Based Phishing: Using Scalable Vector Graphics for Credential Theft
Discover how threat actors leverage SVG files to bypass email filters and execute credential theft through embedded JavaScript and HTML forms.
LiteLLM PyPI Supply Chain Attack: TeamPCP Steals Credentials
TeamPCP compromised the LiteLLM PyPI package, backdooring it to steal credentials and auth tokens from hundreds of thousands of devices.
Tycoon 2FA PaaS Recovery: Detecting AitM Phishing Infrastructure
Tycoon 2FA Phishing-as-a-Service has recovered from law enforcement disruption. Learn how this AitM platform bypasses MFA and how to protect your organization.
Advertisement
VoidStealer: Bypassing Chrome ABE via Remote Debugging Protocol
VoidStealer malware uses a novel debugger technique to bypass Google Chrome’s Application-Bound Encryption and exfiltrate browser-stored credentials.
Perseus Android Malware: Technical Analysis of Note-Stealing Tactics
Perseus Android malware targets sensitive secrets in user notes by abusing Accessibility Services. Learn how to detect and mitigate this mobile threat.
Credential Theft Surge: Understanding Infostealer & AI Social Engineering
Credential theft surged in late 2025, driven by sophisticated infostealer malware and AI-enhanced social engineering.
7-Stage Phishing Chain Targets Outpost24 C-Suite via Redirects
Security researchers identify a sophisticated 7-stage phishing attack targeting Outpost24 executives using legitimate domains to evade email gateways.
2025 Identity Threat Report: Analyzing the Infostealer Economy
Recorded Future's 2025 Identity Threat Landscape Report examines how infostealer malware and session cookie theft drive the modern credential threat economy.
ForceMemo: Credential Theft Compromises Python Repositories
Researchers reveal ForceMemo, a campaign exploiting credentials stolen via GlassWorm to compromise hundreds of GitHub accounts and Python repositories.
FBI Seeks Victims of Malicious Steam Games Stealing Credentials
The FBI is investigating eight malicious games on Steam that stole user credentials from tens of thousands of players.
Starbucks Employee Portal Phishing Leads to Data Breach
Starbucks confirms a data breach impacting hundreds of employees via targeted phishing attacks on an internal portal. Learn about the incident and prevention.
Storm-2561 Leverages SEO Poisoning for Credential Theft
Microsoft warns of Storm-2561's credential theft campaign using SEO poisoning to distribute fake, digitally signed VPN clients disguised as legitimate enterprise…
Phishing Credential Exfiltration via EmailJS and React Frameworks
Security analysis of a sophisticated React-based phishing kit that leverages the EmailJS service for stealthy exfiltration of user credentials.
VENON Malware: Rust-Based Banking Trojan Targets Brazilian Banks
A new Rust-based malware called VENON is targeting 33 Brazilian banks with credential-stealing overlays, signaling a shift in Latin American cybercrime TTPs.
FortiGate NGFW Exploitation Leads to Service Account Credential Theft
Threat actors are exploiting FortiGate devices to extract configuration files and steal service account credentials, facilitating lateral movement in networks.
Phishing Alert: Impersonation of US City/County Officials Targets Permit Applicants
The FBI warns of active phishing campaigns impersonating US city and county officials to target businesses and individuals seeking permits, aiming for fraud and data…
Europol Dismantles Tycoon 2FA Phishing Platform: Mitigating MFA Bypass
Europol and cybersecurity vendors dismantle Tycoon 2FA, a major phishing-as-a-service platform known for its sophisticated MFA bypass capabilities.
LastPass Phishing Campaign Targets Master Passwords via Fake Alerts
LastPass warns of a new phishing campaign using fraudulent security alerts to steal master passwords. Learn how to identify and mitigate these vault threats.
Compromised Site Management Panels: A Commoditized Cybercrime Threat
Underground markets commoditize compromised cPanel and other site management panels, fueling phishing and scam infrastructure. Learn to secure web admin interfaces.
Phishing Campaign Leverages Fake Google PWA to Steal Credentials, MFA
A sophisticated phishing campaign uses a fake Google Security PWA to compromise accounts, steal MFA codes, and proxy traffic. Learn how to protect.
QuickLens Chrome Extension Hijacked to Deploy ClickFix Malware
Malicious QuickLens Chrome extension removed from Web Store after stealing cryptocurrency and deploying ClickFix malware to 30,000 users.