Skip to main content
← All Articles

Tag

#Phishing

191 articles

Advertisement

HIGH
Threat Intel

Faronics Deploy Abused by Phishing Actors to Install ScreenConnect

Phishing actors are abusing the legitimate Faronics Deploy endpoint management tool to gain remote access and install ScreenConnect via malicious installers.

Runtime Rebel Intel
4 min read · Sep 2, 2026
Threat Actors Prefer Repeatable Playbooks Over Novel Exploits
INFO
Threat Intel

Threat Actors Prefer Repeatable Playbooks Over Novel Exploits

Analysis of modern cyberattacks reveals threat actors increasingly favour scalable, repeatable playbooks over novel exploit development.

Runtime Rebel Intel
3 min read · Sep 1, 2026
LOW
Threat Intel

Polymorphic Phishing Page Analysis: JavaScript Obfuscation Flaws

Analysis of a polymorphic phishing page utilizing heavy JavaScript obfuscation and variable scope bugs that cause browser loops.

Runtime Rebel Intel
3 min read · Sep 1, 2026
Deobfuscating Malicious JavaScript for Threat Analysis
INFO
Threat Intel

Deobfuscating Malicious JavaScript for Threat Analysis

Understanding JavaScript obfuscation techniques used in phishing and malware. Learn static and dynamic deobfuscation methods to uncover malicious intent.

Runtime Rebel Intel
4 min read · Sep 1, 2026
INFO
Threat Intel

OpenAI Disrups LLM-Powered Social Engineering Operations

OpenAI disrupts a Cambodian threat network leveraging ChatGPT for complex multi-stage social engineering, romance scams, and fraud.

Runtime Rebel Intel
2 min read · Sep 1, 2026
MEDIUM
Supply Chain

Hackers Abuse npm Mirrors to Host Phishing Redirects

Threat actors exploit npm and its mirroring platforms like UNPKG to host malicious HTML pages, impersonating Cloudflare CAPTCHAs for phishing redirects.

Runtime Rebel Intel
5 min read · Aug 26, 2026

Advertisement

MEDIUM
Threat Intel

ShinyHunters Breaches ReliaQuest Identity Dashboard via Phishing

ReliaQuest confirms ShinyHunters gained brief, view-only access to its identity dashboard via a sophisticated social engineering attack.

Runtime Rebel Intel
4 min read · Aug 25, 2026
MEDIUM
Data Breach

ReliaQuest Thwarts ShinyHunters Social Engineering Attack on Okta SSO

ReliaQuest confirms a social engineering attack by ShinyHunters targeting an employee's Okta SSO, blocked from accessing applications or customer data.

Runtime Rebel Intel
5 min read · Aug 24, 2026
Grandoreiro Banking Trojan: New Evasion Tactics in Mexico
MEDIUM
Malware

Grandoreiro Banking Trojan: New Evasion Tactics in Mexico

Grandoreiro banking Trojan resurfaces in Mexico, employing advanced evasion tactics after a law enforcement takedown to target financial users.

Runtime Rebel Intel
4 min read · Aug 24, 2026
MEDIUM
Malware

FTP Banners Abused to Deliver E4del and PINHOLE RATs

Threat actors are using FTP server banners to hide commands, delivering new Windows remote access trojans E4del and PINHOLE via LNK-based infection chains.

Runtime Rebel Intel
4 min read · Aug 24, 2026
MEDIUM
Malware

ToxicPanda 2.0 Android Malware Abuses Wireless ADB and VPN

ToxicPanda 2.0 Android malware uses VPN permissions to block Google Play and abuses Wireless ADB to gain shell access and deploy overlays.

Runtime Rebel Intel
3 min read · Aug 23, 2026
Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage
MEDIUM
Threat Intel

Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage

Google Threat Intelligence reports three suspected Russian groups using OAuth phishing, Google app passwords, and WhatsApp device linking to hijack accounts.

Runtime Rebel Intel
3 min read · Aug 23, 2026
MEDIUM
Threat Intel

iAuthFlow V2 Phishing Toolkit Leverages Passkeys for Persistence

Discover how the iAuthFlow V2 phishing toolkit registers malicious passkeys to maintain persistent account access despite password resets.

Runtime Rebel Intel
3 min read · Aug 23, 2026
HIGH
Malware

SynkLoader Malware Steals Credentials in Microsoft Teams Phishing

New SynkLoader malware distributed via Microsoft Teams phishing campaigns uses a fake lock screen to steal Windows credentials, enabling corporate network access.

Runtime Rebel Intel
4 min read · Aug 22, 2026
Identity Abuse and Phishing via Enterprise Collaboration Platforms
MEDIUM
Threat Intel

Identity Abuse and Phishing via Enterprise Collaboration Platforms

Threat actors increasingly misuse enterprise collaboration platforms for identity phishing, credential theft, and malware delivery.

Runtime Rebel Intel
3 min read · Aug 20, 2026
MEDIUM
Threat Intel

Russian Threat Clusters Target Academia and Government via Auth Abuse

Google Threat Intelligence Group tracks three Russian cyber espionage clusters abusing legitimate authentication flows and app passwords.

Runtime Rebel Intel
3 min read · Aug 20, 2026
Crime Script Analysis: Mapping Threat Workflows and AI Risks
INFO
Threat Intel

Crime Script Analysis: Mapping Threat Workflows and AI Risks

Discover how crime script analysis translates complex cyber attacks into narratives, highlighting AI threats in business email compromise.

Runtime Rebel Intel
3 min read · Aug 19, 2026
Mitigating Large-Scale Credential Attacks and Password Spraying
HIGH
Threat Intel

Mitigating Large-Scale Credential Attacks and Password Spraying

Analysis of large-scale password spraying and credential theft campaigns targeting enterprise identity perimeters, edge devices, and cloud tenants.

Runtime Rebel Intel
2 min read · Aug 19, 2026
HIGH
Data Breach

Threat Actor Claims 3.6 Million Azure Account Records Stolen

A threat actor named TheHatman is selling 3.6 million employee records allegedly stolen from major corporate Azure tenants using compromised credentials.

Runtime Rebel Intel
3 min read · Aug 18, 2026
HIGH
Threat Intel

Public Wi-Fi DNS Hijacking: Credential Theft Risk

Criminals are actively manipulating public Wi-Fi DNS settings to redirect users to fake login pages, stealing sensitive credentials. Learn how to protect yourself.

Runtime Rebel Intel
4 min read · Aug 17, 2026
HIGH
Data Breach

SafePal Data Breach Exposes 39,798 Customer Order Details

SafePal confirms a data breach impacting 39,798 customers, exposing names, emails, and shipping info. Stolen data is for sale, increasing phishing risks.

Runtime Rebel Intel
5 min read · Aug 17, 2026
New JWR Phishing Framework Bypasses MFA with Live Monitoring
HIGH
Malware

New JWR Phishing Framework Bypasses MFA with Live Monitoring

JWR, a new real-time phishing framework, uses WebSockets to bypass MFA and steal sensitive data via SMS lures, posing a critical threat.

Runtime Rebel Intel
3 min read · Aug 14, 2026
INFO
Threat Intel

Ukraine Dismantles 94 Fraudulent Call Centers, Seizing Millions

Ukraine, in collaboration with German police, dismantled 94 fraudulent call centers, seizing millions in assets. This disrupts investment and bank account phishing scams.

Runtime Rebel Intel
4 min read · Aug 14, 2026
JWR Phishing Framework: Real-time Data Theft via PhaaS
HIGH
Malware

JWR Phishing Framework: Real-time Data Theft via PhaaS

The JWR phishing framework, a variant of The Outsider PhaaS, harvests payment data, PII, and 2FA codes in real-time via operator-controlled sessions.

Runtime Rebel Intel
4 min read · Aug 13, 2026