<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Phishing</title><description>Cybersecurity articles tagged #Phishing on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Faronics Deploy Abused by Phishing Actors to Install ScreenConnect</title><link>https://runtimerebel.com/blog/faronics-deploy-abused-by-phishing-actors-to-install-screenconnect</link><guid isPermaLink="true">https://runtimerebel.com/blog/faronics-deploy-abused-by-phishing-actors-to-install-screenconnect</guid><description>Phishing actors are abusing the legitimate Faronics Deploy endpoint management tool to gain remote access and install ScreenConnect via malicious installers.</description><pubDate>Wed, 02 Sep 2026 01:58:12 GMT</pubDate><category>Screenconnect</category><category>Phishing</category><category>Remote Access Trojan</category><category>Huntress</category><category>PowerShell</category></item><item><title>Threat Actors Prefer Repeatable Playbooks Over Novel Exploits</title><link>https://runtimerebel.com/blog/threat-actors-prefer-repeatable-playbooks-over-novel-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/threat-actors-prefer-repeatable-playbooks-over-novel-exploits</guid><description>Analysis of modern cyberattacks reveals threat actors increasingly favour scalable, repeatable playbooks over novel exploit development.</description><pubDate>Tue, 01 Sep 2026 12:54:04 GMT</pubDate><category>Ransomware</category><category>Zero-Day</category><category>Phishing</category><category>Credential Theft</category><category>Malware</category></item><item><title>Polymorphic Phishing Page Analysis: JavaScript Obfuscation Flaws</title><link>https://runtimerebel.com/blog/polymorphic-phishing-page-analysis-javascript-obfuscation-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/polymorphic-phishing-page-analysis-javascript-obfuscation-flaws</guid><description>Analysis of a polymorphic phishing page utilizing heavy JavaScript obfuscation and variable scope bugs that cause browser loops.</description><pubDate>Tue, 01 Sep 2026 02:51:10 GMT</pubDate><category>Phishing</category><category>Credential Theft</category><category>Obfuscation</category><category>JavaScript</category><category>Malware Analysis</category></item><item><title>Deobfuscating Malicious JavaScript for Threat Analysis</title><link>https://runtimerebel.com/blog/deobfuscating-malicious-javascript-for-threat-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/deobfuscating-malicious-javascript-for-threat-analysis</guid><description>Understanding JavaScript obfuscation techniques used in phishing and malware. Learn static and dynamic deobfuscation methods to uncover malicious intent.</description><pubDate>Tue, 01 Sep 2026 02:45:47 GMT</pubDate><category>JavaScript</category><category>Obfuscation</category><category>Phishing</category><category>Malware</category><category>Deobfuscation</category></item><item><title>OpenAI Disrups LLM-Powered Social Engineering Operations</title><link>https://runtimerebel.com/blog/openai-disrups-llm-powered-social-engineering-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-disrups-llm-powered-social-engineering-operations</guid><description>OpenAI disrupts a Cambodian threat network leveraging ChatGPT for complex multi-stage social engineering, romance scams, and fraud.</description><pubDate>Tue, 01 Sep 2026 02:45:05 GMT</pubDate><category>LLM</category><category>Social Engineering</category><category>Phishing</category><category>Fraud</category></item><item><title>Hackers Abuse npm Mirrors to Host Phishing Redirects</title><link>https://runtimerebel.com/blog/hackers-abuse-npm-mirrors-to-host-phishing-redirects</link><guid isPermaLink="true">https://runtimerebel.com/blog/hackers-abuse-npm-mirrors-to-host-phishing-redirects</guid><description>Threat actors exploit npm and its mirroring platforms like UNPKG to host malicious HTML pages, impersonating Cloudflare CAPTCHAs for phishing redirects.</description><pubDate>Wed, 26 Aug 2026 08:31:38 GMT</pubDate><category>NPM</category><category>Phishing</category><category>Supply Chain Attack</category><category>UNPKG</category><category>Cloudflare Impersonation</category></item><item><title>ShinyHunters Breaches ReliaQuest Identity Dashboard via Phishing</title><link>https://runtimerebel.com/blog/shinyhunters-breaches-reliaquest-identity-dashboard-via-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-breaches-reliaquest-identity-dashboard-via-phishing</guid><description>ReliaQuest confirms ShinyHunters gained brief, view-only access to its identity dashboard via a sophisticated social engineering attack.</description><pubDate>Tue, 25 Aug 2026 00:41:55 GMT</pubDate><category>ShinyHunters</category><category>Social Engineering</category><category>Phishing</category><category>Credential Theft</category><category>Okta</category></item><item><title>ReliaQuest Thwarts ShinyHunters Social Engineering Attack on Okta SSO</title><link>https://runtimerebel.com/blog/reliaquest-thwarts-shinyhunters-social-engineering-attack-on-okta-sso</link><guid isPermaLink="true">https://runtimerebel.com/blog/reliaquest-thwarts-shinyhunters-social-engineering-attack-on-okta-sso</guid><description>ReliaQuest confirms a social engineering attack by ShinyHunters targeting an employee&apos;s Okta SSO, blocked from accessing applications or customer data.</description><pubDate>Mon, 24 Aug 2026 16:25:26 GMT</pubDate><category>ShinyHunters</category><category>Social Engineering</category><category>Phishing</category><category>Vishing</category><category>Okta</category></item><item><title>Grandoreiro Banking Trojan: New Evasion Tactics in Mexico</title><link>https://runtimerebel.com/blog/grandoreiro-banking-trojan-new-evasion-tactics-in-mexico</link><guid isPermaLink="true">https://runtimerebel.com/blog/grandoreiro-banking-trojan-new-evasion-tactics-in-mexico</guid><description>Grandoreiro banking Trojan resurfaces in Mexico, employing advanced evasion tactics after a law enforcement takedown to target financial users.</description><pubDate>Mon, 24 Aug 2026 08:39:06 GMT</pubDate><category>Grandoreiro</category><category>Banking Trojan</category><category>Malware</category><category>Mexico</category><category>Phishing</category></item><item><title>FTP Banners Abused to Deliver E4del and PINHOLE RATs</title><link>https://runtimerebel.com/blog/ftp-banners-abused-to-deliver-e4del-and-pinhole-rats</link><guid isPermaLink="true">https://runtimerebel.com/blog/ftp-banners-abused-to-deliver-e4del-and-pinhole-rats</guid><description>Threat actors are using FTP server banners to hide commands, delivering new Windows remote access trojans E4del and PINHOLE via LNK-based infection chains.</description><pubDate>Mon, 24 Aug 2026 08:38:06 GMT</pubDate><category>RAT</category><category>LNK Files</category><category>Phishing</category><category>E4del</category><category>PINHOLE</category></item><item><title>ToxicPanda 2.0 Android Malware Abuses Wireless ADB and VPN</title><link>https://runtimerebel.com/blog/toxicpanda-2-0-android-malware-abuses-wireless-adb-and-vpn</link><guid isPermaLink="true">https://runtimerebel.com/blog/toxicpanda-2-0-android-malware-abuses-wireless-adb-and-vpn</guid><description>ToxicPanda 2.0 Android malware uses VPN permissions to block Google Play and abuses Wireless ADB to gain shell access and deploy overlays.</description><pubDate>Sun, 23 Aug 2026 16:15:53 GMT</pubDate><category>ToxicPanda</category><category>Android</category><category>Malware</category><category>Phishing</category><category>Credential Theft</category></item><item><title>Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage</title><link>https://runtimerebel.com/blog/russian-threat-clusters-abuse-oauth-and-whatsapp-for-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-threat-clusters-abuse-oauth-and-whatsapp-for-espionage</guid><description>Google Threat Intelligence reports three suspected Russian groups using OAuth phishing, Google app passwords, and WhatsApp device linking to hijack accounts.</description><pubDate>Sun, 23 Aug 2026 16:14:39 GMT</pubDate><category>APT29</category><category>Phishing</category><category>OAuth</category><category>Credential Theft</category><category>Malware</category></item><item><title>iAuthFlow V2 Phishing Toolkit Leverages Passkeys for Persistence</title><link>https://runtimerebel.com/blog/iauthflow-v2-phishing-toolkit-leverages-passkeys-for-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/iauthflow-v2-phishing-toolkit-leverages-passkeys-for-persistence</guid><description>Discover how the iAuthFlow V2 phishing toolkit registers malicious passkeys to maintain persistent account access despite password resets.</description><pubDate>Sun, 23 Aug 2026 00:44:48 GMT</pubDate><category>Phishing</category><category>Credential Theft</category><category>Passkeys</category><category>Phishing as a Service</category></item><item><title>SynkLoader Malware Steals Credentials in Microsoft Teams Phishing</title><link>https://runtimerebel.com/blog/synkloader-malware-steals-credentials-in-microsoft-teams-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/synkloader-malware-steals-credentials-in-microsoft-teams-phishing</guid><description>New SynkLoader malware distributed via Microsoft Teams phishing campaigns uses a fake lock screen to steal Windows credentials, enabling corporate network access.</description><pubDate>Sat, 22 Aug 2026 00:40:08 GMT</pubDate><category>Malware</category><category>Phishing</category><category>Microsoft Teams</category><category>Credential Theft</category><category>Ransomware</category></item><item><title>Identity Abuse and Phishing via Enterprise Collaboration Platforms</title><link>https://runtimerebel.com/blog/identity-abuse-and-phishing-via-enterprise-collaboration-platforms</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-abuse-and-phishing-via-enterprise-collaboration-platforms</guid><description>Threat actors increasingly misuse enterprise collaboration platforms for identity phishing, credential theft, and malware delivery.</description><pubDate>Thu, 20 Aug 2026 16:29:19 GMT</pubDate><category>APT29</category><category>Phishing</category><category>Credential Theft</category><category>Malware</category></item><item><title>Russian Threat Clusters Target Academia and Government via Auth Abuse</title><link>https://runtimerebel.com/blog/russian-threat-clusters-target-academia-and-government-via-auth-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-threat-clusters-target-academia-and-government-via-auth-abuse</guid><description>Google Threat Intelligence Group tracks three Russian cyber espionage clusters abusing legitimate authentication flows and app passwords.</description><pubDate>Thu, 20 Aug 2026 16:26:40 GMT</pubDate><category>APT29</category><category>Phishing</category><category>Oauth Phishing</category><category>Credential Theft</category><category>Zero-Day</category></item><item><title>Crime Script Analysis: Mapping Threat Workflows and AI Risks</title><link>https://runtimerebel.com/blog/crime-script-analysis-mapping-threat-workflows-and-ai-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/crime-script-analysis-mapping-threat-workflows-and-ai-risks</guid><description>Discover how crime script analysis translates complex cyber attacks into narratives, highlighting AI threats in business email compromise.</description><pubDate>Wed, 19 Aug 2026 16:24:36 GMT</pubDate><category>Threat Intel</category><category>Phishing</category><category>Artificial Intelligence</category></item><item><title>Mitigating Large-Scale Credential Attacks and Password Spraying</title><link>https://runtimerebel.com/blog/mitigating-large-scale-credential-attacks-and-password-spraying</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitigating-large-scale-credential-attacks-and-password-spraying</guid><description>Analysis of large-scale password spraying and credential theft campaigns targeting enterprise identity perimeters, edge devices, and cloud tenants.</description><pubDate>Wed, 19 Aug 2026 00:42:17 GMT</pubDate><category>Credential Theft</category><category>Ransomware</category><category>Phishing</category><category>Zero-Day</category></item><item><title>Threat Actor Claims 3.6 Million Azure Account Records Stolen</title><link>https://runtimerebel.com/blog/threat-actor-claims-3-6-million-azure-account-records-stolen</link><guid isPermaLink="true">https://runtimerebel.com/blog/threat-actor-claims-3-6-million-azure-account-records-stolen</guid><description>A threat actor named TheHatman is selling 3.6 million employee records allegedly stolen from major corporate Azure tenants using compromised credentials.</description><pubDate>Tue, 18 Aug 2026 00:40:50 GMT</pubDate><category>Credential Theft</category><category>Data Breach</category><category>Azure</category><category>Phishing</category><category>Social Engineering</category></item><item><title>Public Wi-Fi DNS Hijacking: Credential Theft Risk</title><link>https://runtimerebel.com/blog/public-wi-fi-dns-hijacking-credential-theft-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/public-wi-fi-dns-hijacking-credential-theft-risk</guid><description>Criminals are actively manipulating public Wi-Fi DNS settings to redirect users to fake login pages, stealing sensitive credentials. Learn how to protect yourself.</description><pubDate>Mon, 17 Aug 2026 16:19:43 GMT</pubDate><category>Credential Theft</category><category>Phishing</category><category>Dnssec</category><category>DNS Hijacking</category><category>Public Wi Fi</category></item><item><title>SafePal Data Breach Exposes 39,798 Customer Order Details</title><link>https://runtimerebel.com/blog/safepal-data-breach-exposes-39798-customer-order-details</link><guid isPermaLink="true">https://runtimerebel.com/blog/safepal-data-breach-exposes-39798-customer-order-details</guid><description>SafePal confirms a data breach impacting 39,798 customers, exposing names, emails, and shipping info. Stolen data is for sale, increasing phishing risks.</description><pubDate>Mon, 17 Aug 2026 00:40:25 GMT</pubDate><category>SafePal</category><category>Data Breach</category><category>Phishing</category><category>Cryptocurrency</category><category>Social Engineering</category></item><item><title>New JWR Phishing Framework Bypasses MFA with Live Monitoring</title><link>https://runtimerebel.com/blog/new-jwr-phishing-framework-bypasses-mfa-with-live-monitoring</link><guid isPermaLink="true">https://runtimerebel.com/blog/new-jwr-phishing-framework-bypasses-mfa-with-live-monitoring</guid><description>JWR, a new real-time phishing framework, uses WebSockets to bypass MFA and steal sensitive data via SMS lures, posing a critical threat.</description><pubDate>Fri, 14 Aug 2026 01:09:15 GMT</pubDate><category>Phishing</category><category>Smishing</category><category>MFA Bypass</category><category>JWR</category><category>The Outsider</category></item><item><title>Ukraine Dismantles 94 Fraudulent Call Centers, Seizing Millions</title><link>https://runtimerebel.com/blog/ukraine-dismantles-94-fraudulent-call-centers-seizing-millions</link><guid isPermaLink="true">https://runtimerebel.com/blog/ukraine-dismantles-94-fraudulent-call-centers-seizing-millions</guid><description>Ukraine, in collaboration with German police, dismantled 94 fraudulent call centers, seizing millions in assets. This disrupts investment and bank account phishing scams.</description><pubDate>Fri, 14 Aug 2026 01:07:01 GMT</pubDate><category>Fraud</category><category>Phishing</category><category>Investment Scams</category><category>Law Enforcement Operation</category><category>Call Centers</category></item><item><title>JWR Phishing Framework: Real-time Data Theft via PhaaS</title><link>https://runtimerebel.com/blog/jwr-phishing-framework-real-time-data-theft-via-phaas</link><guid isPermaLink="true">https://runtimerebel.com/blog/jwr-phishing-framework-real-time-data-theft-via-phaas</guid><description>The JWR phishing framework, a variant of The Outsider PhaaS, harvests payment data, PII, and 2FA codes in real-time via operator-controlled sessions.</description><pubDate>Thu, 13 Aug 2026 16:47:48 GMT</pubDate><category>Phishing</category><category>PhaaS</category><category>Credential Theft</category><category>PII</category><category>JWR</category></item><item><title>Webmail CSS Injection: Hidden Data Exfiltration Threats</title><link>https://runtimerebel.com/blog/webmail-css-injection-hidden-data-exfiltration-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/webmail-css-injection-hidden-data-exfiltration-threats</guid><description>Security researchers warn that Cascading Style Sheets can exfiltrate sensitive data from webmail inboxes if vendors fail to sanitize styles.</description><pubDate>Mon, 10 Aug 2026 01:01:51 GMT</pubDate><category>Web Security</category><category>Data Exfiltration</category><category>Phishing</category><category>Vulnerabilities</category></item><item><title>Zero-Click AI Browser Hacking Threatens Claude and ChatGPT Atlas</title><link>https://runtimerebel.com/blog/zero-click-ai-browser-hacking-threatens-claude-and-chatgpt-atlas</link><guid isPermaLink="true">https://runtimerebel.com/blog/zero-click-ai-browser-hacking-threatens-claude-and-chatgpt-atlas</guid><description>Zenity details zero-click indirect prompt injection vulnerabilities affecting OpenAI ChatGPT Atlas and Claude in Chrome via malicious web content.</description><pubDate>Mon, 10 Aug 2026 01:00:52 GMT</pubDate><category>Zero-Day</category><category>Phishing</category><category>Credential Theft</category><category>Artificial Intelligence</category><category>Zenity</category></item><item><title>ClickFix Attacks Deliver macOS Stealer Targeting Crypto</title><link>https://runtimerebel.com/blog/clickfix-attacks-deliver-macos-stealer-targeting-crypto</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-attacks-deliver-macos-stealer-targeting-crypto</guid><description>ClickFix social engineering campaigns target macOS users with Go-based infostealers designed to drain cryptocurrency wallets and credentials.</description><pubDate>Mon, 10 Aug 2026 00:59:16 GMT</pubDate><category>macOS</category><category>Malware</category><category>Cryptocurrency</category><category>Phishing</category><category>Credential Theft</category></item><item><title>CVE-2025-66376: APT28 Exploits Zimbra Zero-Click for Espionage</title><link>https://runtimerebel.com/blog/cve-2025-66376-apt28-exploits-zimbra-zero-click-for-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-66376-apt28-exploits-zimbra-zero-click-for-espionage</guid><description>Russian state-sponsored actors exploit a zero-click Zimbra vulnerability (CVE-2025-66376) to exfiltrate sensitive webmail data from targeted organizations.</description><pubDate>Sat, 08 Aug 2026 08:33:35 GMT</pubDate><category>CVE-2025-66376</category><category>Zimbra</category><category>Cyber Espionage</category><category>Zero Click</category><category>Phishing</category></item><item><title>Q2 2026 IR Trends: Phishing, MFA Bypass, RMM Tool Abuse</title><link>https://runtimerebel.com/blog/q2-2026-ir-trends-phishing-mfa-bypass-rmm-tool-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/q2-2026-ir-trends-phishing-mfa-bypass-rmm-tool-abuse</guid><description>Talos Q2 2026 incident response data shows rising phishing and MFA bypass, with new actors like UAT-11764 and Sinobi ransomware leveraging RMM tools.</description><pubDate>Sat, 08 Aug 2026 00:57:13 GMT</pubDate><category>Phishing</category><category>MFA Bypass</category><category>Ransomware</category><category>Microsoft 365</category><category>UAT 11764</category></item><item><title>UNC6671 Rebrands: Multi-Brand Vishing and Cloud Extortion</title><link>https://runtimerebel.com/blog/unc6671-rebrands-multi-brand-vishing-and-cloud-extortion</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6671-rebrands-multi-brand-vishing-and-cloud-extortion</guid><description>Google Threat Intelligence Group tracks UNC6671 shifting through Redact, Pink, Helix, and Falcon extortion brands while targeting cloud environments.</description><pubDate>Fri, 07 Aug 2026 02:12:08 GMT</pubDate><category>UNC6671</category><category>Phishing</category><category>Credential Theft</category><category>Ransomware</category><category>Cloud Security</category></item><item><title>Talos Q2 2026 Report: Phishing and Living-off-the-Land Trends</title><link>https://runtimerebel.com/blog/talos-q2-2026-report-phishing-and-living-off-the-land-trends</link><guid isPermaLink="true">https://runtimerebel.com/blog/talos-q2-2026-report-phishing-and-living-off-the-land-trends</guid><description>Cisco Talos Q2 2026 report reveals spikes in MFA-bypassing phishing and malicious use of remote management tools.</description><pubDate>Thu, 06 Aug 2026 01:57:17 GMT</pubDate><category>Phishing</category><category>Ransomware</category><category>Credential Theft</category><category>Multi Factor Authentication</category><category>Threat Intel</category></item><item><title>AI-Enabled Fraud: How Global Crime Syndicates Scale Scams</title><link>https://runtimerebel.com/blog/ai-enabled-fraud-how-global-crime-syndicates-scale-scams</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-enabled-fraud-how-global-crime-syndicates-scale-scams</guid><description>Organized crime syndicates use AI voice cloning, deepfake video, and LLMs to execute massive, scalable global financial fraud.</description><pubDate>Thu, 06 Aug 2026 01:56:44 GMT</pubDate><category>Phishing</category><category>Threat Intel</category><category>Machine Learning</category><category>Financial Fraud</category><category>Social Engineering</category></item><item><title>ClickFix Campaign Uses Server-Side Fingerprinting to Hide macOS Malware</title><link>https://runtimerebel.com/blog/clickfix-campaign-uses-server-side-fingerprinting-to-hide-macos-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-campaign-uses-server-side-fingerprinting-to-hide-macos-malware</guid><description>Over 250 ClickFix domains utilize server-side browser fingerprinting to evade security sandboxes and distribute macOS infostealers like AMOS.</description><pubDate>Thu, 06 Aug 2026 01:56:14 GMT</pubDate><category>Phishing</category><category>Malware</category><category>Credential Theft</category><category>macOS</category><category>Atomic Stealer</category></item><item><title>Smoke#Screen RMM Takeover Campaign Targets Enterprise Networks</title><link>https://runtimerebel.com/blog/smoke-screen-rmm-takeover-campaign-targets-enterprise-networks</link><guid isPermaLink="true">https://runtimerebel.com/blog/smoke-screen-rmm-takeover-campaign-targets-enterprise-networks</guid><description>Discover how the Smoke#Screen phishing campaign uses rotating payloads and ScreenConnect to achieve persistent remote network access.</description><pubDate>Wed, 05 Aug 2026 01:42:03 GMT</pubDate><category>Phishing</category><category>Ransomware</category><category>Credential Theft</category><category>Screenconnect</category></item><item><title>Device Code Phishing Surges 1,500% as Vishing Doubles</title><link>https://runtimerebel.com/blog/device-code-phishing-surges-1500-as-vishing-doubles</link><guid isPermaLink="true">https://runtimerebel.com/blog/device-code-phishing-surges-1500-as-vishing-doubles</guid><description>Device code phishing attacks surged 1,500% while vishing doubled, exploiting modern authentication flows to bypass traditional security controls.</description><pubDate>Tue, 04 Aug 2026 11:23:35 GMT</pubDate><category>Phishing</category><category>Social Engineering</category><category>Credential Theft</category><category>Identity Access</category><category>Multi Factor Authentication</category></item><item><title>Hotel Wi-Fi Campaigns Use CornFlake and ChocoShell Malware</title><link>https://runtimerebel.com/blog/hotel-wi-fi-campaigns-use-cornflake-and-chocoshell-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/hotel-wi-fi-campaigns-use-cornflake-and-chocoshell-malware</guid><description>Russian threat actor Midnight Blizzard targets hotel Wi-Fi networks using captive portal manipulation, DNS hijacking, and custom malware.</description><pubDate>Tue, 04 Aug 2026 01:28:40 GMT</pubDate><category>Midnight Blizzard</category><category>APT29</category><category>Credential Theft</category><category>Phishing</category><category>Malware</category></item><item><title>Phishing Targets AI Service Users: Guard Your ChatGPT Accounts</title><link>https://runtimerebel.com/blog/phishing-targets-ai-service-users-guard-your-chatgpt-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/phishing-targets-ai-service-users-guard-your-chatgpt-accounts</guid><description>Recent phishing campaigns impersonate popular AI services like ChatGPT to trick users into divulging credentials. Learn how to protect your accounts and data.</description><pubDate>Sat, 01 Aug 2026 10:02:17 GMT</pubDate><category>Phishing</category><category>AI Services</category><category>ChatGPT</category><category>Social Engineering</category><category>Credential Theft</category></item><item><title>Interpol&apos;s I-GRIP System Curtails Fraudulent Payments: A Threat Intel Brief</title><link>https://runtimerebel.com/blog/interpol-s-i-grip-system-curtails-fraudulent-payments-a-threat-intel-brief</link><guid isPermaLink="true">https://runtimerebel.com/blog/interpol-s-i-grip-system-curtails-fraudulent-payments-a-threat-intel-brief</guid><description>Explore Interpol&apos;s I-GRIP system, a global initiative enabling rapid freezing of fraudulent payments and enhancing international cooperation against cyber-enabled…</description><pubDate>Fri, 31 Jul 2026 14:11:22 GMT</pubDate><category>INTERPOL</category><category>Financial Fraud</category><category>Cybercrime</category><category>I GRIP</category><category>Payment Fraud</category><category>BEC</category><category>Phishing</category></item><item><title>OAuth 2.0 Device Code Phishing Escalates to Industrial Threat</title><link>https://runtimerebel.com/blog/oauth-2-0-device-code-phishing-escalates-to-industrial-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/oauth-2-0-device-code-phishing-escalates-to-industrial-threat</guid><description>Device code phishing, exploiting the OAuth 2.0 device authorization grant, is rapidly stealing access tokens. Learn how to defend against this growing threat.</description><pubDate>Fri, 31 Jul 2026 14:09:49 GMT</pubDate><category>Device Code Phishing</category><category>OAuth 2 0</category><category>Access Tokens</category><category>Phishing</category><category>Identity Theft</category></item><item><title>Chrome Security Update and SonicWall Targeted in AI-Driven Campaigns</title><link>https://runtimerebel.com/blog/chrome-security-update-and-sonicwall-targeted-in-ai-driven-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-security-update-and-sonicwall-targeted-in-ai-driven-campaigns</guid><description>Analysis of 370 Chrome vulnerabilities and active SonicWall targeting, highlighting the rise of AI-powered phishing and automated DNS hijacking threats.</description><pubDate>Thu, 30 Jul 2026 17:29:33 GMT</pubDate><category>Google Chrome</category><category>SonicWall</category><category>AI Powered Hacking</category><category>DNS Hijacking</category><category>Phishing</category></item><item><title>ShinyHunters Targeting Healthcare: Data Theft Surges, Health-ISAC Warns</title><link>https://runtimerebel.com/blog/shinyhunters-targeting-healthcare-data-theft-surges-health-isac-warns</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-targeting-healthcare-data-theft-surges-health-isac-warns</guid><description>Health-ISAC warns of increasing ShinyHunters data theft attacks on healthcare and med-tech organizations. Learn about TTPs and critical mitigations.</description><pubDate>Wed, 29 Jul 2026 20:57:58 GMT</pubDate><category>ShinyHunters</category><category>Healthcare</category><category>Data Theft</category><category>Health ISAC</category><category>Phishing</category><category>Data Exfiltration</category></item><item><title>ShinyHunters Data Leaks Fuel $2,000 Sextortion Phishing Campaign</title><link>https://runtimerebel.com/blog/shinyhunters-data-leaks-fuel-2000-sextortion-phishing-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-data-leaks-fuel-2000-sextortion-phishing-campaign</guid><description>Scammers are weaponizing personal data from ShinyHunters leaks to launch convincing sextortion campaigns demanding $2,000 in Bitcoin from victims.</description><pubDate>Sat, 25 Jul 2026 17:00:04 GMT</pubDate><category>ShinyHunters</category><category>Sextortion</category><category>Phishing</category><category>Data Breach</category><category>Social Engineering</category></item><item><title>BlueNoroff Zoom Phishing Kit Targets Crypto Wallets</title><link>https://runtimerebel.com/blog/bluenoroff-zoom-phishing-kit-targets-crypto-wallets</link><guid isPermaLink="true">https://runtimerebel.com/blog/bluenoroff-zoom-phishing-kit-targets-crypto-wallets</guid><description>BlueNoroff uses a custom phishing kit to profile crypto wallets before delivering malware through impersonated Zoom and Microsoft Teams platforms.</description><pubDate>Fri, 24 Jul 2026 17:39:06 GMT</pubDate><category>BlueNoroff</category><category>Lazarus Group</category><category>Cryptocurrency Theft</category><category>ClickFix</category><category>Phishing</category></item><item><title>Zimbra Zero-Day Exploited by Laundry Bear Against US &amp; Ukraine</title><link>https://runtimerebel.com/blog/zimbra-zero-day-exploited-by-laundry-bear-against-us-ukraine</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-zero-day-exploited-by-laundry-bear-against-us-ukraine</guid><description>Russian state-sponsored group &apos;Laundry Bear&apos; exploits a Zimbra zero-day via &apos;half-click&apos; phishing, targeting US and Ukrainian entities for credential theft and backdoor…</description><pubDate>Fri, 24 Jul 2026 02:47:14 GMT</pubDate><category>Laundry Bear</category><category>Zimbra</category><category>Zero-Day</category><category>Phishing</category><category>US</category><category>Ukraine</category><category>State Sponsored</category></item><item><title>Bing Ads Promote Fake Claude App, Deliver SectopRAT Malware</title><link>https://runtimerebel.com/blog/bing-ads-promote-fake-claude-app-deliver-sectoprat-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/bing-ads-promote-fake-claude-app-deliver-sectoprat-malware</guid><description>A malvertising campaign on Bing Search is distributing a fake Claude AI desktop app, leading to SectopRAT malware infections. Verify software sources.</description><pubDate>Thu, 23 Jul 2026 21:06:56 GMT</pubDate><category>Sectop RAT</category><category>Malvertising</category><category>Bing Ads</category><category>Claude AI</category><category>Information Stealer</category><category>Phishing</category></item><item><title>Zimbra Zero-Click Exploitation by Russian APT for Email Theft</title><link>https://runtimerebel.com/blog/zimbra-zero-click-exploitation-by-russian-apt-for-email-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-zero-click-exploitation-by-russian-apt-for-email-theft</guid><description>CISA warns of Russian APT Laundry Bear (Void Blizzard) exploiting a patched Zimbra zero-click flaw combined with phishing to compromise email servers for data…</description><pubDate>Thu, 23 Jul 2026 17:27:19 GMT</pubDate><category>Laundry Bear</category><category>Void Blizzard</category><category>APT28</category><category>Zimbra Collaboration</category><category>Zero Click</category><category>Email Theft</category><category>Phishing</category><category>Russian APT</category></item><item><title>Brazilian Banking Trojan Expansion into Portugal Targets Businesses</title><link>https://runtimerebel.com/blog/brazilian-banking-trojan-expansion-into-portugal-targets-businesses</link><guid isPermaLink="true">https://runtimerebel.com/blog/brazilian-banking-trojan-expansion-into-portugal-targets-businesses</guid><description>Portuguese businesses face increased risk from Brazilian banking trojans leveraging shared language for phishing and credential theft.</description><pubDate>Thu, 23 Jul 2026 10:27:20 GMT</pubDate><category>Banking Trojan</category><category>Portugal</category><category>Grandoreiro</category><category>Financial Crime</category><category>Phishing</category></item><item><title>Fake Bahrain Alert Apps Deploy Android Surveillance Malware</title><link>https://runtimerebel.com/blog/fake-bahrain-alert-apps-deploy-android-surveillance-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-bahrain-alert-apps-deploy-android-surveillance-malware</guid><description>Analyzing fake Bahrain alert apps distributing four-stage Android surveillance malware via phony app stores, exploiting geopolitical tensions for extensive data…</description><pubDate>Wed, 22 Jul 2026 21:12:30 GMT</pubDate><category>Android</category><category>Mobile Security</category><category>Spyware</category><category>Surveillance Malware</category><category>Fake Apps</category><category>Phishing</category><category>Social Engineering</category><category>Bahrain</category></item><item><title>Email Account Takeover via 2FA Compromise: Mitigating Identity Theft Risk</title><link>https://runtimerebel.com/blog/email-account-takeover-via-2fa-compromise-mitigating-identity-theft-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/email-account-takeover-via-2fa-compromise-mitigating-identity-theft-risk</guid><description>An identity theft incident highlights how easily email account takeover via compromised 2FA can lead to broader security breaches. Learn to protect your digital identity.</description><pubDate>Wed, 22 Jul 2026 17:24:17 GMT</pubDate><category>Identity Theft</category><category>Account Takeover</category><category>2FA Bypass</category><category>Email Security</category><category>Phishing</category><category>Social Engineering</category></item><item><title>Securing Critical Infrastructure: Closing Identity Gaps</title><link>https://runtimerebel.com/blog/securing-critical-infrastructure-closing-identity-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-critical-infrastructure-closing-identity-gaps</guid><description>Attacks on critical infrastructure leverage identity gaps. This analysis details common vulnerabilities and how Zero Trust principles can enhance sector security.</description><pubDate>Tue, 21 Jul 2026 17:24:12 GMT</pubDate><category>Critical Infrastructure</category><category>Identity Security</category><category>Zero Trust</category><category>Credential Theft</category><category>MFA Bypass</category><category>Supply Chain Attack</category><category>Phishing</category></item></channel></rss>