Glossary
Phishing
A social engineering attack that uses deceptive emails, messages, or websites to trick users into revealing sensitive information.
Recent coverage mentioning Phishing
CVE-2026-85880: Windows ALPC Heap Overflow Exploited
CISA confirms active exploitation of CVE-2026-85880, a heap-based buffer overflow in Microsoft Windows ALPC leading to local privilege escalation.
CVE-2026-81963: Windows Update Stack Privilege Escalation
CISA adds CVE-2026-81963 to the KEV catalog after confirming active exploitation of a Windows Update Stack privilege escalation flaw.
ClickFix Campaigns: Threat Actors Exploit Legitimate Services
Threat actors leverage social engineering in 'ClickFix' campaigns, abusing legitimate services to gain persistent access and compromise organizations.
ClickFix Variant Leverages Google API for Crypto Theft
A ClickFix social engineering variant abuses Google Visualization API and Google Sheets for C2, injecting web skimmers into browsers for cryptocurrency theft.
BigBear PhaaS Bypasses Microsoft 365 MFA at 258 Orgs
BigBear 2.0 PhaaS uses Evilginx2 AiTM to bypass Microsoft 365 MFA, stealing credentials and session cookies from 258 organizations.
Microsoft 365 Vishing Leads to Executive Data Theft, Extortion
A widespread threat cluster, PREY-0058, targets Microsoft 365 executives with vishing, AitM token theft, and data extortion.
Advertisement