The FBI Atlanta Field Office and Indonesian authorities have dismantled the „W3LL“ global phishing platform, seizing infrastructure and arresting the alleged developer in what is described as the first coordinated enforcement action between the United States and Indonesia targeting a phishing kit developer. […]
How Phishing Kits Targeting U.S. Giants Are Built, Sold, and Deployed Modern phishing kits can steal authenticated sessions from Microsoft 365 and Google accounts in real time, even when MFA is enabled, and access to those kits can cost as little as $120 for ten days. That low barrier to entry shows how far the […]
Threat actors using a previously undocumented phishing-as-a-service (PhaaS) platform called „VENOM“ are targeting credentials of C-suite executives across multiple industries. […]
By hiding malicious instructions on an attacker-controlled Web page, AI could ingest orders that appear benign but return sensitive data to the attacker’s server.
Since January 2026, CERT-UA has been tracking a series of intrusions attributed to UAC-0252 and built around SHADOWSNIFF and SALATSTEALER infostealers. The campaigns rely on well-crafted phishing lures, payload staging on legitimate infrastructure, and user-driven execution of disguised EXE files. Detect UAC-0252 Attacks Covered in CERT-UA#Adresse geschuetztPhishing Trends Q2 2025 research by […] The post […]
Device code phishing attacks that abuse the OAuth 2.0 Device Authorization Grant flow to hijack accounts have surged more than 37 times this year. […]