2FA phishing
-
Oxford University says CareerConnect breach exposed user names, emails and passwords
Oxford University said a breach of its third-party CareerConnect platform exposed user names, email addresses and encrypted passwords on May 28. The university said its own systems were not compromised and warned of possible phishing attempts.
-
China-linked TA4922 widens phishing attacks to Europe and South Africa
China-linked TA4922 has expanded phishing campaigns from East Asia to organizations in the U.K., Germany, Italy and South Africa, using malware such as Atlas RAT, RomulusLoader and SilentRunLoader, according to a Proofpoint technical analysis.
-
Malspam campaign uses Google DoubleClick redirect chain to deliver DesckVB RAT
A malspam campaign is using Google DoubleClick redirects and personalized phishing pages to deliver DesckVB RAT, a .NET trojan. The attack chain uses HTML attachments, PowerShell, process hollowing, and anti-analysis checks.
-
ChatGPhish flaw can turn ChatGPT summaries into phishing lures
Researchers disclosed ChatGPhish, a ChatGPT flaw that can render malicious links, images and QR codes inside summaries of web pages. The technique may leak browser details and create a new phishing surface during normal browsing.
-
GREYVIBE campaign targets Ukraine with phishing, fake sites and AI tools
GREYVIBE has targeted Ukraine-linked entities since at least August 2025 using phishing, fake CAPTCHA pages and fraudulent websites, while a WithSecure analysis says the group appears to have used AI tools to speed malware development.
-
Fake LinkedIn emails abuse Adobe service in phishing campaign
A phishing campaign is using fake LinkedIn business emails and Adobe Target to hide credential theft, with attackers disguising HTML attachments as PDFs and redirecting victims to a real LinkedIn page after login.
-
FBI warns of fake FIFA sites ahead of 2026 World Cup
The FBI warned that fake FIFA websites are being used ahead of the 2026 World Cup to steal data, sell bogus tickets and push other scams. Researchers said hundreds of phishing sites and related campaigns are already active.
-
Grandoreiro and BTMOB campaigns target banking users in Europe and Latin America
Researchers say Grandoreiro and BTMOB are being used in separate campaigns against banking users in Europe and Latin America, combining phishing, DLL side-loading and Android social engineering with malware-as-a-service sales.
-
INTERPOL says MENA cybercrime operation leads to 201 arrests
INTERPOL said a five-month crackdown across the Middle East and North Africa led to 201 arrests, 382 additional suspects and 53 server seizures in an operation targeting phishing, malware and online scams.
-
Ghostwriter targets Ukrainian government entities in fresh phishing campaign
Ghostwriter has been tied to new attacks on Ukrainian government entities since March 2026, using malicious PDFs, geofencing checks and a JavaScript version of PicassoLoader to deliver Cobalt Strike, according to an ESET technical analysis.








