phishing

New Ghost Phishing Wave Is Breaking Traditional Email Security

A new “ghost phishing” campaign called EvilTokens uses encrypted phishing pages that only decrypt and display malicious content within the victim's browser, bypassing traditional email and URL security checks. This technique primarily targets Microsoft 365 users across industries in the US and Europe, enabling account takeover without stealing passwords directly and complicating detection and response efforts. Security teams are urged to adopt browser-level sandboxing tools that reveal hidden phishing behaviors in real time to shorten exposure windows and improve incident containment.

https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html

Entra Passkey Enrollment Vishing Targets Microsoft 365 Users

A threat actor tracked as O-UNC-066 has been conducting vishing campaigns targeting Microsoft 365 users across multiple industries by impersonating Microsoft Entra passkey enrollment processes. Attackers use phishing sites mimicking legitimate enrollment portals to trick victims into registering passkeys controlled by the attacker, enabling account takeover and data theft from SharePoint and OneDrive. The extortion group Pink, associated with this campaign, exfiltrates stolen data and pressures victims for ransom payments.

https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/

When Checking the URL Isn’t Enough: Phishing Via the Microsoft Identity Platform

The article discusses a sophisticated phishing technique that abuses the Microsoft identity platform’s device code flow, making it difficult to detect purely by checking URLs. Attackers leverage this method to bypass traditional phishing defenses by exploiting trusted Microsoft OAuth authentication processes, highlighting the need for enhanced vigilance and security measures beyond URL inspection to defend against such threats.

https://securelist.com/microsoft-device-code-phishing-attack/120350/

The Booking.com Phishing Campaign Targeting Hotels and Customers

Since January 2026, a phishing campaign has targeted hotels and their customers by impersonating Booking.com to conduct financial fraud. The attack unfolds in three stages: initial phishing emails sent to hotel partners to harvest credentials via a partner phishing kit, followed by customer-targeted phishing to steal financial information, delivered in part through WhatsApp. The campaign uses domain spoofing, typosquatting, and advanced evasion techniques such as user fingerprinting to avoid detection, posing significant risks to the hospitality sector.

https://www.bridewell.com/insights/blogs/detail/the-booking.com-phishing-campaign-targeting-hotels-and-customers

Cybersecurity Firms Targeted by Fraudulent OpenAI Organization Invites

Threat actors have been creating fraudulent OpenAI ChatGPT organizations impersonating legitimate companies, such as Push Security, to send legitimate-looking invitations to targeted employees with the goal of tricking them into sharing sensitive company information. These attacker-controlled tenants assign invitees administrative privileges and include payment methods to appear credible, enabling them to collect confidential data submitted within the workspace. Security experts warn this reflects a growing tactic of abusing legitimate SaaS invitation systems to bypass email security measures and recommend staff training and monitoring of SaaS memberships to mitigate risks.

https://www.bleepingcomputer.com/news/security/cybersecurity-firms-targeted-by-fraudulent-openai-organization-invites/

Mirage2FA Phishing Kit Uses HTML Smuggling to Steal Microsoft 365 Credentials

Researchers at Fortra uncovered Mirage2FA, a phishing kit that uses HTML smuggling and obfuscated JavaScript to deploy fake Microsoft 365 login pages, tricking users into submitting credentials and multi-factor authentication details. The campaign employs business-themed lures and short-lived domains to carry out Microsoft 365 account takeovers, potentially exposing email, files, Teams messages, and other cloud resources. Users affected are advised to reset passwords, revoke sessions, review MFA methods, and check for unauthorized mailbox access.

https://www.helpnetsecurity.com/2026/06/26/mirage2fa-phishing-kit-microsoft-365-html-smuggling/

A Backdoor in a LinkedIn Job Offer

A LinkedIn message from a recruiter at a crypto startup led Roman Imankulov to analyze a suspicious GitHub repo purportedly needing a Node modules review. The repo contained a hidden backdoor in a test file that executed arbitrary code fetched from a remote server whenever dependencies were installed, triggered by an npm lifecycle script. The repo and recruiter used stolen identities, highlighting the risk of supply-chain and social engineering attacks via seemingly legitimate job offers.

https://roman.pt/posts/linkedin-backdoor/

These Convincing Copyright Notices Are Designed to Steal Google Logins

A new phishing scam targets Chrome extension developers with fake copyright removal notices designed to steal Google login credentials. The scam uses publicly available extension information to create convincing personalized warnings and a fake Google sign-in window, pressuring victims to enter their credentials before a fabricated deadline. Developers are advised to verify warnings only through their Chrome Web Store dashboard and to safeguard accounts with strong authentication and security software.

https://www.malwarebytes.com/blog/threat-intel/2026/06/these-convincing-copyright-notices-are-designed-to-steal-google-logins

ChatGPhish: The Page Is the Payload

Researchers discovered a new phishing and tracking attack called ChatGPhish that exploits ChatGPT's page summarization feature by injecting malicious Markdown links and images into web pages. When users summarize such pages in ChatGPT, the assistant renders active clickable links, spoofed alerts, and QR codes within its trusted interface, enabling phishing, cross-origin data leakage, and off-device attacks without traditional browser protections. This expands the attack surface from email to everyday browsing, highlighting risks in AI-generated outputs that automatically render untrusted external content inside trusted AI interfaces.

https://permiso.io/blog/chatgpt-markdown-rendering-vulnerability

Thousands of Facebook Accounts Stolen by Phishing Emails Sent Through Google

Researchers have uncovered a phishing operation using Google’s AppSheet platform to send deceptive emails that have compromised around 30,000 Facebook business and advertiser accounts, primarily targeting pages with financial value. This campaign abuses trusted Google services to bypass email filters, tricking users into providing Facebook credentials and 2FA codes, enabling attackers to monetize hijacked accounts by running scams or selling access.

https://www.malwarebytes.com/blog/news/2026/05/thousands-of-facebook-accounts-stolen-by-phishing-emails-sent-through-google

Phishing — Sometimes with AI’s Help — Topped Initial-Access Methods in Q1, Cisco Says

In the first quarter of 2026, phishing—sometimes aided by AI tools like the Softr platform—was the most common method hackers used to gain initial access, according to Cisco’s Talos threat intelligence report. Attackers leveraged AI to quickly create fake login pages for credential harvesting without coding, targeting mainly government and health-care sectors, with deficient multifactor authentication being the leading security weakness exploited.

https://www.cybersecuritydive.com/news/phishing-initial-access-ai-cisco/818185/

Hundreds of Orgs Compromised Daily in Microsoft Device Code Phishing Attacks

A widespread Microsoft device-code phishing campaign has been compromising hundreds of organizations daily since mid-March 2026, using AI and automation to bypass multi-factor authentication and gain access to corporate Microsoft 365 accounts. The attackers generate dynamic device codes to trick victims into authorizing access, enabling them to steal sensitive financial emails and data, with the phishing infrastructure leveraging legitimate cloud services to evade detection. Microsoft recommends limiting the use of device code authentication and training employees to recognize phishing attempts to mitigate such attacks.

https://www.theregister.com/2026/04/07/microsoft_device_code_phishing/

New VENOM Phishing Attacks Steal Senior Executives’ Microsoft Logins

Threat actors using a new phishing-as-a-service platform called VENOM have been targeting Microsoft logins of senior executives since at least last November. The attacks impersonate Microsoft SharePoint notifications with highly personalized emails and QR codes leading victims to sophisticated credential-harvesting pages that bypass traditional protections like MFA, highlighting the need for stronger authentication measures such as FIDO2 and stricter access policies.

https://www.bleepingcomputer.com/news/security/new-venom-phishing-attacks-steal-senior-executives-microsoft-logins/

Tycoon2FA Phishing Platform Returns After Recent Police Disruption

The Tycoon2FA phishing-as-a-service platform, disrupted by Europol and partners through the seizure of 330 domains in early March 2026, has quickly resumed operations to pre-disruption levels. Despite the takedown, CrowdStrike observed a rapid recovery using largely unchanged tactics, highlighting that without arrests or physical seizures, cybercriminals can swiftly restore their infrastructure due to continued demand in the phishing ecosystem.

https://www.bleepingcomputer.com/news/security/tycoon2fa-phishing-platform-returns-after-recent-police-disruption/

Hackers Target Cybersecurity Firm Outpost24 in 7-Stage Phish

Security firm Outpost24 recently thwarted a sophisticated phishing attack targeting a C-level executive that used a complex seven-stage redirect chain involving trusted brands like Cisco and JP Morgan. The attackers employed legitimate services and expired domains to bypass email security, ultimately leading to a Microsoft Office credential phishing page, highlighting the increasing use of layered, evasive phishing tactics even against cybersecurity providers. This incident underscores the need for layered defenses and zero-trust principles, as compromising vendor credentials can grant attackers trusted access to multiple organizations.

https://www.darkreading.com/threat-intelligence/hackers-target-cybersecurity-firm-outpost24-phish

Scroll to Top