The Bluekit phishing kit has received a significant upgrade that allows cybercriminals to steal authenticated user sessions more effectively. Security researchers have discovered that the phishing-as-a-service (PhaaS) platform now supports browser-in-the-middle (BitM) attacks, replacing its previous interception technique with a more advanced method for compromising online accounts. The latest version also introduces additional evasion capabilities,…
A WhatsApp phishing attack is targeting businesses with fake document requests that lead to malware infections. Researchers say attackers are posing as business contacts and sending messages that appear to contain legitimate files. Instead of delivering invoices or contracts, the campaign installs ConnectWise RAT, a remote access tool that allows attackers to take control of…
Football fans searching for free World Cup coverage are facing a growing wave of online threats. Security researchers have uncovered more than 40 websites posing as free streaming platforms for the 2026 FIFA World Cup. While these sites promise live access to matches, many serve a different purpose entirely. Instead of delivering reliable streams, the…
An AI phishing service disrupted by U.S. authorities has exposed the growing role of artificial intelligence in cybercrime. The FBI, working alongside Google and security researchers, helped dismantle a large-scale phishing operation known as Outsider. Investigators linked the service to more than one million malicious URLs designed to steal credentials and payment card information from…
Meta says it has disrupted a new campaign of WhatsApp phishing attacks linked to spyware vendor NSO Group. The company claims the activity violated a court order that permanently prohibited NSO from targeting WhatsApp users after a lengthy legal battle over the deployment of Pegasus spyware. The latest discovery suggests that efforts to target WhatsApp…
Visitors to several well-known websites recently faced an unexpected threat when fake Microsoft login prompts began appearing on pages associated with trusted brands. Security researchers traced the activity to a Polyfill-related compromise that allowed attackers to inject phishing content into legitimate websites, including pages connected to Toshiba and Muji. The incident demonstrates how cybercriminals continue…
Cybercriminals are targeting hotel guests with convincing payment scams after a data breach affected more than 100 hotels across Europe. The incident exposed reservation information belonging to travelers staying at properties in the Netherlands, Belgium, and Ireland. Attackers are now using the stolen data to send phishing messages that appear to come from legitimate hotels,…
Security researchers have uncovered a malware-as-a-service platform called BTMOB malware that allows cybercriminals to generate custom Android phishing payloads with minimal technical knowledge. The service gives attackers tools to create malicious Android applications, manage phishing campaigns, and remotely control infected devices. Researchers warned that the platform lowers the barrier for cybercriminals looking to target Android…
The FBI warned that cybercriminals are increasingly using the Kali365 phishing kit to hijack Microsoft 365 accounts while bypassing multi-factor authentication protections. According to investigators, Kali365 operates as a phishing-as-a-service platform distributed through Telegram channels and underground cybercrime communities. Instead of stealing passwords directly, the toolkit focuses on stealing OAuth access tokens and authenticated sessions.…
The Tycoon2FA phishing platform has resurfaced with a new attack method designed to hijack Microsoft 365 accounts through device-code phishing. Researchers warn that the updated campaign allows attackers to gain account access without directly stealing passwords, making the attacks more difficult to detect and block. Tycoon2FA already gained attention for bypassing multi-factor authentication through adversary-in-the-middle…