The ManageWP phishing attack is targeting WordPress administrators through malicious Google Ads that impersonate the legitimate ManageWP login page. Researchers discovered that attackers are purchasing sponsored Google search results designed to trick users into entering their GoDaddy credentials through fake login portals. The campaign specifically targets users of ManageWP, a GoDaddy-owned platform used to manage…
A growing ses phishing trend is raising concerns across the cybersecurity landscape. Attackers now exploit Amazon’s email infrastructure to send convincing phishing messages that slip past traditional security controls. Because these emails come from a trusted source, they often reach inboxes without triggering alerts. This shift shows how attackers adapt their methods. Instead of relying…
A new Bluekit phishing service is lowering the barrier for cybercriminals to run large-scale campaigns. By combining automation, ready-made templates, and AI tools, the platform simplifies what used to require advanced technical skills. What the platform includes The Bluekit phishing service operates as a phishing-as-a-service toolkit. It offers more than 40 templates designed to imitate…
The Robinhood phishing email flaw allowed attackers to send fake security alerts from legitimate company email addresses. Specifically, the issue originated in the account creation process, where attackers manipulated input fields to inject phishing content. As a result, this incident shows how trusted systems can be abused even without a direct breach. Account creation flow…
The Apple iCloud phishing scam is targeting users with fake warnings that their data will be deleted. These messages mimic official Apple alerts and pressure users to act quickly. The attack relies on urgency and trust. Users who respond risk exposing their Apple ID and personal data. Fake alerts imitate Apple communication The phishing emails…
Device code phishing is scaling fast. Attackers have increased activity by 37 times as new phishing kits spread online. What once required technical skill now comes packaged into simple tools. This shift turns a quiet technique into a mainstream threat. Attackers Exploit Trusted Login Flows Attackers abuse a legitimate device login process to run this…
LinkedIn phishing emails are targeting users with convincing fake job offers that lead to credential theft. These messages look authentic and create urgency, which pushes victims to click before verifying the source. Once they interact, attackers move quickly to capture sensitive login details. This campaign shows how phishing tactics continue to improve. Instead of exploiting…
The Dutch police phishing attack shows how a single compromised account can trigger a wider security incident. Attackers gained access through social engineering and moved into internal systems, exposing sensitive data linked to police personnel. The case highlights how human-targeted attacks can bypass strong technical defenses. Phishing opened the door to internal systems Attackers launched…
A TikTok phishing attack is targeting business accounts with a method that goes beyond traditional scams. Instead of simply stealing login details, attackers intercept sessions in real time, allowing them to bypass two-factor authentication and gain direct access to accounts. The campaign focuses on TikTok for Business users, where access to advertising tools and account…
The Bubble AI phishing attack shows how threat actors are shifting tactics. Instead of using suspicious infrastructure, attackers now rely on legitimate platforms to host phishing content. This approach increases trust and reduces the chance of detection. As a result, users are more likely to interact with malicious links. No-code apps used to deliver phishing…