# Phishing

Published articles for Phishing.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Fake parcel delivery messages steal your card and bank details

DevFeed: [Fake parcel delivery messages steal your card and bank details](<https://devfeed.tech/articles/fake-parcel-delivery-messages-steal-your-card-and-bank-details-42790.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/scams/2026/09/fake-parcel-delivery-messages-steal-your-card-and-bank-details>)

Author: Mieke Verburgh

Published: 2026-09-18T07:44:22Z

Content type: article

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [online privacy](<https://devfeed.tech/topics/online-privacy.md>)

Tags: [banking](<https://devfeed.tech/tags/banking.md>), [card](<https://devfeed.tech/tags/card.md>), [delivery](<https://devfeed.tech/tags/delivery.md>), [email](<https://devfeed.tech/tags/email.md>), [financial](<https://devfeed.tech/tags/financial.md>), [personal](<https://devfeed.tech/tags/personal.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [scams](<https://devfeed.tech/tags/scams.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

The article describes parcel-delivery phishing campaigns that impersonate postal and courier services. A Belgian bpost campaign uses a small unpaid-customs-fee claim to direct victims to a fake website that collects personal, card, and banking information.

### Source excerpt

Parcel delivery phishing messages impersonate familiar couriers and use small fees or promised refunds to steal personal and financial information.

## Revolut phishing texts appear days after data breach

DevFeed: [Revolut phishing texts appear days after data breach](<https://devfeed.tech/articles/revolut-phishing-texts-appear-days-after-data-breach-42143.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-days-after-data-breach>)

Author: Pieter Arntz

Published: 2026-09-17T14:07:15Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [breach](<https://devfeed.tech/tags/breach.md>), [password](<https://devfeed.tech/tags/password.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [revolut](<https://devfeed.tech/tags/revolut.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

Revolut customers received phishing texts days after the bank disclosed customer data to a government impostor. The report says the campaign's connection to the breach is not yet known and describes a fake identity check designed to obtain passwords.

### Source excerpt

Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.

## T-Mobile rewards points expiry texts are a phishing scam

DevFeed: [T-Mobile rewards points expiry texts are a phishing scam](<https://devfeed.tech/articles/t-mobile-rewards-points-expiry-texts-are-a-phishing-scam-41305.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/threat-intel/2026/09/t-mobile-rewards-points-expiry-texts-are-a-phishing-scam>)

Author: Pieter Arntz

Published: 2026-09-17T10:44:01Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [account](<https://devfeed.tech/topics/account.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [customer](<https://devfeed.tech/tags/customer.md>), [links](<https://devfeed.tech/tags/links.md>), [messages](<https://devfeed.tech/tags/messages.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [points](<https://devfeed.tech/tags/points.md>), [reward-points](<https://devfeed.tech/tags/reward-points.md>), [rewards-points](<https://devfeed.tech/tags/rewards-points.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>), [t-mobile](<https://devfeed.tech/tags/t-mobile.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

Malwarebytes reports a phishing campaign that sends fake T-Mobile rewards-point expiry messages. The messages use invented balances, urgent expiry dates, and phishing links to pressure recipients into clicking before verifying the claim.

### Source excerpt

A large phishing campaign is using fake T-Mobile rewards points and looming expiry dates to pressure recipients into clicking malicious links.

## Search results are sending people to fake Bitrefill checkouts

DevFeed: [Search results are sending people to fake Bitrefill checkouts](<https://devfeed.tech/articles/search-results-are-sending-people-to-fake-bitrefill-checkouts-26613.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts>)

Author: Stefan Dasic

Published: 2026-09-15T08:40:22Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [Bitcoin](<https://devfeed.tech/topics/bitcoin.md>), [Website](<https://devfeed.tech/topics/website.md>)

Tags: [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [payments](<https://devfeed.tech/tags/payments.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [qr-code](<https://devfeed.tech/tags/qr-code.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>), [search](<https://devfeed.tech/tags/search.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

Fake Bitrefill checkout pages are appearing in search results and copying the company's branding and payment flow. They persuade victims to send cryptocurrency to scammer-controlled addresses, with no goods delivered and little chance of recovering the payment.

### Source excerpt

Fake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers.

## Revolut falls for fake government requests, hands over customer data

DevFeed: [Revolut falls for fake government requests, hands over customer data](<https://devfeed.tech/articles/revolut-falls-for-fake-government-requests-hands-over-customer-data-17407.md>)

Original publisher: [Read original article](<https://www.theregister.com/cyber-crime/2026/09/14/revolut-falls-for-fake-government-requests-hands-over-customer-data/5296118>)

Author: Connor Jones

Published: 2026-09-14T11:26:00Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [customer](<https://devfeed.tech/tags/customer.md>), [cyber-crime](<https://devfeed.tech/tags/cyber-crime.md>), [data](<https://devfeed.tech/tags/data.md>), [phishing](<https://devfeed.tech/tags/phishing.md>)

### AI overview

Revolut handed over passports, selfies, and transaction histories after attackers used fake government requests and claimed responsibility for a crime while demanding 10,000 Bitcoin.

### Source excerpt

Passports, selfies, transaction histories exposed as self-proclaimed culprits demand 10,000 Bitcoin

## UK.gov begins killing off passwords for 23 million users

DevFeed: [UK.gov begins killing off passwords for 23 million users](<https://devfeed.tech/articles/uk-gov-begins-killing-off-passwords-for-23-million-users-17411.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/14/ukgov-begins-killing-off-passwords-for-23-million-users/5296088>)

Author: Carly Page

Published: 2026-09-14T09:16:11Z

Content type: article

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [government-of-the-united-kingdom](<https://devfeed.tech/tags/government-of-the-united-kingdom.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [uk](<https://devfeed.tech/tags/uk.md>), [whitehall](<https://devfeed.tech/tags/whitehall.md>)

### AI overview

The UK government is beginning to replace passwords with passkeys for 23 million users. The change is intended to reduce phishing problems and save Whitehall approximately GBP 600 per day in SMS costs.

### Source excerpt

Passkeys promise fewer phishing headaches - and GBP 600 a day off Whitehall's SMS bill

## The aircraft might not be flying, but the certificate has gone on vacation

DevFeed: [The aircraft might not be flying, but the certificate has gone on vacation](<https://devfeed.tech/articles/the-aircraft-might-not-be-flying-but-the-certificate-has-gone-on-vacation-8547.md>)

Original publisher: [Read original article](<https://www.theregister.com/offbeat/2026/09/12/the-aircraft-might-not-be-flying-but-the-certificate-has-gone-on-vacation/5295622>)

Author: Richard Speed

Published: 2026-09-12T09:00:00Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [NVLink](<https://devfeed.tech/topics/nvlink.md>), [Vibe coding](<https://devfeed.tech/topics/vibe-coding.md>), [ARKTunnel](<https://devfeed.tech/topics/arktunnel.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [.NET](<https://devfeed.tech/topics/net.md>), [how to create smooth CSS transitions](<https://devfeed.tech/topics/how-to-create-smooth-css-transitions.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [bork](<https://devfeed.tech/tags/bork.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [malware](<https://devfeed.tech/tags/malware.md>), [nvidia](<https://devfeed.tech/tags/nvidia.md>), [offbeat](<https://devfeed.tech/tags/offbeat.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [tailwind](<https://devfeed.tech/tags/tailwind.md>), [ubuntu](<https://devfeed.tech/tags/ubuntu.md>)

### AI overview

A news roundup covering security incidents, AI-related developments, semiconductor infrastructure, phishing, ransomware, open-source software, and web development. The supplied title concerns an aircraft certificate, while the body mainly contains unrelated headlines.

### Source excerpt

Information is not forthcoming from this screen

## Crypto customers targeted by scammers after email marketing provider breach

DevFeed: [Crypto customers targeted by scammers after email marketing provider breach](<https://devfeed.tech/articles/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach-8437.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach>)

Author: Pieter Arntz

Published: 2026-09-11T15:01:53Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [incident](<https://devfeed.tech/topics/incident.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [breach](<https://devfeed.tech/tags/breach.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [news](<https://devfeed.tech/tags/news.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [scams](<https://devfeed.tech/tags/scams.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

A Brevo breach enabled phishing emails targeting cryptocurrency-company newsletter subscribers. The attacker exploited a SAML SSO handling flaw, accessed 138 accounts, and used some accounts to send phishing messages or export contacts.

### Source excerpt

A breach at email marketing company Brevo exposed Trezor, CoinTracking, and BitBox customers to phishing emails, but others may also be at risk.

## Android malware creates a hidden copy of your banking app

DevFeed: [Android malware creates a hidden copy of your banking app](<https://devfeed.tech/articles/android-malware-creates-a-hidden-copy-of-your-banking-app-8435.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/mobile/2026/09/android-malware-creates-a-hidden-copy-of-your-banking-app>)

Author: Pieter Arntz

Published: 2026-09-11T12:14:55Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [app](<https://devfeed.tech/tags/app.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [news](<https://devfeed.tech/tags/news.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [profile](<https://devfeed.tech/tags/profile.md>), [security](<https://devfeed.tech/tags/security.md>), [transactions](<https://devfeed.tech/tags/transactions.md>)

### AI overview

Gigabud is an Android banking Trojan that creates a work profile and clones a banking app so operators can conduct fraudulent transactions separately from malware detected in the personal profile.

### Source excerpt

The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.

## Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research

DevFeed: [Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research](<https://devfeed.tech/articles/latest-anthropic-horror-story-chills-with-tales-of-kamikaze-drone-swarms-and-bioweapons-research-8530.md>)

Original publisher: [Read original article](<https://www.theregister.com/ai-and-ml/2026/09/10/latest-anthropic-horror-story-chills-with-tales-of-kamikaze-drone-swarms-and-bioweapons-research/5295702>)

Author: Jessica Lyons

Published: 2026-09-10T22:38:35Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Cloaked Ursa](<https://devfeed.tech/topics/cloaked-ursa.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-and-ml](<https://devfeed.tech/tags/ai-and-ml.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [bioweapons](<https://devfeed.tech/tags/bioweapons.md>), [claude](<https://devfeed.tech/tags/claude.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [scams](<https://devfeed.tech/tags/scams.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Anthropic says malicious actors used Claude models in attempted or disrupted cyber, surveillance, fraud, biological, and weapons-related activity. The article highlights alleged AI-assisted automation of cyberattack workflows by a Russian espionage group.

### Source excerpt

Everyone from ShinyHunters to Russian freelancers is in on the illicit model fun

## Detect and disrupt AI-themed attacks with Microsoft Defender

DevFeed: [Detect and disrupt AI-themed attacks with Microsoft Defender](<https://devfeed.tech/articles/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender-7644.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/10/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender/>)

Author: Rob Lefferts

Published: 2026-09-10T16:00:00Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [adversary-in-the-middle-aitm](<https://devfeed.tech/tags/adversary-in-the-middle-aitm.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [claude](<https://devfeed.tech/tags/claude.md>), [copilot](<https://devfeed.tech/tags/copilot.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [deepseek](<https://devfeed.tech/tags/deepseek.md>), [defender](<https://devfeed.tech/tags/defender.md>), [github](<https://devfeed.tech/tags/github.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

Microsoft describes AI-themed phishing, malvertising, credential theft, and malware campaigns that impersonate popular AI services and tools. It argues that attackers are exploiting trust and urgency around AI brands rather than compromising the referenced services.

### Source excerpt

See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.

## BlueMoon exploit kit turns Chrome and Windows flaws into attacks

DevFeed: [BlueMoon exploit kit turns Chrome and Windows flaws into attacks](<https://devfeed.tech/articles/bluemoon-exploit-kit-turns-chrome-and-windows-flaws-into-attacks-8432.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/bugs/2026/09/bluemoon-exploit-kit-turns-chrome-and-windows-flaws-into-attacks>)

Author: Pieter Arntz

Published: 2026-09-10T15:49:13Z

Content type: article

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [BlueMoon](<https://devfeed.tech/topics/bluemoon.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Google](<https://devfeed.tech/topics/google.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [bluemoon](<https://devfeed.tech/tags/bluemoon.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [news](<https://devfeed.tech/tags/news.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

BlueMoon is a shared exploit kit used by four espionage groups to exploit recently patched Chrome V8 and Windows vulnerabilities after phishing clicks. The article argues that attackers can weaponize public fixes quickly, making prompt patch deployment important; AI assistance is suggested only as an unproven possibility.

### Source excerpt

Four different espionage groups used the same exploit kit to target recently fixed flaws, showing why "patch later" is a dangerous gamble.

## Trezor, BitBox users targeted in newsletter phishing spree

DevFeed: [Trezor, BitBox users targeted in newsletter phishing spree](<https://devfeed.tech/articles/trezor-bitbox-users-targeted-in-newsletter-phishing-spree-8538.md>)

Original publisher: [Read original article](<https://www.theregister.com/cyber-crime/2026/09/10/trezor-bitbox-users-targeted-in-newsletter-phishing-spree/5295496>)

Author: Connor Jones

Published: 2026-09-10T11:30:00Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [cyber-crime](<https://devfeed.tech/tags/cyber-crime.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Attackers exploit legitimate mailing channels to demand crypto wallet backups from Trezor and BitBox users.

### Source excerpt

Attackers exploit legitimate mailing channels to demand crypto wallet backups

## Passkey-themed social engineering leads to identity and cloud compromise

DevFeed: [Passkey-themed social engineering leads to identity and cloud compromise](<https://devfeed.tech/articles/passkey-themed-social-engineering-leads-to-identity-and-cloud-compromise-7642.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/>)

Author: Microsoft Security Research, Krithika Ramakrishnan, Bharat Vaghela, Vaibhav Deshmukh, Subhajit Ghosh, Anusha Chakraborty, Akash Chaudhuri, Victor Chingtham and Ivan Macalintal

Published: 2026-09-09T17:41:18Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [MFA](<https://devfeed.tech/topics/mfa.md>), [data-processing](<https://devfeed.tech/topics/data-processing.md>)

Tags: [adversary-in-the-middle-aitm](<https://devfeed.tech/tags/adversary-in-the-middle-aitm.md>), [apis](<https://devfeed.tech/tags/apis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [data](<https://devfeed.tech/tags/data.md>), [identity](<https://devfeed.tech/tags/identity.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

Microsoft Security Research describes a passkey-themed social-engineering campaign that compromises cloud identities through AiTM phishing or device-code flows, establishes authentication persistence, and collects cloud data. It outlines investigation signals and recommends revoking sessions and removing unauthorized authentication methods after confirmed compromise.

### Source excerpt

Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance. The post Passkey-themed social engineering leads to identity and cloud compromise appeared first on Microsoft Security Blog.

## Black Hat USA 2026: Safeguarding DNS with Secure Access

DevFeed: [Black Hat USA 2026: Safeguarding DNS with Secure Access](<https://devfeed.tech/articles/black-hat-usa-2026-safeguarding-dns-with-secure-access-8407.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/bhusa-2026-soc-dns/>)

Author: Steve Vida

Published: 2026-09-07T15:00:32Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [NOC](<https://devfeed.tech/topics/noc.md>)

Tags: [apple](<https://devfeed.tech/tags/apple.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [cisco-secure-access](<https://devfeed.tech/tags/cisco-secure-access.md>), [cisco-security-cloud](<https://devfeed.tech/tags/cisco-security-cloud.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [cisco-xdr](<https://devfeed.tech/tags/cisco-xdr.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dns](<https://devfeed.tech/tags/dns.md>), [google](<https://devfeed.tech/tags/google.md>), [network-operations-center](<https://devfeed.tech/tags/network-operations-center.md>), [noc](<https://devfeed.tech/tags/noc.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [splunk-cloud](<https://devfeed.tech/tags/splunk-cloud.md>), [splunk-enterprise-security](<https://devfeed.tech/tags/splunk-enterprise-security.md>), [statistics](<https://devfeed.tech/tags/statistics.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

Cisco reports on using Secure Access and DNS telemetry to protect the Black Hat USA 2026 network. The article highlights blocking unapproved encrypted DNS resolvers, DNS request statistics, and activity classified as hacking.

### Source excerpt

Cisco is the Security Cloud Provider for the Black Hat conferences, over a decade providing DNS Security. Learn about protecting DNS with Secure Access.

## ASCII smuggling crosses over from AI prompt injection to phishing evasion

DevFeed: [ASCII smuggling crosses over from AI prompt injection to phishing evasion](<https://devfeed.tech/articles/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion-7640.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/>)

Author: Microsoft Security Research, Noam Kochavi and Sarah Wolstencroft

Published: 2026-09-03T16:00:00Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [ASCII](<https://devfeed.tech/topics/ascii.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Language models](<https://devfeed.tech/topics/language-models.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [ai-models](<https://devfeed.tech/tags/ai-models.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [ascii](<https://devfeed.tech/tags/ascii.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

Microsoft describes a phishing campaign that uses invisible Unicode tag characters to split lure words and evade email parsing. The technique, known as ASCII smuggling, was previously prominent in AI prompt-injection research because models can process hidden text that people cannot see.

### Source excerpt

Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog.

## Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

DevFeed: [Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](<https://devfeed.tech/articles/attackers-expose-ongoing-ai-tool-use-targeting-organizations-in-latin-america-7747.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/>)

Author: Reese Lewis and Sara McBroom

Published: 2026-09-03T10:00:58Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Language models](<https://devfeed.tech/topics/language-models.md>), [AI Chat](<https://devfeed.tech/topics/ai-chat.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [cl-cri-1131](<https://devfeed.tech/tags/cl-cri-1131.md>), [cl-cri-1163](<https://devfeed.tech/tags/cl-cri-1163.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [data](<https://devfeed.tech/tags/data.md>), [financial-sector](<https://devfeed.tech/tags/financial-sector.md>), [go](<https://devfeed.tech/tags/go.md>), [large-language-models-llms](<https://devfeed.tech/tags/large-language-models-llms.md>), [malware](<https://devfeed.tech/tags/malware.md>), [nextchat](<https://devfeed.tech/tags/nextchat.md>), [operations](<https://devfeed.tech/tags/operations.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [shipping-and-transportation](<https://devfeed.tech/tags/shipping-and-transportation.md>), [socks5](<https://devfeed.tech/tags/socks5.md>), [socktz](<https://devfeed.tech/tags/socktz.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

The article examines two ongoing intrusion and data-exfiltration campaigns targeting organizations in Latin America. It describes attackers using commercial large language models, proxy infrastructure, phishing, remote-access malware, and operational tooling.

### Source excerpt

Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America appeared first on Unit 42.

## Defending against AI-fueled social engineering

DevFeed: [Defending against AI-fueled social engineering](<https://devfeed.tech/articles/defending-against-ai-fueled-social-engineering-4794.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/defending-against-ai-fueled-social-engineering>)

Author: Joe DeFever

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>)

Tags: [agentic-ai-alerting-security-analytics](<https://devfeed.tech/tags/agentic-ai-alerting-security-analytics.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

The article describes how AI enables personalized spear phishing, smishing, and deepfake-based impersonation at greater scale. It argues that defenders should detect behavioral signals rather than rely solely on static signatures and known patterns.

### Source excerpt

AI is supercharging social engineering. Learn how SOC teams can detect deepfakes, spear phishing, and smishing before they cause real damage.

## Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

DevFeed: [Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](<https://devfeed.tech/articles/spring-ring-an-inside-look-at-voice-phishing-campaigns-in-microsoft-teams-7760.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/>)

Author: Noam Sala

Published: 2026-08-31T10:00:36Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [remote access software](<https://devfeed.tech/topics/remote-access-software.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Cloaked Ursa](<https://devfeed.tech/topics/cloaked-ursa.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [cloaked-ursa](<https://devfeed.tech/tags/cloaked-ursa.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-teams](<https://devfeed.tech/tags/microsoft-teams.md>), [payload](<https://devfeed.tech/tags/payload.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [spoof](<https://devfeed.tech/tags/spoof.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [vishing](<https://devfeed.tech/tags/vishing.md>), [voice](<https://devfeed.tech/tags/voice.md>)

### AI overview

Spring Ring is a coordinated social engineering campaign that used external Microsoft Teams accounts and voice phishing to impersonate IT help desk staff. The operation targeted more than 150 employees across at least 10 companies and attempted to deliver remote monitoring and management tools or custom malware. A more advanced variant escalated to an NTLM relay attack against an organization's domain controller.

### Source excerpt

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.

## How WhatsApp Upgraded to Secure, Seamless Sign-In for 1 Billion Users with Passkeys

DevFeed: [How WhatsApp Upgraded to Secure, Seamless Sign-In for 1 Billion Users with Passkeys](<https://devfeed.tech/articles/how-whatsapp-upgraded-to-secure-seamless-sign-in-for-1-billion-users-with-passkeys-4242.md>)

Original publisher: [Read original article](<https://android-developers.googleblog.com/2026/08/whatsapp-passkeys-secure-sign-in.html>)

Author: Android Developers (noreply@blogger.com)

Published: 2026-08-27T17:00:00Z

Content type: article

Language: en

Sources: [Android Developers Blog](<https://devfeed.tech/sources/android-developers-blog.md>), [Android Developers Blog](<https://devfeed.tech/sources/android-developers-blog-2.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Android](<https://devfeed.tech/topics/android.md>), [App](<https://devfeed.tech/topics/app.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [api](<https://devfeed.tech/tags/api.md>), [app](<https://devfeed.tech/tags/app.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [scale](<https://devfeed.tech/tags/scale.md>), [whatsapp](<https://devfeed.tech/tags/whatsapp.md>)

### AI overview

WhatsApp's adoption of passkeys provides a fast, phishing-resistant sign-in method for its large global user base. The article explains how passkeys use public-private key cryptography with biometric or screen-lock authentication, reduce reliance on inconsistent SMS OTP delivery, and simplify implementation through Android's Credential Manager API.

### Source excerpt

Posted by Niharika Arora, Senior Developer Relations Engineer, Tracy Agyemang, Product Marketing Manager, Google and Mayank Manuja, Android Engineer, Meta WhatsApp is the world's largest messaging platform, serving billions of users globally. It is the default communication tool for people across diverse regions, connecting users through private, reliable, and secure messaging. "What excites me most is the sheer scale of WhatsApp's impact. Even a small improvement to WhatsApp touches billions of users worldwide," says Mayank Manuja, an Android Engineer on the WhatsApp Registration and Access team who led the design and implementation of passkey-based authentication for WhatsApp. Building for an audience of this magnitude requires navigating a vast range of network conditions, device capabilities, and levels of digital literacy. Recognizing the potential early, WhatsApp committed to adopting passkeys in 2023, becoming one of the first major consumer apps to integrate the technology. By implementing passkeys, WhatsApp aimed to provide a fast, phishing-resistant option that significantly reduces user friction while providing robust protection against account takeovers and credential theft. A user creating a passkey on WhatsApp for faster, more secure sign-ins. The Decision to Adopt Passkeys For WhatsApp, offering multiple access methods is key to making it easier for users to stay connected and regain access when needed. Passkeys offer users a streamlined, one-tap login experience that eliminates phishing risks and functions reliably even in regions where OTP message delivery can be inconsistent. Underneath, passkeys leverage public-private key cryptography to replace manual entry with biometric or screen lock authentication. This workflow drastically improves sign-in speeds by reducing the process to a single tap via a unified, bottom-sheet interface that keeps users engaged within the app's context. The benefits are twofold: passkeys offer users a streamlined login e

## AI-driven OSINT in the wrong hands - and why everyone could be a target for fraud

DevFeed: [AI-driven OSINT in the wrong hands - and why everyone could be a target for fraud](<https://devfeed.tech/articles/ai-driven-osint-in-the-wrong-hands-and-why-everyone-could-be-a-target-for-fraud-8392.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/privacy/ai-powered-osint-why-everyone-viable-target-fraud/>)

Author: Phil Muncaster

Published: 2026-08-27T09:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Web](<https://devfeed.tech/topics/web.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [malware](<https://devfeed.tech/tags/malware.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [research](<https://devfeed.tech/tags/research.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

AI-powered OSINT is making it faster and easier for cybercriminals to gather publicly available information about potential victims. By linking accounts, relationships, images, and videos at machine speed, these tools can make fraud and social engineering more convincing and scalable, lowering the barrier to entry for attackers.

### Source excerpt

It's getting cheaper and easier for cybercriminals to research potential victims. Here's what's still in your control.

## Identity Abuse Through Trusted Communication Channels

DevFeed: [Identity Abuse Through Trusted Communication Channels](<https://devfeed.tech/articles/identity-abuse-through-trusted-communication-channels-7750.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/communication-channel-identity-risks/>)

Author: Bill Batchelor

Published: 2026-08-20T10:00:25Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [identity](<https://devfeed.tech/tags/identity.md>), [identity-theft](<https://devfeed.tech/tags/identity-theft.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [remote-access-software](<https://devfeed.tech/tags/remote-access-software.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

Unit 42 examines how attackers abuse trusted enterprise communication and collaboration platforms for identity phishing, impersonation, credential theft, malware delivery and social engineering. The article describes how compromised identities can make malicious activity appear legitimate within authenticated collaboration sessions and offers recommendations for detecting and defending against these attacks.

### Source excerpt

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.

## How state and local agencies can get ahead of fraud starting with the data they already have

DevFeed: [How state and local agencies can get ahead of fraud starting with the data they already have](<https://devfeed.tech/articles/how-state-and-local-agencies-can-get-ahead-of-fraud-starting-with-the-data-they-already-have-4827.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/how-state-and-local-agencies-get-ahead-of-fraud>)

Author: Leanne Link

Published: 2026-08-19T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [systems](<https://devfeed.tech/topics/systems.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [agentic-ai-alerting-anomaly-detection-fraud-detection-government-state-local-government](<https://devfeed.tech/tags/agentic-ai-alerting-anomaly-detection-fraud-detection-government-state-local-government.md>), [applications](<https://devfeed.tech/tags/applications.md>), [audits](<https://devfeed.tech/tags/audits.md>), [data](<https://devfeed.tech/tags/data.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [government](<https://devfeed.tech/tags/government.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [synthetic](<https://devfeed.tech/tags/synthetic.md>), [systems](<https://devfeed.tech/tags/systems.md>), [tax](<https://devfeed.tech/tags/tax.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

This article explains how fragmented data across state and local government systems can delay fraud detection and remediation. It describes the growing scale of fraud, the use of generative AI by bad actors to fabricate identities and synthetic personas, and the operational, audit, financial, and funding consequences for agencies.

### Source excerpt

Fraud and waste continues to be a challenge for state and local government agencies in the US. Though the data exists, the challenge is pulling it all together for an accurate anomaly detection and remediation.

## How QR-code phishing can slip past corporate security measures

DevFeed: [How QR-code phishing can slip past corporate security measures](<https://devfeed.tech/articles/how-qr-code-phishing-can-slip-past-corporate-security-measures-8339.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/qr-code-phishing-slip-past-corporate-security-measures/>)

Author: Phil Muncaster

Published: 2026-08-17T09:00:00Z

Content type: article

Language: eng

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [QR Code](<https://devfeed.tech/topics/qrcode.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>)

Tags: [business-security](<https://devfeed.tech/tags/business-security.md>), [corporate](<https://devfeed.tech/tags/corporate.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains how QR-code phishing ("quishing") can evade corporate defenses by hiding malicious URLs and directing employees to less-protected mobile devices.

### Source excerpt

Quishing has become a popular alternative to traditional phishing. Here's how businesses can close the gap.

[Next page](<https://devfeed.tech/tags/phishing.md?cursor=WyIyMDI2LTA4LTE3VDA5OjAwOjAwKzAwOjAwIiwgIjdhMDM0NzA1LWFhYTktNDNkYS05MDhjLWVhNWM3YmNjMTRjMSJd>)