Phishing
Curated coverage and analysis in this editorial area.

McKesson in ShinyHunters' Crosshairs: 284 Million Records and a $55 Million Ransom
McKesson disclosed a security incident involving unauthorized access to third-party applications. The ShinyHunters group claims to hav…

BlueDelta Refines HEADLACE: HOOKEDGE Backdoor Abuses Legitimate Webhook Services
The BlueDelta group has used macro-laced Word documents to distribute HOOKEDGE, a batch-script backdoor that leverages webhook.site fo…

Bug in JavaScript Obfuscator Exposes Polymorphic Phishing Campaign
A server-side scope error in an obfuscator triggered infinite loops in 3.6% of variants, revealing a polymorphic evasion mechanism tha…

Mirage2FA: AiTM Phishing Kit Hits 3,500 Organizations, Bypasses MFA on Microsoft 365
The Mirage2FA phishing-as-a-service kit, operated by LinX Coders, has targeted over 3,500 organizations using Adversary-in-the-Middle…

DOUBLECUP: The Fake Steganography That Exposes Criminal Payloads to a Simple grep
The DOUBLECUP loader promises advanced steganography but hides PowerShell code in plaintext after the PNG file. Extractable with FINDS…

Windows: Localized Filename Bug Steals NTLM Credentials with a Single Click
CVE-2026-50508: A flaw in Windows localized filenames enables NTLM hash theft simply by opening a file or visiting a web page. Microso…

SilkParasite Exposes the Line Between AI-Assisted and AI-Generated Malware
Bitdefender uncovered SilkParasite, a cyber-espionage campaign using seven RAT families and AI-assisted development to target governme…

SynkLoader: The 'Kitchen Sink' Malware Attacking via Microsoft Teams
Expel researchers have uncovered SynkLoader, a modular, multi-language malware family that uses Microsoft Teams phishing to breach cor…

North Korea’s Famous Chollima Behind 47% of State-Backed Tech Attacks
The North Korean group Famous Chollima carried out 47% of all state-sponsored attacks against the technology sector in one year, using…

UNC6671: Personal Phones Become the Gateway to Steal SaaS Data
The UNC6671 group uses vishing on personal smartphones to bypass MFA and steal SaaS sessions. Google has tracked over $10 million in e…

DGFiP Data Breach Exposes 678,000 French Taxpayers; CNIL Weighs Enforcement
The French Finance Ministry confirmed on August 17, 2026, that the DGFiP suffered a breach exposing sensitive tax data for 678,000 ind…

RingCentral Breach Exposes 1.6 Million Records via Vishing Call
ShinyHunters compromised RingCentral with a single phone call, exposing 1.6 million records and leaking 280 GB of data. The real-time…