Phishing
Curated coverage and analysis in this editorial area.

DGFiP Data Breach Exposes 678,000 French Taxpayers; CNIL Weighs Enforcement
The French Finance Ministry confirmed on August 17, 2026, that the DGFiP suffered a breach exposing sensitive tax data for 678,000 ind…

RingCentral Breach Exposes 1.6 Million Records via Vishing Call
ShinyHunters compromised RingCentral with a single phone call, exposing 1.6 million records and leaking 280 GB of data. The real-time…

Passkey Bypass: Three Attacks Demolish Phishing-Resistant Authentication
Three independent studies published in August 2026 demonstrate post-compromise attack chains that bypass passkey-based phishing-resist…

Generative AI as a Cyber Force Multiplier: Three North Korean Groups, Three Tactics
Famous Chollima (47% of state-backed tech attacks), Kimsuky (HelloDoor malware with AI assistance), and APT45 (recursive prompting): t…

Criminals Buy Expired Domains to Inherit Reputation and Traffic
A single threat actor spent nearly $7 million on over 10,000 expired domains, weaponizing their inherited trust signals for illegal st…

Lazarus Exploits Microsoft Zero-Day: Job Offers Turn Into Kernel Spyware
Check Point Research uncovers a new wave of Operation Dream Job featuring SecurityPDF and Troy. Lazarus leverages CVE-2026-68820 to de…

Passkey Bypass: Three Studies Shatter FIDO2's 'Anti-Phishing' Promise
On August 3, 2026, researchers from SpecterOps, Palo Alto Networks Unit 42, and independent researcher Dirk-jan Mollema published dist…

Trezor: ShipMonk Exposes 13,689 Customers — Where Physical and Digital Security Collide
Logistics provider ShipMonk notified Trezor of unauthorized access exposing personal data for 13,689 customers. The incident lays bare…

WindRelay Turns Android Phones into NFC Relays to Drain Contactless Cards
Group-IB discovered WindRelay, Android malware that captures and relays contactless payment card NFC data in real time during social-e…

Lazarus Strikes with CVE-2026-68820: Microsoft Zero-Day in Defense Sector
Check Point discovers the 2026 wave of Operation Dream Job. Lazarus exploits CVE-2026-68820 in AFD.sys to deploy FudModule via fake jo…

Greatness PhaaS: Device Code Phishing and MFA Bypass in a Single Platform
The Greatness PhaaS platform has added device code phishing to its arsenal alongside AiTM and OAuth consent abuse, enabling Microsoft…

Kimsuky Builds Offline AI Stack to Automate Phishing and Malware
North Korean APT group Kimsuky has deployed a fully offline AI pipeline on its own C2 servers. Genians researchers documented the stac…