Phishing
Curated coverage and analysis in this editorial area.

Banking Phishing: Evasion via IPv4-Mapped IPv6
A phishing campaign targeting Belgian e-banking exploits compressed IPv4-mapped IPv6 syntax to bypass regex-based security checks and…

June 2026 ThreatsDay Bulletin: When Claude’s Shared Chat Becomes a Malware Vector
The June 2026 ThreatsDay Bulletin documents the abuse of Anthropic Claude’s shared chat feature to distribute the MacSync credential s…

Operation Endgame Dismantles SocGholish: Nearly 15,000 Sites Cleaned
On June 18, 2026, the international Operation Endgame coalition took down 106 servers and domains linked to SocGholish and cleaned 14,…

Rokarolla: The Android Trojan That Turns Your Phone Into a Digital Prison
Discovered by Zimperium zLabs, the Rokarolla trojan deploys 137 commands and fake overlays to isolate victims, steal banking credentia…

Lorem Ipsum Pivots to ClickFix After Fox Tempest Takedown
BlueVoyant reports the Lorem Ipsum malware abandoned signed Microsoft Teams installers for ClickFix tactics on compromised WordPress s…

Infinite Campus: 137,123 Staff Emails Exposed in Salesforce Breach
ShinyHunters compromised an Infinite Campus employee's Salesforce account on March 18, 2026. After a failed extortion attempt, 137,123…

Maine Disables Breach Notification Portal After Fake Discord and VRChat Disclosures
Maine's government portal automatically published data breach notifications without verification, facilitating the spread of misinform…

Algorithmic Exploitation: How TikTok and Instagram Reels Amplify Vidar Malware
ReversingLabs research reveals threat actors are using fake Spotify Premium tutorials to distribute the Vidar infostealer via PowerShe…

Edge Tab-Splitting and Invisible Phishing: The Pwn2Own Flaw
CVE-2026-45494: A Universal XSS in Microsoft Edge discovered by Orange Tsai leverages tab-splitting to mask malicious URLs. Update to…

TA4922 Targets Europe with New Atlas RAT and AI-Assisted Malware Development
Proofpoint tracks the European expansion of TA4922, a Chinese-speaking cybercrime group deploying the new Atlas RAT, RomulusLoader, an…

Gamaredon APT Weaponizes WinRAR Path Traversal Bug for Ukrainian Espionage
The Gamaredon APT group is exploiting CVE-2025-8088, a path traversal vulnerability in WinRAR, to deploy a modular malware suite again…

OpenAI Mandates Hardware-Backed Passkeys for Access to Frontier AI Models
Starting June 1, 2026, OpenAI will require Trusted Access for Cyber (TAC) program members to use hardware-backed passkeys, setting a n…