Phishing
Curated coverage and analysis in this editorial area.

Phishing Tops 50% of IR Cases: Cisco Talos Flags Perimeter Collapse
In Q2 2026, phishing became the leading initial access vector in over half of Cisco Talos Incident Response engagements, up from rough…

SSRF in Phoenix Contact MQTT Broker: The Assault on EV Chargers Starts Here
ZDI-26-518 reveals a flaw in the MQTT service of Phoenix Contact CHARX SEC-3150 EV chargers. An unauthenticated, network-adjacent atta…

SourTrade: The Browser Becomes an In-Memory Malware Factory
The SourTrade malvertising campaign assembles malware directly in the victim's browser memory using legitimate web APIs. The technique…

The Great Patching Isn't Enough Anymore: When Attackers Weaponize Your Own Tools
Cisco Talos IR's Q2 2026 report marks a turning point: phishing now drives over 50% of engagements, while authentication abuse surged…

TransUnion, the SaaS Periphery Paradox: 4.4 Million SSNs Exposed via Third-Party OAuth App
Credit bureau TransUnion disclosed a data breach exposing 4,461,511 unredacted Social Security Numbers. The vector was not a direct in…

Device Code Phishing: How Attackers Bypass MFA on Microsoft 365
Proofpoint documents threat clusters exploiting Microsoft's legitimate OAuth device authorization flow to compromise Microsoft 365 acc…

Kratos Dismantled: AiTM Code Remains in Hands of 1,800 Criminals
German and U.S. authorities seized over 200 servers linked to the Kratos phishing-as-a-service kit, but the source code still circulat…

Bank of Baroda Data Breach Traced to Compromised Email Account: The Limits of What We Know
India's Bank of Baroda confirms an employee email account was compromised, but insists core banking systems remain untouched. A threat…

OWAReaper: The Malware That Survives Device Reimaging
Russia-aligned APT Laundry Bear (TA488) exploited CVE-2026-42897, an XSS flaw in Outlook Web Access, to deploy OWAReaper — a browser-b…

Kratos Phishing Kit Dismantled: 200 Servers Seized, but AiTM Code Remains in Circulation
German, U.S., and Indonesian authorities took down the Kratos phishing kit, seizing over 200 servers and arresting the alleged develop…

Hotel Wi-Fi DNS Attacks Steal Microsoft 365 Accounts, Bypass MFA
Threat actors compromise hotel and conference center Wi-Fi captive portals to manipulate DNS and steal Microsoft 365 credentials, sess…

OctagonPanel Spyware Hides Behind Fake Bahrain Civil Defense Alert App
A counterfeit "BH Alert" app impersonating Bahrain's civil defense system delivers the OctagonPanel surveillance malware via a four-st…