Phishing
Curated coverage and analysis in this editorial area.

SourTrade: The Browser Becomes an In-Memory Malware Factory
The SourTrade malvertising campaign assembles malware directly in the victim's browser memory using legitimate web APIs. The technique…

The Great Patching Isn't Enough Anymore: When Attackers Weaponize Your Own Tools
Cisco Talos IR's Q2 2026 report marks a turning point: phishing now drives over 50% of engagements, while authentication abuse surged…

TransUnion, the SaaS Periphery Paradox: 4.4 Million SSNs Exposed via Third-Party OAuth App
Credit bureau TransUnion disclosed a data breach exposing 4,461,511 unredacted Social Security Numbers. The vector was not a direct in…

Device Code Phishing: How Attackers Bypass MFA on Microsoft 365
Proofpoint documents threat clusters exploiting Microsoft's legitimate OAuth device authorization flow to compromise Microsoft 365 acc…

Kratos Dismantled: AiTM Code Remains in Hands of 1,800 Criminals
German and U.S. authorities seized over 200 servers linked to the Kratos phishing-as-a-service kit, but the source code still circulat…

Bank of Baroda Data Breach Traced to Compromised Email Account: The Limits of What We Know
India's Bank of Baroda confirms an employee email account was compromised, but insists core banking systems remain untouched. A threat…

OWAReaper: The Malware That Survives Device Reimaging
Russia-aligned APT Laundry Bear (TA488) exploited CVE-2026-42897, an XSS flaw in Outlook Web Access, to deploy OWAReaper — a browser-b…

Kratos Phishing Kit Dismantled: 200 Servers Seized, but AiTM Code Remains in Circulation
German, U.S., and Indonesian authorities took down the Kratos phishing kit, seizing over 200 servers and arresting the alleged develop…

Hotel Wi-Fi DNS Attacks Steal Microsoft 365 Accounts, Bypass MFA
Threat actors compromise hotel and conference center Wi-Fi captive portals to manipulate DNS and steal Microsoft 365 credentials, sess…

OctagonPanel Spyware Hides Behind Fake Bahrain Civil Defense Alert App
A counterfeit "BH Alert" app impersonating Bahrain's civil defense system delivers the OctagonPanel surveillance malware via a four-st…

Russia Exploits Zimbra Zero-Day: Patching Alone Won't Evict the Spies
A zero-click XSS flaw in Zimbra Collaboration Suite let a Russian espionage group harvest emails, 2FA codes, and persistent app passwo…

Misconfigured Server Exposes Three Evilginx Operations Targeting Microsoft 365
A phishing server with directory listing enabled exposed complete M365 phishing toolkits, two distinct MFA bypass techniques, and evid…