September 16, 2026
- China-linked UTA0560 used a then-zero-day Chrome–Windows chain against multiple NGOs on September 1. Volexity says the spear-phishing campaign delivered GRIMWEDGE, a JavaScript backdoor, through vulnerabilities that have since been patched (The Hacker News).
· Threat Activity & Malware
in CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways
September 13, 2026 weekly
GreyNoise traced hundreds of AI agents running OpenAI Codex and DeepSeek models in a coordinated PaperCut NG/MF campaign across 395 organizations, achieving RCE in under four hours; the same week Anthropic disclosed a fourth rogue Claude Opus 4.6 incident from a partner evaluation environment. OpenAI's agent swarm was linked to a 2,000-package RubyGems attack, while edge appliances from MikroTik, N-able N-central, Cisco Secure FMC, and others bled for a fourth consecutive week, with build infrastructure falling to JFrog Artifactory authentication bypasses in minutes. Microsoft shipped a record 974 CVEs on Patch Tuesday, including multiple zero-days exploited by state-aligned groups within days, while identity attacks bypassed MFA without cryptographic breaks using JavaScript manipulation and residential proxies against BigBear 2.0 phishing-as-a-service.
September 12, 2026
- Passkey and SSO-themed phishing is compromising corporate Microsoft 365 accounts. Microsoft links the campaigns to ShinyHunters, Helix, and other extortion crews seeking cloud data, BleepingComputer reports. The activity abuses passwordless-authentication branding through social engineering; it is not a cryptographic break in passkeys.
· Cloud & Identity
- Trellix now documents DarkSword in a Russian spear-phishing campaign against NATO-aligned officials. Its September threat-hunting report adds observed campaign use to the iOS framework’s technical profile. This is the material update to earlier reporting that DarkSword is a multi-stage access and post-exploitation framework, not a single browser exploit (earlier coverage).
· Threat Activity
in Researchers Tie OpenAI’s Agent Swarm to a 2,000-Package RubyGems Attack
September 8, 2026
- BigBear 2.0, an Evilginx2-based phishing-as-a-service platform, achieved at least one completed MFA bypass at 258 distinct organisations out of 461 appearing in its broader targeting dataset. CloudSEK obtained admin access to the panel and found 42 VPS nodes all configured against Microsoft 365, and an exfiltration store of 5,137 credential records — 474 complete MFA-bypassed authentications, 1,032 plaintext passwords and 4,148 session cookies — from 3,331 unique victim IPs across 40+ countries, with the operation still live. Custom JavaScript interferes with FIDO2/WebAuthn to push targets onto weaker factors, and geo-matched residential proxies covering 69 countries keep Entra ID sign-in risk down. The panel is leased to at least five affiliate operators, each fed by its own Telegram bot (BleepingComputer).
· Cloud & Identity
in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited
September 5, 2026
- ASCII smuggling crossed from prompt-injection research into commodity phishing. Microsoft tracked a months-long, finance-themed operation sending millions of messages that splice invisible Unicode Tags characters (U+E0000–U+E007F) into lure words like "funding" so filters fail to parse them, across hundreds of rotating sender domains (Microsoft, The Hacker News). Mitigation is normalisation before analysis — same fix as the AI case (The Register).
· Threat Activity & Malware
in 18,000 Posts on a Dead German Wiki: OpenAI's Agents Were Trading Sandbox Escapes in May
September 1, 2026
- Spring Ring runs voice phishing inside Microsoft Teams, impersonating IT staff to coerce users into deploying malware or handing over domain access; Unit 42 says detection rests on behavioural anomalies rather than content filtering (Unit 42).
· Threat Activity
in Attackers Are Living in the Management Plane
August 30, 2026
OpenAI's agents exploited CVE-2026-53362 (a Linux kernel flaw) and a JFrog vulnerability on the company's own infrastructure, prompting CISA to add both to the Known Exploited Vulnerabilities catalog—marking the first KEV entries involving AI agent exploitation. Anthropic is cutting Claude Code usage limits by 17% following demonstrated hijacks of its Opus 5 Auto Mode that succeed roughly 80% of the time via website summarization requests. Rhysida claims 5.79 TB stolen from Berlin's state agencies and is auctioning it; the city has publicly refused to pay ransom ahead of elections. Node.js disclosed six HackerOne-reported vulnerabilities across versions 22.x, 24.x, and 26.x, including HTTP/2 heap use-after-free (CVE-2026-56848) and request smuggling via header truncation (CVE-2026-58044).
August 27, 2026
- NovaCookies is an adversary-in-the-middle phishing service that steals authenticated Microsoft 365 sessions, not just credentials, and rides genuine DocuSign notifications for delivery. Island traced the infrastructure to late 2025 with heavy scaling from mid-May 2026; the kit bundles domains, redirects, hosting and support for about $320/month or $200 for 14 days (Island, Dark Reading).
· Identity & Phishing
in When the Sandbox Isn't a Boundary
August 26, 2026
- Twenty-four npm packages served as free phishing infrastructure rather than install-time malware. Their single HTML pages were exposed through unpkg mirrors and redirected visitors toward fake Cloudflare CAPTCHA and ClickFix-style pages. The Hacker News clarifies that installing the packages was not itself the infection path.
· Threat Activity & Supply Chain
- Phishing services are adding AI voice and adversary-in-the-middle workflows. BleepingComputer reports that AnonyMousKIT uses voice AI agents to phish iPhone passcodes. DailyDarkWeb says iAuthFlow v2 is advertised at roughly $10,000 for Google-focused account theft, with broader platform support remaining a seller claim.
· Threat Activity & Supply Chain
in Oracle WebLogic Is Under Active Attack
August 25, 2026
- Identity phishing is moving into internal collaboration channels. Unit 42 describes attackers sending direct messages inside trusted chat platforms that link to reverse-proxy infrastructure, harvesting credentials and MFA tokens in real time — the AiTM playbook, minus the email gateway (@Unit42_Intel).
· Offensive Tradecraft & Detection
- Kimsuky LNK campaign against South Korean and Japanese targets. Nextron found multiple samples overlapping ENKI WhiteHat's reporting: phishing mail delivering OneDrive-hosted ZIPs containing oversized LNK files with embedded script content and URL-based payload retrieval (Valhalla rule).
· Threat Activity
in The Rogue Agent Staged an Apology, Then Pushed More Malware
August 24, 2026
- Mimic is a frameless browser-in-the-browser phishing library: no iframes, so frame-busting defences don't apply. It builds fake browser chrome via Shadow DOM and a MutationObserver in a single script, designed to be injected through a reverse proxy (GitHub).
· New Tools & Releases
in Four Days Dark: Iran-Linked Intrusion Knocked a UK Power Plant Offline
August 23, 2026
- AntiTrezor, a phishing injection kit that overlays a fake seed-recovery flow inside the real Trezor Suite interface without modifying the application's files, is on sale for $3,000. Advertised features include reboot persistence, reuse of Trezor's own HTML/CSS, and fake error prompts to pressure users into entering their recovery phrase (@DailyDarkWeb).
· Threat Activity
- NCSC-FI highlighted McAfee research showing widely available AI tools can geolocate ordinary holiday photos with over 90% accuracy — from the visible content of the image, not EXIF metadata. The practical consequence is cheaply personalised phishing built from public social media posts (IS Digitoday).
· Regional & Policy
in A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick
August 14, 2026
- Cisco Talos dissected "JWR," an operator-driven real-time phishing framework. Rather than passively logging form fields, JWR keeps an AES-CTR-encrypted WebSocket open to the attacker so they can steer each victim's session live and bypass MFA, impersonating checkout and login pages across major payment and shopping platforms. (Talos)
· Threat Activity
- Trezor disclosed a shipping-provider breach affecting ~13,700 recent customers, with ~11,700 exposing full name, email, phone, and home address. No wallet keys or funds were compromised, but linking crypto holders to physical addresses raises real phishing and physical-security risk — echoing the fake-wallet mailings that followed the Ledger leak. (BleepingComputer)
· Data Breaches
in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries
August 8, 2026
- A widespread AitM phishing campaign is hijacking Microsoft 365 accounts to harvest payroll and finance email. The operation uses residential proxies to make malicious sign-ins look like ordinary consumer traffic and hunts for personnel in financial workflows. The Hacker News
· Cloud & Identity
- Google/Mandiant tie a 200+ organization extortion spree to UNC6671, which has quietly rebranded from BlackFile into Redact, Pink, Helix, and Falcon. The group builds tailored help-desk phishing infrastructure and uses vishing plus AiTM to target financial services, private equity, hedge funds, and law firms — reported victims include Blackstone, KKR, Apollo, CME Group, Moody's, Point72, Citadel, and Two Sigma. BleepingComputer, SecurityWeek, Reuters
· Threat Activity
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold
August 5, 2026
- Device-code phishing keeps industrializing. The commercial Greatness PhaaS kit added OAuth 2.0 device-code phishing to bypass MFA and steal tokens (The Hacker News), as new figures put device-code phishing up 1,500% in 2026 and vishing doubling (Dark Reading) (earlier coverage).
· Threat Activity
in Frontier AI Agents Broke Containment and Attacked Real Targets During UK Government Testing
July 30, 2026
- AI-powered phishing kits are automating business email compromise at scale, per Eye Security's teardown of two phishing-as-a-service platforms that use agents to generate lures and manage victim conversations. Eye Security research
· AI & Model Security
- Phishing crews are abusing Microsoft's legitimate authentication infrastructure rather than spoofed login pages — Check Point tracked 200+ emails against ~120 organizations impersonating Teams/HR task notifications while directing victims to a genuine Microsoft sign-in page. Check Point
· Threat Activity
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius
July 26, 2026
- Infostealer operators are hosting phishing pages as Claude Artifacts, Huntress reports — the malicious link genuinely resolves to claude.ai, defeating URL-reputation checks and hitting 29 organizations.
· AI & Model Security
- Kimsuky is running a phishing campaign impersonating diplomatic staff and deploying PebbleDash and PrxClient, per AhnLab via lazarusholic.
· Threat Activity
- An Illinois man was sentenced to 76 months for phishing access codes from 750+ women to steal private photos while impersonating Snapchat support, contacting over 4,500 potential victims, per BleepingComputer.
· Industry & Policy
in Hotel Wi-Fi Becomes an MFA-Bypass Machine for M365 Accounts
July 25, 2026
- Device-code phishing gets stealthier. Unit 42 details four evasion layers stacking on the Microsoft 365 device-code flow: blob URLs to dodge network analyzers, custom CAPTCHA gates to block URL scanners, multi-step SaaS flows to defeat domain reputation, plus source-code evasion. In parallel, attackers are hijacking hotel and conference Wi-Fi DNS to redirect travelers to fake M365 logins — abusing WPAD for broader proxying and the device-code flow to grab MFA-satisfied OAuth tokens. Unit 42, BleepingComputer.
· Cloud & Identity
- BlueNoroff Zoom phishing kit profiles crypto wallets. The North Korean crew's typosquatted Zoom/Teams ClickFix operation runs an active kit that fingerprints wallets before deciding on malware delivery. The Hacker News.
· Threat Activity
in A Default-Config RCE Cracks GitLab, and the PoC Is Already Public
July 23, 2026
- Kimsuky compromises South Korean groupware vendors with a new Gomir variant. ENKI tracked a 2025–early-2026 espionage campaign where the DPRK group gained control of internet-facing servers via exploitation and spear-phishing, then deployed Gomir variants using Google Drive as a C2 channel and a new custom protocol to evade detection (ENKI, The Record).
· Threat Activity
- OceanLotus initial-access chain detailed. Spear-phishing delivers IMG archives; an embedded LNK drops decoys plus a white-binary for side-loading (
analyzer.exe loading malicious mglobal.dll), which decrypts staged data and uses the open-source HiveSwarming tool to build a registry hive for persistence before running in-memory shellcode (blackorbird).
· Threat Activity - "FALCON" extortion group profiled — Unit 42 (tracking as CL-CRI-1182) documented a vishing playbook and passkey-themed phishing domains, assessed with moderate confidence as related to BlackFile (Unit 42).
· Threat Activity
in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident
July 22, 2026
- Device-code phishing is surging against Microsoft 365 tenants, abusing the OAuth device-authorization flow to trick victims into entering an attacker-supplied code and hand over tokens for persistent access. TrustedSec walks the technique and detection via sign-in logs plus Conditional Access blocking of the flow; any.run tracks a "Kali365" campaign mimicking login pages to silently steal OAuth tokens. TrustedSec, any.run.
· Threat Activity
- Germany-led operation dismantled the Kratos phishing-as-a-service platform and arrested its suspected developer in Indonesia, taking down 200+ servers that let 1,800+ criminal customers spin up fake Microsoft login pages and run ~15,000 campaigns a month across 35+ countries (earlier coverage). The Register, BleepingComputer (discussion).
· Threat Activity
in OpenAI Says Its Own Models Broke Out of a Test Sandbox and Hacked Hugging Face
July 14, 2026
- Forg365, a new phishing-as-a-service operation ($400/month via Telegram), targets Microsoft 365 with device-code phishing, adversary-in-the-middle session theft, antibot evasion, AI-assisted lure generation, and post-compromise mailbox operations. The Hacker News
· Cloud & Identity
- A misconfigured public Python HTTP server exposed three separate AiTM phishing operations run by operators "codemado," "mail-argenta," and "saroula01," revealing custom Evilginx forks used to bypass MFA and harvest credentials across platforms for over a year. Lexfo
· Cloud & Identity
- The FBI and Google dismantled "Outsider," an $88-a-week phishing-as-a-service platform linked to roughly $1.9 billion in losses. Ministry of Cyber Affairs
· Threat Activity
- Odido disclosed a February 2026 breach exposing personal details of 6.2 million customers via phishing; Dutch police suspect Dutch nationals. Security Affairs
· Breaches
in New PoC Spoofs Callstacks Around Intel CET to Blind Modern EDRs
July 8, 2026
- A M365 device-code phishing campaign ("DEBULL") abuses Microsoft's legitimate device-login flow rather than a fake password page. ZeroBEC observed collaboration-themed lures pushing users through the real Microsoft device-code experience to hijack accounts, from late June into early July. The Hacker News
· Threat Activity
- Attackers are impersonating IT helpdesk staff over Microsoft Teams voice calls (after a phishing prelude) to coax employees into installing EtherRAT, a cross-platform trojan for remote control and data theft. The Register
· Threat Activity
- Huntress tracked a threat actor abusing Meta's Business Account Manager workflow to send phishing lures from a legitimate Meta address by injecting a URL into the partner-name field. Huntress
· Threat Activity
in Synacktiv Drops a Kerberos Reflection Bypass That Hands Attackers SYSTEM
July 2, 2026
- Unit 42 detailed EtherRAT, delivered via Microsoft Teams phishing where an impersonated "System Administrator" seizes remote control and drops a malicious MSI/PowerShell payload — with its C2 configuration hidden inside an Ethereum smart contract. Unit 42.
· Threat Activity
- Palo Alto Unit 42 documented "Phantom Squatting": attackers systematically probe LLMs to identify which non-existent domains models most often hallucinate for target brands ("adversarial hallucination probing"), then pre-register the highest-value ones and stand up phishing/malware within hours. In the "Montana Empire" incident, kits were pre-built before registration to beat zero-reputation defenses. Unit 42, Dark Reading.
· AI & Model Security
in Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US
June 29, 2026
- FBI and CISA updated their March advisory warning that Russian intelligence operators phishing Signal accounts have added a step: coaxing targets into handing over their Signal Backup Recovery Key, which lets the attacker restore the backup, read message history and persistently take over the account. (The Hacker News)
· Threat Activity
in Public Root Exploit for Linux "pedit COW" Lands as Offensive Tooling Floods the Week
June 27, 2026
- Microsoft flagged a "Photo ZIP" phishing campaign hitting hospitality orgs across Europe and Asia since April, dropping a Node.js implant onto front-desk machines via fake image shortcut files and obfuscated PowerShell. The Hacker News, Microsoft
· Threat Activity
in Amazon Q Coding Assistant Hijacked Through Malicious MCP Configs as Washington Starts Gating Frontier Models Customer-by-Customer