MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Sep 24, 2026, 2:02 AM (UTC+3)
Topic · Phishing
Serial number: AV26-959 Date: September 23, 2026 As of September 21, 2026, Dell is affected by vulnerabilities in the following products: • Dell Command Powershell Provider (DCPP) • Prior to 2.10.2 • Dell Command Monitor (DCM) • Prior to 10.13.2 • Dell Inventory Collector Client • Prior to 15.0.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
You receive an invitation to a password-protected meeting, a secure chatroom, or a shared document. To get access, it says, you need to enter a short code on a sign-in page for one of your accounts. The message claims the code will let you open the document or join the meeting. In fact, it approves a sign-in the scammer started. The page is real and the code works, which is why this type of attack—known as device code phishing—is so dangerous. Device code phishing abuses a legitimate sign-in feature intended for devices that cannot easily display a normal login screen (such as smart TVs, printers, conference-room equipment, and some command-line tools). Instead of entering a username and password on the device itself, you open a browser on another device, visit a sign-in page, enter a short code, and approve the sign-in.
Email Makes Up Nearly 1 in 3 MSSP Analyses: How Tier 1 Can Triage Phishing Faster Hackread
Threat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.
The Australian Signals Directorate (ASD) has this month issued a clear call to action through its Multi-factor authentication: Switch it on campaign, urging businesses, organisations, and individuals to enable multi-factor authentication (MFA) across their online accounts. At AWS, we strongly support this message. As threat actors continue to target credentials through phishing, credential stuffing, and social engineering, passwords alone are no longer enough. MFA is one of the most effective security controls available. It’s a cornerstone of ASD’s Essential Eight maturity model and a recognized component of major cybersecurity frameworks worldwide.
Cofense has announced an expansion of its AI-driven Phishing Defense Platform through Cofense Command Center, its orchestration layer for measurement and reporting. The new Competency Dashboard measures how employees recognize, report and respond to phishing threats, giving security teams evidence of program effectiveness rather than training completion. This measurement advances Secure Behavior Management (SBM), an approach that builds competency, tracks behavior, and shows progress across a phishing defense program. The Competency Dashboard, available now, drives … More → The post Cofense measures employee readiness against real-world phishing threats appeared first on Help Net Security .
Qrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxying
DarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again. This time around, its distribution has been simplified: instead of leveraging zero-day exploits, attackers are betting on a simple email to convince targets to run it on their machine: The malicious email pointing to the first stage downloader for DarkMe (Source: Huntress) The link supposedly points to … More → The post DarkMe RAT trades zero-days for plain phishing emails appeared first on Help Net Security .
Lookout has launched Social Engineering Protection (SEP), a new module within the Lookout Mobile AI Security Platform. SEP provides automated, real-time protection against the next generation of AI-driven mobile threats, including linkless smishing attacks, synthetic voice cloning, and other voice phishing (vishing) techniques. Frontier AI is transforming social engineering by enabling attackers to create highly convincing deception with unprecedented realism, personalization, and scale. Advanced AI models can craft context-aware messages tailored to individual employees, while … More → The post Lookout targets smishing, voice cloning, and vishing with real-time mobile protection appeared first on Help Net Security .
A sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. No phishing domain, no spoofed UI, no browser. Here's how to detect it.
Phishing follows whatever people want at the moment, and right now that includes AI subscriptions they don’t have to pay for. We recently uncovered a new variation on this theme: A fake Claude Max giveaway that uses a convincing Google sign-in window to steal login information. Claude’s paid plans start at $20 a month and cost considerably more for higher usage limits, while free accounts have stricter limits. That makes the promise of a free upgrade an attractive lure. Microsoft reported in June that it had seen a growing number of phishing, malicious advertising, and search-based campaigns impersonating services such as ChatGPT, Claude, DeepSeek and Copilot. Some claim that a payment has failed and send you to a fake checkout. Others offer an app download that installs malware. The campaign we found takes a different approach.
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets. The post AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft appeared first on SecurityWeek .
Lapsus$ is a hacking and extortion group first known for breaching Okta, Microsoft, Nvidia, Samsung, and Uber in 2021 and 2022 using social engineering rather than malware, and it has since reemerged as part of a larger collective called Scattered Lapsus$ Hunters. Unlike ransomware gangs that rely on encryption, Lapsus$ built its reputation on stealing source code and internal data, then threatening to leak it publicly unless the victim paid or complied with its demands. This tactic made it one of the most disruptive threat actors of the past few years despite reportedly being run largely by teenagers. That threat hasn’t gone away; it’s evolved.
Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 organizations. Microsoft says the EvilTokens platform, operated by Storm-2992, is a phishing-as-a-service kit sold to cybercriminals through Telegram. The service costs $1,500 upfront and $500 per month, with additional tools available for extra fees. Its control panel lets customers build and manage phishing campaigns, customize landing pages, configure domains, track victims, and manage stolen authentication tokens. The platform includes 44 themes and uses AI to create targeted phishing emails based on a victim’s role.
EvilTokens turns a Microsoft sign-in into a route to corporate email fraud. The phishing kit, first seen in February 2026, tricks people into approving an attacker’s login through a real device code process without handing over a password. The lure usually arrives as an urgent email about an invoice, shared file, document signature or expiring password. A link or attachment takes the recipient to a page that presents a code and urges them to continue with the sign-in. The request looks routine. Microsoft researchers tied EvilTokens to a group they track as Storm-2992 and said the toolkit helped scale business email compromise. Microsoft said in a report shared with Cyber Security News (CSN) that campaigns using the kit compromised more than 12,000 inboxes at over 10,000 organizations worldwide. Affected sectors include finance, construction, healthcare and education.
A threat group best known for exploiting previously unknown flaws in WinRAR and Windows has switched to a much simpler method: an email link to what appears to be an image. New research from Huntress details a 2026 campaign delivering DarkMe, a remote access trojan (RAT) historically linked to Water Hydra and also tracked as DarkCasino. The group made headlines in 2023 and 2024 for weaponising two zero-days, CVE-2023-38831 in WinRAR and CVE-2024-21412 in Windows Defender SmartScreen, in attacks on foreign exchange traders. This time, no exploit is involved. According to Huntress, victims receive a phishing email containing a link that looks like it serves a picture but instead downloads a file called image. pif, a Windows program in disguise. The file carries forged details suggesting it belongs to a security product named “Aegis Sentinel”.
According to fresh ANY. RUN data, phishing exposure remains above 70% in several critical industries. This doesn’t happen because organizations aren’t protected enough. Companies have been implementing email filtering, MFA, and phishing-awareness training for years. However, threats continue to evolve, and security methods that were highly effective yesterday can develop visibility gaps as attackers adapt. In this article, ANY.RUN explores data-driven insights to get to the bottom of phishing risk across key industries in the United States and examines how SOC teams can mitigate it. See our previous article on phishing risk among US-based financial organizations. Phishing Risk Remains High Across Critical Industries Phishing exposure statistics based on ANY.RUN submissions data, 2026 As the statistics show, very different industries face almost the same level of phishing exposure.
What Happened • On 25 August 2026, Manchester Airports Group (MAG), the operator of Manchester Airport, London Stansted Airport, and East Midlands Airport, reported they recently suffered data breach. • Personal information belonging to approximately 8.7 million customers was reportedly accessed. The majority of affected records involve email addresses collected via in-airport Wi-Fi sign ups, alongside customer data from car parking, airport lounge, and Fast Track security bookings. • According to BBC reports, the cybercriminals behind the attack issued a ransom demand to MAG. MAG said it had to temporarily suspended access to its online "Manage My Booking" service but importantly said that passenger safety, aviation security, and flight operations remained uncompromised and operated normally.
Cyberattacks are increasingly built around familiar actions: signing in, approving a payment, or using a trusted app. Artificial intelligence can help attackers repeat those actions at speed, making financial fraud and network intrusion harder to spot before damage is done. The threats take different forms. Some automate parts of a network break-in, while others imitate executives on video calls, hide inside mobile apps, or place fake payment forms over legitimate checkouts. The shared weakness is misplaced trust in an apparently normal interaction. These attacks require continuous checks of identity and behavior, not just trust in a login. The report brings together espionage, mobile malware, fraud, and extortion rather than describing one new malware family. The consequences range from stolen phone data and payment details to large fraudulent transfers and reputational damage.
The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft. With authorization from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs to seize 50 websites used to operate the service and disable more than 150 domains tied to … More → The post Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes appeared first on Help Net Security .
Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download a fake authenticator, and ended up killing 145 different antivirus and EDR products using a driver that Microsoft itself had signed. That last part is the one worth sitting with. LastPass’s Threat Intelligence, Mitigation, and Escalation team spotted the fake GitHub organization on August 13, 2026. It appeared high in search results for “LastPass Authenticator download” and used real LastPass logos and branding to look legitimate. The download page also displayed fake trust badges, including “VirusTotal Approved.” The badges were meaningless and were simply there to make users feel safe enough to download the file.
Attackers using AI have greatly benefited when it comes to speed and scale, and now, says Cisco Talos, the technology has evolved to execute large portions of the attack chain entirely without human involvement. Researchers at the threat intelligence group have identified what they call the first “LLM-as-C2” architecture that can fully automate the command-and-control (C2) chain. Dubbed CLOSEDQUORUM, the malware binary relies on a panel of large language model (LLM) judges to map and execute the optimal path to steal credentials. “This is not merely augmenting what an operator can accomplish in a session, but transferring an entire phase of the attack from the operator to the system,” Cisco Talos security and threat researcher Ryan Fetterman explained in a blog post . The benefits of speed and scale are compounded because the human-in-the-loop is no longer the bottleneck, he noted.
Recorded Future's Insikt Group Ⓡ has been tracking ClickFix, a social engineering technique that turns a familiar logo or verification prompt into the entry point for an attack. Here's what that research reveals about catching it, and why it's now running inside Malicious Site Monitoring, part of our newly launched Digital Risk Protection solution. Recorded Future's Insikt Group Ⓡ , our team of threat intelligence analysts and security researchers, has been tracking a technique called ClickFix as it works its way into a growing number of brand impersonation campaigns. We recently hosted a webinar digging into that research, and what stood out wasn't just the technique itself. There's no malware automatically installed, no exploit, just a page convincing enough that the victim ends up doing the damage themselves.
Microsoft has hailed its success in disrupting EvilTokens , an AI-powered a phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000 organizations worldwide. Since February 2026, EvilTokens has offered a subscription platform combining account compromise, mailbox analysis, target selection, and fraud preparation. Its dashboard and chatbot centralized access to those capabilities, with a $1,500 initial sign-up fee and $500 monthly subscription, marketed through Telegram channels. “EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service,” Microsoft explains in a post about the takedown . “Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface.”
CISA rides out a Cyber Storm. The EU struggles to share cyber threat information. Nightmare Eclipse drops another Defender zero-day. TASK#STOMP steals business documents. North Korean operatives fake their way through job interviews. A genetics lab pays $700,000 over a phishing breach. A zero-day in Meta’s Muse AI assistant opens the door to privilege hijacking. Marc Woolward, Senior Advisor to Humanix and former CTO for Goldman Sachs, discussing social engineering and vishing attacks. Infiltrating Team PCP. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.
Volexity researchers spotted another state-aligned Chinese threat group exploiting a triple-link chain of zero-day vulnerabilities across multiple campaigns, the company said in a blog post Monday. The threat group it tracks as UTA0565 exploited the vulnerabilities in Chrome and Microsoft between Sept. 3 and 4 before the defects were disclosed or patched, researchers said. The timing of the malicious activity mirrors other spikes threat hunters observed and attributed to multiple Chinese espionage threat groups. Yet, Volexity noted UTA0565’s campaigns differed from those attacks by using multiple fake websites to deceive victims. Volexity shared phishing emails UTA0565 sent to Asian government entities urging them to publicly support imprisoned Hong Kong activist Chow Hang-tung.
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U. S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver
In this article • What is device code phishing? • EvilTokens platform and operations • EvilTokens phishing emails • Mitigation and protection guidance • Microsoft Defender XDR detections • Hunting queries Following its emergence in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, providing cybercriminals with AI capabilities for tailoring phishing lures and analyzing compromised inboxes to identify high-value targets. This AI-powered cybercrime platform facilitated sophisticated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes in over 10,000 organizations worldwide. EvilTokens enabled threat actors to abuse the device code authentication flow, steal tokens, and compromise organizational accounts at scale using an AI-driven infrastructure and automating multiple parts of the attack chain.
Microsoft, along with a group of industry partners, disrupted EvilTokens, a short-lived but highly consequential cybercrime platform that investigators linked to more than 12,000 compromised Microsoft customer email inboxes across more than 10,000 organizations globally, the company said Tuesday. Acting on federal court order Sept. 15, Microsoft and partners seized 50 websites the phishing-as-a-service used for operations and disabled more than 175 domains linked to EvilTokens’ supporting infrastructure. EvilTokens, launched in February 2026, was “a powerful cybercrime platform that used AI at every step of the attack chain — from compromising email accounts to designing intricate roadmaps for financial fraud and scams,” Steven Masada, associate general counsel and general manager of Microsoft’s Digital Crimes Unit, wrote in a blog post .
Microsoft has confirmed a high-severity remote code execution vulnerability in on-premises SharePoint Server that lets an authenticated, low-privileged attacker run arbitrary code over a network without user interaction. Tracked as CVE-2026-65660, the code-injection flaw carries a CVSS score of 8.8 and affects SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Because SharePoint servers hold sensitive documents and operate with powerful service identities, successful exploitation could provide attackers with a foothold for credential theft, lateral movement, data exfiltration, and persistent access across environments. The vulnerability was discovered by Viettel Cyber Security researcher Dinh Ho Anh Khoa, who described it as another bypass of SharePoint’s SafeControls protection .
TASK#STOMP is a newly analyzed Windows backdoor that turns ordinary built-in tools into a durable spying operation. It uses a Visual Basic Script installer, hidden PowerShell, scheduled tasks, and runtime code compilation to collect business documents, saved Wi-Fi passwords, clipboard data, and screenshots from compromised machines. The observed infection begins with a randomly named VBS file in a user-accessible location. Its delivery route remains unconfirmed: the available evidence cannot distinguish phishing, a browser download, removable media, remote access, or an extracted archive. Once launched, the script builds several ways to survive a restart or partial cleanup. Securonix said in a report shared with Cyber Security News (CSN) that its analysts decoded the final payloads and identified TASK#STOMP as a fully working PowerShell backdoor.
Tomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. [... ]
A critical local privilege escalation flaw in Veeam Agent for Microsoft Windows is drawing attention after public proof-of-concept exploit code became available. The vulnerability, tracked as CVE-2026-32996 , could let a low-privileged local user run commands with NT AUTHORITY\SYSTEM permissions on affected Windows devices. Technical details and exploit code were publicly released on September 14, 2026, increasing the risk that threat actors may incorporate the issue into post-compromise attack chains. The flaw affects Veeam Agent for Microsoft Windows version 13. 0. 1. 2067 and earlier 13 builds. The issue exists in the Veeam Endpoint Backup service, which handles privileged client activity through a local gRPC named pipe located at \\.\pipe\Veeam\VAW\ServiceConnectionPipe.
Red Hat has disclosed an Important security vulnerability in the OpenShift oc-mirror tool that could allow attackers to bypass PGP signature verification and introduce malicious release images into disconnected OpenShift environments. Tracked as CVE-2026-75939, the issue carries a CVSS v3. 1 score of 7. 4 and was made public on September 21, 2026. The flaw affects the openshift/oc-mirror component, which organizations use to copy OpenShift release images, operator catalogs, and related content into private registries. This process is particularly important for air-gapped or disconnected deployments, where systems cannot download software directly from Red Hat registries or the public internet. According to Red Hat, oc-mirror incorrectly validates PGP-signed release image signatures. The tool checks for signature errors before it has finished processing the entire signed message body.
AI is letting cybercriminals reach deeper into organizations than a phishing email ever could. 41% of CISOs reported at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months, according to Gartner. 36% reported the same for a video call. 79% of CISOs surveyed reported at least one phishing, spear-phishing, or business email compromise incident in the past 12 months. 58% reported a vishing or smishing incident. … More → The post The latest deepfake numbers give CISOs plenty to worry about appeared first on Help Net Security .
Impersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC’s The State of Online IP Risk 2026 report. Internet and branded content, online marketplaces and paid search were the channels most frequently targeted. CSC surveyed 300 senior executives specializing in intellectual property law during the second quarter of 2026. Top three operational challenges when managing IP infringements (Source: CSC) “We know from dealing with our customers that … More → The post The next intellectual property thief may sound like your CEO appeared first on Help Net Security .
ANY. RUN researchers investigated CSuite , a phishing and remote-access operation that combines credential theft, Microsoft 365 session hijacking, and the abuse of legitimate management tools. The campaign showed a strong US focus, with 60% of identified victim organizations based in the United States . By blending trusted business services with legitimate remote-access software, CSuite can give attackers both account and endpoint access while making malicious activity harder to distinguish from normal workflows. Discover how the operation works, which tools and techniques it relies on, and what SOC teams should watch to detect related activity earlier. TL;DR • CSuite is a multi-stage phishing and remote-access operation targeting organizations across the US and Europe.
• CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project , exhibits fully autonomous command and control (C2). While we do not have confirmation of in-the-wild deployment, artifacts from the binary were used to connect the developer to postings on criminal forums related to carding, dating back to 2025. • This malware is a useful reference example of how attackers can collapse the decision space of a particular attack phase into a constrained set of choices, allowing AI models to provide reasoning and act independently. • CLOSEDQUORUM represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement. AI’s impact on offensive cyber operations has thus far mainly focused on two dimensions: speed and scale .
Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to detect