NovaCookies: A New AitM Phishing Kit Targeting Microsoft 365
NovaCookies is a subscription-based phishing-as-a-service (PhaaS) toolkit that uses adversary-in-the-middle (AitM) techniques to steal Microsoft 365 sessions. It is sold for $320…
NovaCookies is a subscription-based phishing-as-a-service (PhaaS) toolkit that uses adversary-in-the-middle (AitM) techniques to steal Microsoft 365 sessions. It is sold for $320…
DOUBLOON DREDGER is a financially motivated threat actor that abuses Notion accounts to invite targets to view PDFs containing malicious links. The…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released advisory AA26-237A, titled "A Tale of Two SOCs," on August 25, 2026, detailing…
Cybersecurity researchers have uncovered a phishing-as-a-service (PhaaS) platform called AnonyMousKIT that uses AI voice agents to trick owners of stolen Apple devices…
AnonyMousKIT is a phishing-as-a-service platform that uses AI voice agents and multi-channel lures to steal Apple device passcodes and 2FA codes from…
Mirage Security analyzed a subscription vishing service with commercial text-to-speech, providing insights into the evolution of AI-driven phishing.
Meta has announced new WhatsApp account security features, including support for multiple passkeys per account on both iOS and Android, enhancing phishing-resistant…
Cybersecurity researchers have uncovered a novel campaign that abuses FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote…
Cybersecurity researchers at OX Security have uncovered a campaign that abuses 24 npm packages as free phishing infrastructure. The packages host HTML…
unpkg is a content delivery network for npm packages. Threat actors have abused it to host malicious HTML files that render as…