<?xml version="1.0" encoding="UTF-8" ?> 
<rss version="2.0" xmlns:atom="https://www.w3.org/2005/Atom"> 
<channel> 
<title><![CDATA[Team IT Security - 🎥 IT Security Video]]></title> 
<link><![CDATA[https://tsecurity.de/feed.php?typ=1&q=Phishing]]></link> 
<description><![CDATA[Willkommen bei Cybersecurity Videos, Ihrem Informationsportal für IT-Sicherheit. Hier können Sie sich über die aktuellsten Themen, Herausforderungen und Lösungen im Bereich der Cybersecurity informieren. Ob Sie sich für Hacking, Malware, Ransomware, Datenschutz oder andere Aspekte der IT-Sicherheit interessieren, hier finden Sie eine Vielzahl von Videos, die Ihnen wertvolle Einblicke und Ratschläge bieten. Lernen Sie von renommierten Fachleuten, wie Sie sich und Ihre Systeme vor Cyberangriffen schützen können. Entdecken Sie neue Tools, Technologien und Trends, die die Zukunft der Cybersecurity gestalten. Und lassen Sie sich inspirieren von spannenden Geschichten und Erfahrungen aus der Praxis. Cybersecurity Videos ist Ihr Portal für alles rund um IT-Sicherheit.]]></description>
<copyright>2026</copyright>
<atom:link href="https://tsecurity.de/feed.php?typ=1&amp;q=Phishing" rel="self" type="application/rss+xml" />
<item> 
<title><![CDATA[AI Phishing Looks Too Real]]></title> 
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:68 AI-assisted phishing campaigns can now incorporate publicly available information such as conference schedules, speaker lists, and organizational roles. In this case, a message referencing Zero Trust World used a SharePoint link and appeared to come from an event organizer.

Recipients engaged with it because it aligned with expected pre-event communication.

The traditional indicators of phishing &mdash; poor grammar, generic messaging, or irrelevant context &mdash; are becoming less reliable.

Attacks increasingly blend into normal business processes, making human verification harder without disrupting workflows.

If malicious messages are indistinguishable from legitimate operational communication, where should the burden of verification actually sit?

Subscribe to our podcasts: https://securityweekly.com/subscribe

#Phishing #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec ]]></description>
<link>https://tsecurity.de/de/3611376/IT+Sicherheit/Cybersecurity+Videos/AI+Phishing+Looks+Too+Real/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611376/IT+Sicherheit/Cybersecurity+Videos/AI+Phishing+Looks+Too+Real/</guid>
<pubDate>Sat, 20 Jun 2026 00:00:05 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing erkennen trotz künstlicher Intelligenz - Netzpalaver]]></title> 
<description><![CDATA[Tags:CybersecurityCybersicherheitKI-ArtefaktKnowBe4k&uuml;nstliche IntelligenzPhishingSecurity-Awareness ... Helmich IT-Security &middot; HiScout &middot; IBM &middot; Imory&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3610801/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing+erkennen+trotz+k%C3%BCnstlicher+Intelligenz+-+Netzpalaver/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610801/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing+erkennen+trotz+k%C3%BCnstlicher+Intelligenz+-+Netzpalaver/</guid>
<pubDate>Fri, 19 Jun 2026 13:00:05 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Operation Ghost Hook: KI-Phishing-Netz mit 1,9 Mrd. Euro Schaden - BornCity]]></title> 
<description><![CDATA[Ermittler zerschlagen mehrere Phishing-Ringe, darunter ein KI-gesteuertes Netzwerk mit fast zwei Milliarden Euro Schaden und Millionen gestohlener&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3609717/IT+Sicherheit/Hacker/Operation+Ghost+Hook%3A+KI-Phishing-Netz+mit+1%2C9+Mrd.+Euro+Schaden+-+BornCity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609717/IT+Sicherheit/Hacker/Operation+Ghost+Hook%3A+KI-Phishing-Netz+mit+1%2C9+Mrd.+Euro+Schaden+-+BornCity/</guid>
<pubDate>Fri, 19 Jun 2026 02:55:26 +0200</pubDate>
</item>
<item> 
<title><![CDATA[NFT-Phishing: Hacker erbeuten 282 Millionen Euro mit Social Engineering - Börse Express]]></title> 
<description><![CDATA[Die T&auml;ter setzen dabei nicht mehr auf Schwachstellen im Code, sondern auf perfide psychologische Tricks und die &Uuml;bernahme offizieller&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3609715/IT+Sicherheit/Hacker/NFT-Phishing%3A+Hacker+erbeuten+282+Millionen+Euro+mit+Social+Engineering+-+B%C3%B6rse+Express/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609715/IT+Sicherheit/Hacker/NFT-Phishing%3A+Hacker+erbeuten+282+Millionen+Euro+mit+Social+Engineering+-+B%C3%B6rse+Express/</guid>
<pubDate>Fri, 19 Jun 2026 07:52:48 +0200</pubDate>
</item>
<item> 
<title><![CDATA[eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)]]></title> 
<description><![CDATA[I detected an interesting phishing email this morning. It targets a major Belgian bank: This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)
Read more &rarr;
The post eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th) appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3609627/IT+Sicherheit/Cybersecurity+Nachrichten/eBanking+Phishing+Delivered+Through+IPv4-Mapped+IPv6+Address%2C+%28Fri%2C+Jun+19th%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609627/IT+Sicherheit/Cybersecurity+Nachrichten/eBanking+Phishing+Delivered+Through+IPv4-Mapped+IPv6+Address%2C+%28Fri%2C+Jun+19th%29/</guid>
<pubDate>Fri, 19 Jun 2026 09:34:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)]]></title> 
<description><![CDATA[I detected an interesting phishing email this morning. It targets a major Belgian bank: ]]></description>
<link>https://tsecurity.de/de/3609611/IT+Sicherheit/Cybersecurity+Nachrichten/eBanking+Phishing+Delivered+Through+IPv4-Mapped+IPv6+Address%2C+%28Fri%2C+Jun+19th%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609611/IT+Sicherheit/Cybersecurity+Nachrichten/eBanking+Phishing+Delivered+Through+IPv4-Mapped+IPv6+Address%2C+%28Fri%2C+Jun+19th%29/</guid>
<pubDate>Fri, 19 Jun 2026 09:05:36 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FBI Warns of a Hidden Web Tactic Fueling Phishing and Ransomware]]></title> 
<description><![CDATA[The FBI Warns of Malicious Traffic Distribution Systems being increasingly used by cybercriminals to redirect internet users to phishing pages, malware downloads, ransomware attacks, and online financial scams. In a newly released Public Service Announcement (PSA), the Federal Bureau of Investigation cautioned that cybercriminals are leveraging Traffic Distribution Systems (TDS) to gain access to victim networks while evading traditional security controls.

According to the FBI, TDS technology is designed to route internet traffic to different destinations after users visit websites, click advertisements, download applications, or engage with online promotions. While the technology itself has legitimate uses, cybercriminals are exploiting it to selectively redirect users to compromised websites and fraudulent login pages.
FBI Warns of Malicious Traffic Distribution Systems Used in Cyber Attacks
As the FBI Warns of Malicious Traffic Distribution Systems, the agency explained that cybercriminals often drive victims to a malicious TDS through various methods,&nbsp;including Social Engineering, phishing emails, malicious advertisements, and compromised websites.

One common technique involves Search Engine Optimization (SEO) Poisoning, where fraudulent advertisements are designed to imitate legitimate websites. Users who click these links may unknowingly enter a redirection chain controlled by threat actors.

Cybercriminals also compromise legitimate websites by exploiting weak passwords, outdated plugins, and vulnerable website themes. Once administrative access is obtained, attackers can modify website code to automatically redirect visitors to a malicious TDS infrastructure.
How Traffic Distribution Systems Help Evade Detection
According to the FBI, Traffic Distribution Systems (TDS) can bypass traditional firewall protections that would normally block access to malicious websites.

The system uses multiple intermediate nodes before directing users to the final destination, making it more difficult for defenders to identify and block malicious activity.

In addition to hiding malicious infrastructure, attackers use TDS platforms to gather information about visitors. Data collected may include:

 	IP address
 	Operating system
 	Geographic location
 	Device information
 	Browser details

The FBI noted that this information allows attackers to determine whether a victim is a suitable target. It also enables cybercriminals to avoid detection by presenting harmless content to users they are not interested in targeting, including security researchers and analysts.
Phishing, Malware, and Ransomware Risks
The FBI warned that users reaching the end of a malicious redirection chain may encounter Phishing Pages, financial fraud schemes, or malware downloads.

In some cases, attackers use malware delivered through a TDS to gain access to victim networks. The agency stated that compromised accounts and network access obtained through these methods may later be sold to other criminal groups, including Ransomware operators.

The PSA highlights how a single visit to a compromised website or malicious advertisement can ultimately lead to broader cybersecurity incidents.
FBI Shares Protection Measures
To reduce the risk of compromise, the FBI advised individuals to verify website URLs before clicking advertisements or promotional links. The agency also recommended keeping software, website plugins, and themes updated to address known vulnerabilities.

Additional recommendations include:

 	Using strong passwords
 	Enabling Two-Factor Authentication (2FA)
 	Installing reputable security plugins and web application firewalls
 	Downloading software only from trusted developers

For businesses, the FBI recommended monitoring endpoints for suspicious activity involving JavaScript, PowerShell, and script execution tools. Organizations are also encouraged to strengthen phishing awareness training, regularly audit website administration accounts, and patch content management systems and third-party components.
FBI Urges Victims to Report Incidents
The FBI encouraged individuals and organizations that believe they have been affected by activity linked to malicious TDS infrastructure to report the incident through the Internet Crime Complaint Center (IC3) and contact their local FBI field office.

The agency emphasized that cybercriminals continue to evolve their techniques for delivering malware and conducting online fraud, making vigilance and proactive cybersecurity measures essential for both individuals and businesses. ]]></description>
<link>https://tsecurity.de/de/3609502/IT+Sicherheit/Cybersecurity+Nachrichten/FBI+Warns+of+a+Hidden+Web+Tactic+Fueling+Phishing+and+Ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609502/IT+Sicherheit/Cybersecurity+Nachrichten/FBI+Warns+of+a+Hidden+Web+Tactic+Fueling+Phishing+and+Ransomware/</guid>
<pubDate>Fri, 19 Jun 2026 07:58:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Gezieltes Urlaubs-Phishing mit neuer Qualität]]></title> 
<description><![CDATA[
    Mit Beginn der Reisesaison nehmen auch Cyberangriffe auf Urlauber wieder zu. 

Tags: #Phishing | #Urlaub ]]></description>
<link>https://tsecurity.de/de/3609480/IT+Sicherheit/Cybersecurity+Nachrichten/Gezieltes+Urlaubs-Phishing+mit+neuer+Qualit%C3%A4t/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609480/IT+Sicherheit/Cybersecurity+Nachrichten/Gezieltes+Urlaubs-Phishing+mit+neuer+Qualit%C3%A4t/</guid>
<pubDate>Fri, 19 Jun 2026 07:20:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories]]></title> 
<description><![CDATA[Ravie LakshmananJun 18, 2026Hacking News / Cybersecurity News The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. Cloud agents looked like helpers until [&hellip;] ]]></description>
<link>https://tsecurity.de/de/3609319/IT+Sicherheit/Cybersecurity+Nachrichten/ThreatsDay+Bulletin%3A+Claude+Chat+Abuse%2C+NastyC2+npm+Packages%2C+Device-Code+Phishing+%2B+25+More+Stories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609319/IT+Sicherheit/Cybersecurity+Nachrichten/ThreatsDay+Bulletin%3A+Claude+Chat+Abuse%2C+NastyC2+npm+Packages%2C+Device-Code+Phishing+%2B+25+More+Stories/</guid>
<pubDate>Fri, 19 Jun 2026 05:17:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories]]></title> 
<description><![CDATA[The internet did not break this week. It got used exactly as designed, which is worse.

Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. Cloud agents looked like helpers until attackers treated them like open shells.

Add exposed edge gear, poisoned packages, cash courier scams, ]]></description>
<link>https://tsecurity.de/de/3608360/IT+Sicherheit/Cybersecurity+Nachrichten/ThreatsDay+Bulletin%3A+Claude+Chat+Abuse%2C+NastyC2+npm+Packages%2C+Device-Code+Phishing+%2B+25+More+Stories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608360/IT+Sicherheit/Cybersecurity+Nachrichten/ThreatsDay+Bulletin%3A+Claude+Chat+Abuse%2C+NastyC2+npm+Packages%2C+Device-Code+Phishing+%2B+25+More+Stories/</guid>
<pubDate>Thu, 18 Jun 2026 17:27:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Abuse PowerShell Commands to Deliver SmartRAT Through Brazilian Bank Phishing Page]]></title> 
<description><![CDATA[A new cyberattack campaign has emerged, using cleverly crafted phishing pages and PowerShell tricks to deliver a dangerous piece of malware called SmartRAT. The attack targets Brazilian banking customers and combines social engineering with AI-generated web pages to make the&hellip;
Read more &rarr;
The post Hackers Abuse PowerShell Commands to Deliver SmartRAT Through Brazilian Bank Phishing Page appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3607944/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Abuse+PowerShell+Commands+to+Deliver+SmartRAT+Through+Brazilian+Bank+Phishing+Page/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607944/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Abuse+PowerShell+Commands+to+Deliver+SmartRAT+Through+Brazilian+Bank+Phishing+Page/</guid>
<pubDate>Thu, 18 Jun 2026 15:34:36 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Abuse PowerShell Commands to Deliver SmartRAT Through Brazilian Bank Phishing Page]]></title> 
<description><![CDATA[A new cyberattack campaign has emerged, using cleverly crafted phishing pages and PowerShell tricks to deliver a dangerous piece of malware called SmartRAT. The attack targets Brazilian banking customers and combines social engineering with AI-generated web pages to make the threat feel disturbingly real. Researchers say the campaign marks a troubling shift in how attackers [&hellip;]
The post Hackers Abuse PowerShell Commands to Deliver SmartRAT Through Brazilian Bank Phishing Page appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3607536/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Abuse+PowerShell+Commands+to+Deliver+SmartRAT+Through+Brazilian+Bank+Phishing+Page/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607536/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Abuse+PowerShell+Commands+to+Deliver+SmartRAT+Through+Brazilian+Bank+Phishing+Page/</guid>
<pubDate>Thu, 18 Jun 2026 13:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Abuse Fake Anonymous Tips to Trick Executives Into Clicking Phishing Links]]></title> 
<description><![CDATA[Hacking enterprise networks is becoming increasingly difficult as organizations invest heavily in robust security architecture. To bypass these hardened defenses, sophisticated threat actors are shifting their focus from exploiting software to exploiting human psychology. A recent social engineering assessment highlights how advanced these attacks have become, demonstrating that attackers can compromise high-level executives by posing [&hellip;]
The post Hackers Abuse Fake Anonymous Tips to Trick Executives Into Clicking Phishing Links appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3607191/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Abuse+Fake+Anonymous+Tips+to+Trick+Executives+Into+Clicking+Phishing+Links/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607191/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Abuse+Fake+Anonymous+Tips+to+Trick+Executives+Into+Clicking+Phishing+Links/</guid>
<pubDate>Thu, 18 Jun 2026 11:17:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies]]></title> 
<description><![CDATA[AUSTIN, Tex., June 17, 2026, CyberNewswire&ndash;SpyCloud, the leader in identity threat protection, today released its 2026 Phishing Pulse Report, revealing that phishing attacks continue to increase in both volume and sophistication for enterprise organizations as artificial intelligence &hellip; (more&hellip;) 
The post News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies first appeared on The Last Watchdog. ]]></description>
<link>https://tsecurity.de/de/3605786/IT+Sicherheit/Cybersecurity+Nachrichten/News+alert%3A+SpyCloud+report+finds+phishing+surge+exposing+employee+data+at+Fortune+100+companies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605786/IT+Sicherheit/Cybersecurity+Nachrichten/News+alert%3A+SpyCloud+report+finds+phishing+surge+exposing+employee+data+at+Fortune+100+companies/</guid>
<pubDate>Wed, 17 Jun 2026 20:17:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[GitBait Phishing Campaign Abuses GitHub Pages to Attack Financial Institutions]]></title> 
<description><![CDATA[A sophisticated phishing campaign called &ldquo;GitBait&rdquo; has been caught targeting Mexico&rsquo;s financial sector with a level of precision rarely seen in credential-theft operations. The campaign abuses GitHub Pages, a widely trusted free hosting service, to deliver fake banking portals that&hellip;
Read more &rarr;
The post GitBait Phishing Campaign Abuses GitHub Pages to Attack Financial Institutions appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3605760/IT+Sicherheit/Cybersecurity+Nachrichten/GitBait+Phishing+Campaign+Abuses+GitHub+Pages+to+Attack+Financial+Institutions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605760/IT+Sicherheit/Cybersecurity+Nachrichten/GitBait+Phishing+Campaign+Abuses+GitHub+Pages+to+Attack+Financial+Institutions/</guid>
<pubDate>Wed, 17 Jun 2026 20:04:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[GitBait Phishing Campaign Abuses GitHub Pages to Attack Financial Institutions]]></title> 
<description><![CDATA[A sophisticated phishing campaign called &ldquo;GitBait&rdquo; has been caught targeting Mexico&rsquo;s financial sector with a level of precision rarely seen in credential-theft operations. The campaign abuses GitHub Pages, a widely trusted free hosting service, to deliver fake banking portals that look nearly identical to the real thing. Victims who land on these pages are tricked [&hellip;]
The post GitBait Phishing Campaign Abuses GitHub Pages to Attack Financial Institutions appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3605600/IT+Sicherheit/Cybersecurity+Nachrichten/GitBait+Phishing+Campaign+Abuses+GitHub+Pages+to+Attack+Financial+Institutions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605600/IT+Sicherheit/Cybersecurity+Nachrichten/GitBait+Phishing+Campaign+Abuses+GitHub+Pages+to+Attack+Financial+Institutions/</guid>
<pubDate>Wed, 17 Jun 2026 18:52:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[URL Phishing Is Draining SOCs, How to Cut Triage Time and Catch Incidents Early  ]]></title> 
<description><![CDATA[URL phishing is becoming harder to triage at scale.&nbsp;Suspicious links can hide behind redirects, fresh domains, and browser-side changes that basic URL checks often miss. For analysts, that means more time spent rebuilding what the page&nbsp;actually does&nbsp;before they can make a clear decision.&nbsp; To respond faster, SOC teams need browser-level visibility: what the page loads, [&hellip;]
The post URL Phishing Is Draining SOCs, How to Cut Triage Time and Catch Incidents Early&nbsp;&nbsp; appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3605546/IT+Sicherheit/Cybersecurity+Nachrichten/URL+Phishing+Is+Draining+SOCs%2C+How+to+Cut+Triage+Time+and+Catch+Incidents+Early%C2%A0%C2%A0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605546/IT+Sicherheit/Cybersecurity+Nachrichten/URL+Phishing+Is+Draining+SOCs%2C+How+to+Cut+Triage+Time+and+Catch+Incidents+Early%C2%A0%C2%A0/</guid>
<pubDate>Wed, 17 Jun 2026 18:42:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies]]></title> 
<description><![CDATA[Austin, TX, USA, June 17th, 2026, CyberNewswire New SpyCloud research highlights the expansion of phishing attacks as AI and phishing-as-a-service fuel enterprise targeting. SpyCloud, the leader in identity threat protection, today released its 2026 Phishing Pulse Report, revealing that phishing attacks continue to increase in both volume and sophistication for enterprise organizations as artificial intelligence [&hellip;]
The post SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3605545/IT+Sicherheit/Cybersecurity+Nachrichten/SpyCloud+Report+Finds+Phishing+Attacks+Surge+as+Employee+Data+Is+Exposed+at+86%25+of+Fortune+100+Companies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605545/IT+Sicherheit/Cybersecurity+Nachrichten/SpyCloud+Report+Finds+Phishing+Attacks+Surge+as+Employee+Data+Is+Exposed+at+86%25+of+Fortune+100+Companies/</guid>
<pubDate>Wed, 17 Jun 2026 18:42:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies]]></title> 
<description><![CDATA[Austin, TX, USA, June 17th, 2026, CyberNewswire New SpyCloud research highlights the expansion of phishing attacks as AI and phishing-as-a-service fuel enterprise targeting. SpyCloud, the leader in identity threat protection, today released its 2026 Phishing Pulse Report, revealing that phishing attacks continue to increase in both volume and sophistication for enterprise organizations as artificial intelligence [&hellip;]
The post SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3605544/IT+Sicherheit/Cybersecurity+Nachrichten/SpyCloud+Report+Finds+Phishing+Attacks+Surge+as+Employee+Data+Is+Exposed+at+86%25+of+Fortune+100+Companies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605544/IT+Sicherheit/Cybersecurity+Nachrichten/SpyCloud+Report+Finds+Phishing+Attacks+Surge+as+Employee+Data+Is+Exposed+at+86%25+of+Fortune+100+Companies/</guid>
<pubDate>Wed, 17 Jun 2026 18:44:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing, Banking-Trojaner und Stealer-Logs bedrohen WM-Fans - Security-Insider]]></title> 
<description><![CDATA[FIFA WM 2026 im Visier von Cyberkriminellen Geklonte FIFA-Seiten, Banking-Trojaner und Stealer-Logs bedrohen WM-Fans. 17.06.2026 Von Thomas Joos 4 min&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3605504/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing%2C+Banking-Trojaner+und+Stealer-Logs+bedrohen+WM-Fans+-+Security-Insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605504/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing%2C+Banking-Trojaner+und+Stealer-Logs+bedrohen+WM-Fans+-+Security-Insider/</guid>
<pubDate>Wed, 17 Jun 2026 16:39:03 +0200</pubDate>
</item>
<item> 
<title><![CDATA[SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies]]></title> 
<description><![CDATA[Austin, TX, USA, 17th June 2026, CyberNewswire
SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses. ]]></description>
<link>https://tsecurity.de/de/3605376/IT+Sicherheit/Cybersecurity+Nachrichten/SpyCloud+Report+Finds+Phishing+Attacks+Surge+as+Employee+Data+Is+Exposed+at+86%25+of+Fortune+100+Companies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605376/IT+Sicherheit/Cybersecurity+Nachrichten/SpyCloud+Report+Finds+Phishing+Attacks+Surge+as+Employee+Data+Is+Exposed+at+86%25+of+Fortune+100+Companies/</guid>
<pubDate>Wed, 17 Jun 2026 15:00:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Gezieltes Urlaubs-Phishing in neuer Qualität - Netzpalaver]]></title> 
<description><![CDATA[Die Bitdefender Labs erkennen in ihrer aktuellen Analyse des Geschehens in &uuml;ber zehn L&auml;ndern &ndash; einschlie&szlig;lich Deutschlands &ndash; aber neue,&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3605285/IT+Sicherheit/Hacker/Gezieltes+Urlaubs-Phishing+in+neuer+Qualit%C3%A4t+-+Netzpalaver/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605285/IT+Sicherheit/Hacker/Gezieltes+Urlaubs-Phishing+in+neuer+Qualit%C3%A4t+-+Netzpalaver/</guid>
<pubDate>Wed, 17 Jun 2026 16:31:48 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Serverless Phishing Kit on GitHub Targets Mexican Banks]]></title> 
<description><![CDATA[GitBait phishing kit abuses GitHub Pages and the SheetBest API to steal Mexican banking credentials This article has been indexed from www.infosecurity-magazine.com Read the original article: Serverless Phishing Kit on GitHub Targets Mexican Banks
Read more &rarr;
The post Serverless Phishing Kit on GitHub Targets Mexican Banks appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3605110/IT+Sicherheit/Cybersecurity+Nachrichten/Serverless+Phishing+Kit+on+GitHub+Targets+Mexican+Banks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605110/IT+Sicherheit/Cybersecurity+Nachrichten/Serverless+Phishing+Kit+on+GitHub+Targets+Mexican+Banks/</guid>
<pubDate>Wed, 17 Jun 2026 16:07:28 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Serverless Phishing Kit on GitHub Targets Mexican Banks]]></title> 
<description><![CDATA[GitBait phishing kit abuses GitHub Pages and the SheetBest API to steal Mexican banking credentials ]]></description>
<link>https://tsecurity.de/de/3605061/IT+Sicherheit/Cybersecurity+Nachrichten/Serverless+Phishing+Kit+on+GitHub+Targets+Mexican+Banks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605061/IT+Sicherheit/Cybersecurity+Nachrichten/Serverless+Phishing+Kit+on+GitHub+Targets+Mexican+Banks/</guid>
<pubDate>Wed, 17 Jun 2026 16:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Modular Phishing Kit Uses GitHub Pages to Steal Payment Card Details and Passwords]]></title> 
<description><![CDATA[A sophisticated, long-running phishing operation has evolved into a serverless, modular campaign that weaponizes GitHub Pages to harvest payment card data, credentials, and customer identifiers from banking customers in Mexico. The campaign&rsquo;s architecture centers on a phishing kit containing a&hellip;
Read more &rarr;
The post Modular Phishing Kit Uses GitHub Pages to Steal Payment Card Details and Passwords appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3604930/IT+Sicherheit/Cybersecurity+Nachrichten/Modular+Phishing+Kit+Uses+GitHub+Pages+to+Steal+Payment+Card+Details+and+Passwords/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604930/IT+Sicherheit/Cybersecurity+Nachrichten/Modular+Phishing+Kit+Uses+GitHub+Pages+to+Steal+Payment+Card+Details+and+Passwords/</guid>
<pubDate>Wed, 17 Jun 2026 15:07:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies]]></title> 
<description><![CDATA[Austin, TX, USA, 17th June 2026, CyberNewswire This article has been indexed from Hackread &ndash; Cybersecurity News, Data Breaches, AI and More Read the original article: SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of&hellip;
Read more &rarr;
The post SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3604929/IT+Sicherheit/Cybersecurity+Nachrichten/SpyCloud+Report+Finds+Phishing+Attacks+Surge+as+Employee+Data+Is+Exposed+at+86%25+of+Fortune+100+Companies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604929/IT+Sicherheit/Cybersecurity+Nachrichten/SpyCloud+Report+Finds+Phishing+Attacks+Surge+as+Employee+Data+Is+Exposed+at+86%25+of+Fortune+100+Companies/</guid>
<pubDate>Wed, 17 Jun 2026 15:07:36 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FBI takes down Phishing-as-a-Service platform "Outsider" | heise online]]></title> 
<description><![CDATA[... cybercrime. Videos by heise. mehr Videos. c&#039;t 3003 &middot; heise &amp; ct &middot; Peertube. In this context, Google has also explained that the company intends to&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3604896/IT+Sicherheit/Cybersecurity+Nachrichten/FBI+takes+down+Phishing-as-a-Service+platform+%22Outsider%22+%7C+heise+online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604896/IT+Sicherheit/Cybersecurity+Nachrichten/FBI+takes+down+Phishing-as-a-Service+platform+%22Outsider%22+%7C+heise+online/</guid>
<pubDate>Tue, 16 Jun 2026 15:45:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Modular Phishing Kit Uses GitHub Pages to Steal Payment Card Details and Passwords]]></title> 
<description><![CDATA[A sophisticated, long-running phishing operation has evolved into a serverless, modular campaign that weaponizes GitHub Pages to harvest payment card data, credentials, and customer identifiers from banking customers in Mexico. The campaign&rsquo;s architecture centers on a phishing kit containing a selector panel that operators use to generate institution-specific landing pages. Those landing pages impersonate at [&hellip;]
The post Modular Phishing Kit Uses GitHub Pages to Steal Payment Card Details and Passwords appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3604893/IT+Sicherheit/Cybersecurity+Nachrichten/Modular+Phishing+Kit+Uses+GitHub+Pages+to+Steal+Payment+Card+Details+and+Passwords/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604893/IT+Sicherheit/Cybersecurity+Nachrichten/Modular+Phishing+Kit+Uses+GitHub+Pages+to+Steal+Payment+Card+Details+and+Passwords/</guid>
<pubDate>Wed, 17 Jun 2026 14:59:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies]]></title> 
<description><![CDATA[Austin, TX, USA, 17th June 2026, CyberNewswire ]]></description>
<link>https://tsecurity.de/de/3604890/IT+Sicherheit/Cybersecurity+Nachrichten/SpyCloud+Report+Finds+Phishing+Attacks+Surge+as+Employee+Data+Is+Exposed+at+86%25+of+Fortune+100+Companies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604890/IT+Sicherheit/Cybersecurity+Nachrichten/SpyCloud+Report+Finds+Phishing+Attacks+Surge+as+Employee+Data+Is+Exposed+at+86%25+of+Fortune+100+Companies/</guid>
<pubDate>Wed, 17 Jun 2026 15:00:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FBI nimmt Phishing-as-a-Service-Plattform „Outsider“ hops | heise online]]></title> 
<description><![CDATA[It was translated with ... Newsletter. Ob Sicherheitsl&uuml;cken, Viren oder Trojaner &ndash; alle sicherheitsrelevanten Meldungen gibts bei heise security&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3604633/IT+Sicherheit/Cybersecurity+Nachrichten/FBI+nimmt+Phishing-as-a-Service-Plattform+%E2%80%9EOutsider%E2%80%9C+hops+%7C+heise+online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604633/IT+Sicherheit/Cybersecurity+Nachrichten/FBI+nimmt+Phishing-as-a-Service-Plattform+%E2%80%9EOutsider%E2%80%9C+hops+%7C+heise+online/</guid>
<pubDate>Wed, 17 Jun 2026 09:49:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Product showcase: From phishing texts to risky Wi-Fi, Norton 360 Deluxe watches the gaps]]></title> 
<description><![CDATA[Norton 360 Deluxe combines device security, scam detection, web protection, and VPN privacy in a single subscription that covers up to five devices. It is available for Windows, macOS, Android, and iOS. Setup and first impressions After downloading the app&hellip;
Read more &rarr;
The post Product showcase: From phishing texts to risky Wi-Fi, Norton 360 Deluxe watches the gaps appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3603693/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+From+phishing+texts+to+risky+Wi-Fi%2C+Norton+360+Deluxe+watches+the+gaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603693/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+From+phishing+texts+to+risky+Wi-Fi%2C+Norton+360+Deluxe+watches+the+gaps/</guid>
<pubDate>Wed, 17 Jun 2026 07:33:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Product showcase: From phishing texts to risky Wi-Fi, Norton 360 Deluxe watches the gaps]]></title> 
<description><![CDATA[Norton 360 Deluxe combines device security, scam detection, web protection, and VPN privacy in a single subscription that covers up to five devices. It is available for Windows, macOS, Android, and iOS. Setup and first impressions After downloading the app from the App Store, users can complete the onboarding process in a few steps. They can activate a free trial, select a protection plan, and access key features from a centralized dashboard. The app displays &hellip; More &rarr;
The post Product showcase: From phishing texts to risky Wi-Fi, Norton 360 Deluxe watches the gaps appeared first on Help Net Security. ]]></description>
<link>https://tsecurity.de/de/3603633/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+From+phishing+texts+to+risky+Wi-Fi%2C+Norton+360+Deluxe+watches+the+gaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603633/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+From+phishing+texts+to+risky+Wi-Fi%2C+Norton+360+Deluxe+watches+the+gaps/</guid>
<pubDate>Wed, 17 Jun 2026 07:00:45 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Holiday season is here — but watch out, hackers are launching more phishing scams and attacks than ever before]]></title> 
<description><![CDATA[Firms in hospitality are hit with more than 2,000 attacks every week now, while consumers are being served fake accommodation sites. ]]></description>
<link>https://tsecurity.de/de/3603432/IT+Nachrichten/Holiday+season+is+here+%E2%80%94+but+watch+out%2C+hackers+are+launching+more+phishing+scams+and+attacks+than+ever+before/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603432/IT+Nachrichten/Holiday+season+is+here+%E2%80%94+but+watch+out%2C+hackers+are+launching+more+phishing+scams+and+attacks+than+ever+before/</guid>
<pubDate>Wed, 17 Jun 2026 03:20:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Brandgefährliche Phishing-Attacken nutzen echte Microsoft-Anmeldung - ntv.de]]></title> 
<description><![CDATA[Betrug im NetzFu&szlig;ball-WM ist Cybercrime-Time: Sieben Tipps zu Ihrem Schutz. Doch selbstverst&auml;ndlich gilt es auch f&uuml;r Nutzerinnen und Nutzer&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3602837/IT+Sicherheit/Cybersecurity+Nachrichten/Brandgef%C3%A4hrliche+Phishing-Attacken+nutzen+echte+Microsoft-Anmeldung+-+ntv.de/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602837/IT+Sicherheit/Cybersecurity+Nachrichten/Brandgef%C3%A4hrliche+Phishing-Attacken+nutzen+echte+Microsoft-Anmeldung+-+ntv.de/</guid>
<pubDate>Tue, 16 Jun 2026 18:48:21 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Google verklagt chinesisches Phishing-Netzwerk Outsider]]></title> 
<description><![CDATA[
    Google geht gerichtlich gegen ein chinesisches Cybernetzwerk vor, das die hauseigene KI Gemini zur Erstellung betr&uuml;gerischer SMS-Nachrichten nutzte.

Tags: #Cyber Crime | #Google | #Phishing ]]></description>
<link>https://tsecurity.de/de/3602716/IT+Sicherheit/Cybersecurity+Nachrichten/Google+verklagt+chinesisches+Phishing-Netzwerk+Outsider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602716/IT+Sicherheit/Cybersecurity+Nachrichten/Google+verklagt+chinesisches+Phishing-Netzwerk+Outsider/</guid>
<pubDate>Tue, 16 Jun 2026 19:03:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FBI nimmt Phishing-as-a-Service-Plattform „Outsider“ hops | heise online]]></title> 
<description><![CDATA[... Cybercrime zum Gegenstand hat. Videos by heise. mehr Videos. c&#039;t 3003 &middot; heise &amp; ct &middot; Peertube. In dem Zusammenhang hat Google zudem erl&auml;utert, dass&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3602645/IT+Sicherheit/Cybersecurity+Nachrichten/FBI+nimmt+Phishing-as-a-Service-Plattform+%E2%80%9EOutsider%E2%80%9C+hops+%7C+heise+online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602645/IT+Sicherheit/Cybersecurity+Nachrichten/FBI+nimmt+Phishing-as-a-Service-Plattform+%E2%80%9EOutsider%E2%80%9C+hops+%7C+heise+online/</guid>
<pubDate>Tue, 16 Jun 2026 18:54:23 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Black Hat Europe 2025 | Insights From Phishing-Resistant Authentication]]></title> 
<description><![CDATA[Author: Black Hat - Bewertung: 3x - Views:38 How many phishing attempts bypass enterprise pre-authentication security, including email gateways, DNS filtering, SASE, SWG, browser security, and endpoint protection, to trick users into malicious logins? And how effectively do current security systems detect and respond to these? While general phishing trends are known, the true impact and organizational defense postures remain unclear.
Analyzing two years of phishing attempts stopped only by phishing-resistant authentication, we quantify a notable volume of attacks that bypass the pre-authentication security layers and successfully trick users. We then dive into events linked to AiTM campaigns using EvilProxy kits, dissecting their patterns across verticals and company sizes, identifying indicators of compromise, and tracking longitudinal trends. As part of our investigation, we also reached out to impacted organizations, with a notable number indicating they hadn&#039;t detected these attempts until our notifications.
This work provides crucial, data-driven evidence highlighting the importance of phishing-resistant authentication and exposing many organizations&#039; often mediocre security postures. It transforms failed authentication into actionable threat intelligence, revealing and helping address organizations&#039; actual security gaps.

By: Fei Liu  |  Principal Emerging Technology Researcher, Okta ]]></description>
<link>https://tsecurity.de/de/3602636/IT+Sicherheit/Cybersecurity+Videos/Black+Hat+Europe+2025+%7C+Insights+From+Phishing-Resistant+Authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602636/IT+Sicherheit/Cybersecurity+Videos/Black+Hat+Europe+2025+%7C+Insights+From+Phishing-Resistant+Authentication/</guid>
<pubDate>Tue, 16 Jun 2026 18:40:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow]]></title> 
<description><![CDATA[A new phishing campaign targeting Microsoft 365 users has been uncovered, and it takes a different approach than most attacks seen in the wild. Instead of trying to steal a victim&rsquo;s password directly, this campaign tricks users into completing a&hellip;
Read more &rarr;
The post Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3602437/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft+365+Device+Code+Phishing+Campaign+Bypasses+Password+Theft+With+Legitimate+Login+Flow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602437/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft+365+Device+Code+Phishing+Campaign+Bypasses+Password+Theft+With+Legitimate+Login+Flow/</guid>
<pubDate>Tue, 16 Jun 2026 17:37:35 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow]]></title> 
<description><![CDATA[A new phishing campaign targeting Microsoft 365 users has been uncovered, and it takes a different approach than most attacks seen in the wild. Instead of trying to steal a victim&rsquo;s password directly, this campaign tricks users into completing a real Microsoft authentication process that quietly hands over control of their account to an attacker. [&hellip;]
The post Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3602147/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft+365+Device+Code+Phishing+Campaign+Bypasses+Password+Theft+With+Legitimate+Login+Flow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602147/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft+365+Device+Code+Phishing+Campaign+Bypasses+Password+Theft+With+Legitimate+Login+Flow/</guid>
<pubDate>Tue, 16 Jun 2026 16:19:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Silent Ransom Group Targets US Legal Firms With Voice Phishing and Data Theft Extortion]]></title> 
<description><![CDATA[A concentrated data theft extortion campaign by UNC3753 also reported as Luna Moth, Chatty Spider, and Silent Ransom Group targeting dozens of U.S. professional, legal, and financial services firms. The cluster&rsquo;s hallmark is fast, human-centric intrusions that combine voice phishing (vishing), social engineering, abuse of legitimate remote support tools, and in some cases physical office [&hellip;]
The post Silent Ransom Group Targets US Legal Firms With Voice Phishing and Data Theft Extortion appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3602042/IT+Sicherheit/Cybersecurity+Nachrichten/Silent+Ransom+Group+Targets+US+Legal+Firms+With+Voice+Phishing+and+Data+Theft+Extortion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602042/IT+Sicherheit/Cybersecurity+Nachrichten/Silent+Ransom+Group+Targets+US+Legal+Firms+With+Voice+Phishing+and+Data+Theft+Extortion/</guid>
<pubDate>Tue, 16 Jun 2026 15:27:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Silent Ransom Group Targets US Legal Firms With Voice Phishing and Data Theft Extortion]]></title> 
<description><![CDATA[A concentrated data theft extortion campaign by UNC3753 also reported as Luna Moth, Chatty Spider, and Silent Ransom Group targeting dozens of U.S. professional, legal, and financial services firms. The cluster&rsquo;s hallmark is fast, human-centric intrusions that combine voice phishing&hellip;
Read more &rarr;
The post Silent Ransom Group Targets US Legal Firms With Voice Phishing and Data Theft Extortion appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3601999/IT+Sicherheit/Cybersecurity+Nachrichten/Silent+Ransom+Group+Targets+US+Legal+Firms+With+Voice+Phishing+and+Data+Theft+Extortion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601999/IT+Sicherheit/Cybersecurity+Nachrichten/Silent+Ransom+Group+Targets+US+Legal+Firms+With+Voice+Phishing+and+Data+Theft+Extortion/</guid>
<pubDate>Tue, 16 Jun 2026 15:34:44 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FBI nimmt Phishing-as-a-Service-Plattform „Outsider“ hops]]></title> 
<description><![CDATA[Der Phishing-as-a-Service-Dienst &bdquo;Outsider&ldquo; wurde vom FBI vom Netz genommen. Auf tausenden Domains stahl er Millionen Kreditkarten. ]]></description>
<link>https://tsecurity.de/de/3601831/IT+Sicherheit/Cybersecurity+Nachrichten/FBI+nimmt+Phishing-as-a-Service-Plattform+%E2%80%9EOutsider%E2%80%9C+hops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601831/IT+Sicherheit/Cybersecurity+Nachrichten/FBI+nimmt+Phishing-as-a-Service-Plattform+%E2%80%9EOutsider%E2%80%9C+hops/</guid>
<pubDate>Tue, 16 Jun 2026 14:20:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FBI nimmt Phishing-as-a-Service-Plattform „Outsider“ hops]]></title> 
<description><![CDATA[Der Phishing-as-a-Service-Dienst &bdquo;Outsider&ldquo; wurde vom FBI vom Netz genommen. Auf tausenden Domains stahl er Millionen Kreditkarten. ]]></description>
<link>https://tsecurity.de/de/3601817/IT+Nachrichten/FBI+nimmt+Phishing-as-a-Service-Plattform+%E2%80%9EOutsider%E2%80%9C+hops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601817/IT+Nachrichten/FBI+nimmt+Phishing-as-a-Service-Plattform+%E2%80%9EOutsider%E2%80%9C+hops/</guid>
<pubDate>Tue, 16 Jun 2026 14:20:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[The New Standard for URL Analysis: Closing Phishing Blind Spots with In-Browser Data Inspection ]]></title> 
<description><![CDATA[Modern&nbsp;URL phishing relies&nbsp;on dynamic pages, credential harvesting flows, client-side scripts, and layered redirect chains. But most SOC workflows are still built around static analysis, making them blind to most of these&nbsp;tactics.&nbsp; ANY.RUN changes&nbsp;this forever with&nbsp;in-browser data inspection.&nbsp; The&nbsp;new technology&nbsp;takes URL analysis to the next level by bringing static and dynamic analysis into one single workflow.&nbsp;Now, [&hellip;]
The post The New Standard for URL Analysis: Closing Phishing&nbsp;Blind&nbsp;Spots&nbsp;with In-Browser Data Inspection&nbsp; appeared first on ANY.RUN&#039;s Cybersecurity Blog. ]]></description>
<link>https://tsecurity.de/de/3601442/IT+Sicherheit/Cybersecurity+Nachrichten/The+New+Standard+for+URL+Analysis%3A+Closing+Phishing%C2%A0Blind%C2%A0Spots%C2%A0with+In-Browser+Data+Inspection%C2%A0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601442/IT+Sicherheit/Cybersecurity+Nachrichten/The+New+Standard+for+URL+Analysis%3A+Closing+Phishing%C2%A0Blind%C2%A0Spots%C2%A0with+In-Browser+Data+Inspection%C2%A0/</guid>
<pubDate>Tue, 16 Jun 2026 12:11:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Microsoft 365 Users Targeted by Device Code Phishing Campaign Using OAuth 2.0 Flow]]></title> 
<description><![CDATA[Cybersecurity researchers have uncovered an active phishing campaign targeting corporate Microsoft 365 users by exploiting the OAuth 2.0 Device Authorization Grant flow. Instead of relying on traditional credential harvesting via fake login pages, this sophisticated attack tricks victims into authorizing an attacker-controlled device. This method leverages legitimate Microsoft authentication infrastructure, making the intrusion highly convincing [&hellip;]
The post Microsoft 365 Users Targeted by Device Code Phishing Campaign Using OAuth 2.0 Flow appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3601155/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft+365+Users+Targeted+by+Device+Code+Phishing+Campaign+Using+OAuth+2.0+Flow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601155/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft+365+Users+Targeted+by+Device+Code+Phishing+Campaign+Using+OAuth+2.0+Flow/</guid>
<pubDate>Tue, 16 Jun 2026 10:23:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[UNC1151 Ghostwriter Hackers Target Gmail Users With 2FA-Stealing Phishing Campaign]]></title> 
<description><![CDATA[The advanced persistent threat (APT) group UNC1151, widely tracked under the alias Ghostwriter, has significantly escalated its cyber espionage operations. Traditionally known for targeting regional Polish email providers like Onet, Wirtualna Polska, and Interia, the state-sponsored threat actors have abruptly shifted their focus. Since March 2026, the group has launched highly intensive phishing campaigns specifically [&hellip;]
The post UNC1151 Ghostwriter Hackers Target Gmail Users With 2FA-Stealing Phishing Campaign appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3601151/IT+Sicherheit/Cybersecurity+Nachrichten/UNC1151+Ghostwriter+Hackers+Target+Gmail+Users+With+2FA-Stealing+Phishing+Campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601151/IT+Sicherheit/Cybersecurity+Nachrichten/UNC1151+Ghostwriter+Hackers+Target+Gmail+Users+With+2FA-Stealing+Phishing+Campaign/</guid>
<pubDate>Tue, 16 Jun 2026 10:41:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Belarus-Linked UNC1151 Launches Gmail Phishing Campaign to Steal 2FA Codes]]></title> 
<description><![CDATA[The UNC1151 Gmail phishing campaign has emerged as a cyber threat targeting Polish internet users, with attackers now focusing on Gmail accounts and deploying phishing pages capable of stealing both passwords and two-factor authentication (2FA) credentials. According to researchers at CERT Polska, the campaign marks a notable evolution in the tactics of the Ghostwriter-linked threat group, which has spent years targeting email users across Poland.

Also tracked as Ghostwriter and Storm-0257, UNC1151 has been linked by cybersecurity researchers to Belarusian state intelligence services and has remained active against Polish targets since Russia&#039;s full-scale invasion of Ukraine.
UNC1151 Gmail Phishing Campaign Expands Target Scope
For years, UNC1151 primarily targeted users of popular Polish email providers including Onetpasswords, Wirtualna Polska, and Interia. Since March 2026, however, the group has shifted its attention to Gmail users, launching high-volume phishing operations that run almost daily during weekdays.

CERT Polska researchers said the attackers target a wide range of individuals, including politicians, public officials, researchers, journalists, law enforcement personnel, government employees, and people connected to them through professional, family, or social relationships.

[caption id=&quot;attachment_112742&quot; align=&quot;aligncenter&quot; width=&quot;600&quot;] Image Source: CERT Polska[/caption]

The group also conducts campaigns against specific professional sectors and geographic regions. In some cases, phishing emails are sent to unintended recipients because attackers attempt to guess email addresses based on names and affiliations.
How the UNC1151 Gmail Phishing Campaign Works
The UNC1151 Gmail phishing campaign relies on fraudulent emails designed to resemble official Gmail security notifications. The messages often warn recipients about suspicious account activity, unauthorized login attempts, or alleged violations of service policies.

Victims are urged to act quickly to avoid account suspension or permanent deletion.

The emails are typically sent from Gmail accounts created specifically for phishing operations, although attackers occasionally use compromised accounts to increase credibility. Common subject lines include warnings about security alerts, suspicious activity, and account verification requirements.

Embedded links direct recipients to fake Gmail login pages that closely imitate Google&#039;s legitimate authentication portal. Once users enter their credentials, attackers capture both usernames and passwords.
2FA Credential Theft Marks Key Evolution
One of the most concerning developments in the campaign is its ability to harvest two-factor authentication theft credentials.

Unlike earlier phishing campaigns targeting Polish email services, the latest operation includes additional prompts requesting verification codes after login credentials have been entered. If a victim&#039;s account is protected by 2FA, the phishing page automatically displays a form requesting the authentication code.

This enables attackers to steal both SMS-based verification codes and codes generated through applications such as Google Authenticator.

Researchers noted that attackers frequently continue targeting the same victims even after unsuccessful login attempts. Multiple phishing emails may be delivered within days to increase pressure and improve the chances of credential theft.

[caption id=&quot;attachment_112735&quot; align=&quot;aligncenter&quot; width=&quot;600&quot;] Source: CERT Polska[/caption]
Ghostwriter Phishing Infrastructure Continues to Evolve
The campaign relies on a constantly changing phishing infrastructure.

According to CERT Polska, operators use domains registered specifically for phishing activities, often leveraging top-level domains such as .icu, .digital, and .top. The group also abuses hosting platforms such as Netlify by creating deceptive subdomains that imitate account verification services.

Examples of domains observed in the campaign include mailverify.digital, verify-check.digital, monitoring-google-konta.netlify.app, and service-auth.netlify.app.

In addition, attackers host fake login panels on compromised websites belonging to legitimate organizations. Rather than replacing the main website, the phishing content is hidden within the compromised infrastructure, allowing attacks to remain undetected for extended periods.
Gmail Phishing Attacks Signal Broader Threat
Security researchers warn that the increase in Gmail phishing attacks demonstrates UNC1151&#039;s continued ability to adapt its tactics while maintaining its long-standing objective of gaining access to email accounts.

Once access is obtained, attackers search for sensitive documents, contact lists, and linked services, including social media accounts that can be further compromised. Stolen contacts may also be used to identify additional targets for future phishing campaigns.

Although the group&#039;s recent focus has shifted toward Gmail, researchers caution that attacks against users of Polish email providers have not disappeared entirely.

The findings highlight the growing sophistication of state-linked phishing operations and reinforce the importance of scrutinizing login requests, verifying website domains, and protecting accounts with strong authentication practices.

As the UNC1151 Gmail phishing campaign continues to evolve, cybersecurity experts expect further adaptations designed to bypass defenses and increase the success rate of credential theft operations. ]]></description>
<link>https://tsecurity.de/de/3600994/IT+Sicherheit/Cybersecurity+Nachrichten/Belarus-Linked+UNC1151+Launches+Gmail+Phishing+Campaign+to+Steal+2FA+Codes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600994/IT+Sicherheit/Cybersecurity+Nachrichten/Belarus-Linked+UNC1151+Launches+Gmail+Phishing+Campaign+to+Steal+2FA+Codes/</guid>
<pubDate>Tue, 16 Jun 2026 09:38:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Anthropic models defended, FBI shuts down massive phishing service, 1Password acquires Apono]]></title> 
<description><![CDATA[Cyber leaders defend Anthropic&rsquo;s banned models FBI disrupts massive phishing service 1Password acquires Apono Get the show notes here: https://cisoseries.com/cybersecurity-news-anthropic-models-defended-massive-phishing-service-shuttered-1password-acquires-apono/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we&hellip;
Read more &rarr;
The post Anthropic models defended, FBI shuts down massive phishing service, 1Password acquires Apono appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3600951/IT+Sicherheit/Cybersecurity+Nachrichten/Anthropic+models+defended%2C+FBI+shuts+down+massive+phishing+service%2C+1Password+acquires+Apono/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600951/IT+Sicherheit/Cybersecurity+Nachrichten/Anthropic+models+defended%2C+FBI+shuts+down+massive+phishing+service%2C+1Password+acquires+Apono/</guid>
<pubDate>Tue, 16 Jun 2026 09:34:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns]]></title> 
<description><![CDATA[A wave of phishing campaigns targeting American taxpayers has been traced back to a single, highly organized cybercrime operation known as The Quarry. What appeared to be dozens of unrelated incidents impersonating the IRS, Social Security Administration, and platforms like&hellip;
Read more &rarr;
The post Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3600888/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Abuse+Legitimate+RMM+Tools+in+The+Quarry+IRS+and+SSA+Phishing+Campaigns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600888/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Abuse+Legitimate+RMM+Tools+in+The+Quarry+IRS+and+SSA+Phishing+Campaigns/</guid>
<pubDate>Tue, 16 Jun 2026 09:04:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns]]></title> 
<description><![CDATA[A wave of phishing campaigns targeting American taxpayers has been traced back to a single, highly organized cybercrime operation known as The Quarry. What appeared to be dozens of unrelated incidents impersonating the IRS, Social Security Administration, and platforms like DocuSign turned out to be the work of one developer selling a Phishing-as-a-Service (PhaaS) toolkit [&hellip;]
The post Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3600865/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Abuse+Legitimate+RMM+Tools+in+The+Quarry+IRS+and+SSA+Phishing+Campaigns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600865/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Abuse+Legitimate+RMM+Tools+in+The+Quarry+IRS+and+SSA+Phishing+Campaigns/</guid>
<pubDate>Tue, 16 Jun 2026 08:41:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cybercriminals Use The Quarry Toolkit to Launch IRS and SSA Phishing Attacks]]></title> 
<description><![CDATA[A sweeping wave of phishing attacks impersonating the IRS and Social Security Administration (SSA) has been traced to a sophisticated Phishing-as-a-Service (PhaaS) platform. Dubbed &ldquo;The Quarry,&rdquo; this operation equips nearly 200 cybercriminals with the tools needed to launch highly evasive campaigns. According to threat researchers at SOCRadar, this phishing ecosystem operates essentially as a managed [&hellip;]
The post Cybercriminals Use The Quarry Toolkit to Launch IRS and SSA Phishing Attacks appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3600825/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercriminals+Use+The+Quarry+Toolkit+to+Launch+IRS+and+SSA+Phishing+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600825/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercriminals+Use+The+Quarry+Toolkit+to+Launch+IRS+and+SSA+Phishing+Attacks/</guid>
<pubDate>Tue, 16 Jun 2026 08:23:17 +0200</pubDate>
</item>
<item> 
<title><![CDATA[EvilTokens: Neue Phishing-Kampagne verschafft sich Zugriff mit legitimen Mitteln]]></title> 
<description><![CDATA[Was passiert, wenn bei einem Phishing-Angriff offizielle Infrastruktur genutzt wird, anstatt diese zu f&auml;lschen? EvilTokens markiert eine Weiterentwicklung des Phishing: Es werden nicht mehr Anmeldedaten gestohlen, sondern die Opfer dazu verleitet, legitime Sitzungen zu autorisieren. ]]></description>
<link>https://tsecurity.de/de/3600740/IT+Sicherheit/Cybersecurity+Nachrichten/EvilTokens%3A+Neue+Phishing-Kampagne+verschafft+sich+Zugriff+mit+legitimen+Mitteln/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600740/IT+Sicherheit/Cybersecurity+Nachrichten/EvilTokens%3A+Neue+Phishing-Kampagne+verschafft+sich+Zugriff+mit+legitimen+Mitteln/</guid>
<pubDate>Mon, 15 Jun 2026 10:57:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Use The Quarry PhaaS Ecosystem to Target U.S. Victims With IRS Phishing]]></title> 
<description><![CDATA[A single developer-known online as RockyBelling has assembled a highly modular PhaaS/MaaS ecosystem that affiliates worldwide use to launch highly targeted IRS and SSA-themed phishing campaigns that predominantly hit U.S. victims. SOCRadar research spanning April 2025&ndash;April 2026 ties almost 200&hellip;
Read more &rarr;
The post Hackers Use The Quarry PhaaS Ecosystem to Target U.S. Victims With IRS Phishing appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3600733/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Use+The+Quarry+PhaaS+Ecosystem+to+Target+U.S.+Victims+With+IRS+Phishing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600733/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Use+The+Quarry+PhaaS+Ecosystem+to+Target+U.S.+Victims+With+IRS+Phishing/</guid>
<pubDate>Tue, 16 Jun 2026 07:34:35 +0200</pubDate>
</item>
<item> 
<title><![CDATA[EvilTokens: A phishing attack that doesn’t steal your password]]></title> 
<description><![CDATA[A phishing kit subverting Microsoft&rsquo;s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages ]]></description>
<link>https://tsecurity.de/de/3600695/IT+Sicherheit/Cybersecurity+Nachrichten/EvilTokens%3A+A+phishing+attack+that+doesn%E2%80%99t+steal+your+password/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600695/IT+Sicherheit/Cybersecurity+Nachrichten/EvilTokens%3A+A+phishing+attack+that+doesn%E2%80%99t+steal+your+password/</guid>
<pubDate>Mon, 15 Jun 2026 10:55:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Use The Quarry PhaaS Ecosystem to Target U.S. Victims With IRS Phishing]]></title> 
<description><![CDATA[A single developer-known online as RockyBelling has assembled a highly modular PhaaS/MaaS ecosystem that affiliates worldwide use to launch highly targeted IRS and SSA-themed phishing campaigns that predominantly hit U.S. victims. SOCRadar research spanning April 2025&ndash;April 2026 ties almost 200 affiliates to a commercial toolkit that combines sophisticated cloaking, flexible payload options, real-time victim telemetry [&hellip;]
The post Hackers Use The Quarry PhaaS Ecosystem to Target U.S. Victims With IRS Phishing appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3600688/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Use+The+Quarry+PhaaS+Ecosystem+to+Target+U.S.+Victims+With+IRS+Phishing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600688/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Use+The+Quarry+PhaaS+Ecosystem+to+Target+U.S.+Victims+With+IRS+Phishing/</guid>
<pubDate>Tue, 16 Jun 2026 07:11:36 +0200</pubDate>
</item>
<item> 
<title><![CDATA[EvilTokens: A phishing attack that doesn’t steal your password]]></title> 
<description><![CDATA[A phishing kit subverting Microsoft&rsquo;s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages This article has been indexed from WeLiveSecurity Read the original article: EvilTokens: A phishing attack that doesn&rsquo;t steal your&hellip;
Read more &rarr;
The post EvilTokens: A phishing attack that doesn&rsquo;t steal your password appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3600686/IT+Sicherheit/Cybersecurity+Nachrichten/EvilTokens%3A+A+phishing+attack+that+doesn%E2%80%99t+steal+your+password/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600686/IT+Sicherheit/Cybersecurity+Nachrichten/EvilTokens%3A+A+phishing+attack+that+doesn%E2%80%99t+steal+your+password/</guid>
<pubDate>Tue, 16 Jun 2026 07:12:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Falcon Secure Access: Phishing Protection Inside the Browser]]></title> 
<description><![CDATA[Author: CrowdStrike - Bewertung: 0x - Views:4 Phishing attacks increasingly rely on highly convincing login experiences designed to mimic trusted services. Watch how Falcon Secure Access detects sophisticated phishing attempts directly inside the browser, prevents sensitive data from being exposed, and protects users in real time.

🛡️ Falcon Secure Access
Learn more here: https://cs.link/uo7HJ

📣 Connect With Us:
► LinkedIn:
https://www.linkedin.com/company/crowdstrike
► X:
https://x.com/CrowdStrike
► Facebook:
https://www.facebook.com/CrowdStrike
► Instagram:
https://www.instagram.com/crowdstrike

🔔 Subscribe and stay updated!
#CrowdStrike #Cybersecurity ]]></description>
<link>https://tsecurity.de/de/3600450/IT+Sicherheit/Cybersecurity+Videos/Falcon+Secure+Access%3A+Phishing+Protection+Inside+the+Browser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600450/IT+Sicherheit/Cybersecurity+Videos/Falcon+Secure+Access%3A+Phishing+Protection+Inside+the+Browser/</guid>
<pubDate>Tue, 16 Jun 2026 02:32:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing: Betrüger geben sich als Verbraucherschützer aus - Handelsblatt]]></title> 
<description><![CDATA[Wer ist hier die echte Verbraucherzentrale?&ldquo;, fragt man sich bei dieser Warnung der Verbraucherzentrale vor einer neuen Betrugsmasche. ]]></description>
<link>https://tsecurity.de/de/3600253/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing%3A+Betr%C3%BCger+geben+sich+als+Verbrauchersch%C3%BCtzer+aus+-+Handelsblatt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600253/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing%3A+Betr%C3%BCger+geben+sich+als+Verbrauchersch%C3%BCtzer+aus+-+Handelsblatt/</guid>
<pubDate>Mon, 15 Jun 2026 22:20:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Inside a malicious infrastructure delivering EtherRAT, phishing pages, and malicious software ]]></title> 
<description><![CDATA[We found&nbsp;EtherRAT&nbsp;malware being distributed by a website with a strange homepage.&nbsp;Following the trail, we discovered a vast network of malicious infrastructures, distributing malware,&nbsp;malicious documents,&nbsp;remote desktop&nbsp;software,&nbsp;and phishing pages.&nbsp; ]]></description>
<link>https://tsecurity.de/de/3600180/IT+Sicherheit/Cybersecurity+Nachrichten/Inside+a%C2%A0malicious+infrastructure+delivering%C2%A0EtherRAT%2C%C2%A0phishing+pages%2C%C2%A0and+malicious+software%C2%A0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600180/IT+Sicherheit/Cybersecurity+Nachrichten/Inside+a%C2%A0malicious+infrastructure+delivering%C2%A0EtherRAT%2C%C2%A0phishing+pages%2C%C2%A0and+malicious+software%C2%A0/</guid>
<pubDate>Mon, 15 Jun 2026 22:17:46 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Inside a malicious infrastructure delivering EtherRAT, phishing pages, and malicious software]]></title> 
<description><![CDATA[We found&nbsp;EtherRAT&nbsp;malware being distributed by a website with a strange homepage.&nbsp;Following the trail, we discovered a vast network of malicious infrastructures, distributing malware,&nbsp;malicious documents,&nbsp;remote desktop&nbsp;software,&nbsp;and phishing pages. This article has been indexed from Malwarebytes Read the original article: Inside a&nbsp;malicious&hellip;
Read more &rarr;
The post Inside a&nbsp;malicious infrastructure delivering&nbsp;EtherRAT,&nbsp;phishing pages,&nbsp;and malicious software appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3600178/IT+Sicherheit/Cybersecurity+Nachrichten/Inside+a%C2%A0malicious+infrastructure+delivering%C2%A0EtherRAT%2C%C2%A0phishing+pages%2C%C2%A0and+malicious+software/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600178/IT+Sicherheit/Cybersecurity+Nachrichten/Inside+a%C2%A0malicious+infrastructure+delivering%C2%A0EtherRAT%2C%C2%A0phishing+pages%2C%C2%A0and+malicious+software/</guid>
<pubDate>Mon, 15 Jun 2026 22:34:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hacker-Operation Riptide: FBI zerschlägt KI-Phishing-Netzwerk mit 1,7 Mrd. Schaden]]></title> 
<description><![CDATA[Das FBI warnt vor der Plattform Kali365, einem abonnementbasierten Hacking-Dienst, der seit April 2026 aktiv ist. Die Angreifer umgehen die MFA&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3599645/IT+Sicherheit/Hacker/Hacker-Operation+Riptide%3A+FBI+zerschl%C3%A4gt+KI-Phishing-Netzwerk+mit+1%2C7+Mrd.+Schaden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599645/IT+Sicherheit/Hacker/Hacker-Operation+Riptide%3A+FBI+zerschl%C3%A4gt+KI-Phishing-Netzwerk+mit+1%2C7+Mrd.+Schaden/</guid>
<pubDate>Mon, 15 Jun 2026 17:12:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hacker-Operation Riptide: FBI zerschlägt KI-Phishing-Netzwerk mit 1,7 Mrd. Schaden]]></title> 
<description><![CDATA[Hacker nutzen KI f&uuml;r Phishing-Kampagnen gegen Personalabteilungen und Beh&ouml;rden. FBI zerschl&auml;gt Netzwerk mit Milliarden-Schaden. ]]></description>
<link>https://tsecurity.de/de/3599552/IT+Sicherheit/Hacker/Hacker-Operation+Riptide%3A+FBI+zerschl%C3%A4gt+KI-Phishing-Netzwerk+mit+1%2C7+Mrd.+Schaden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599552/IT+Sicherheit/Hacker/Hacker-Operation+Riptide%3A+FBI+zerschl%C3%A4gt+KI-Phishing-Netzwerk+mit+1%2C7+Mrd.+Schaden/</guid>
<pubDate>Mon, 15 Jun 2026 17:12:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Google Lawsuit: China-Based Scammers Used Gemini to Scale Phishing]]></title> 
<description><![CDATA[Google sued Outsider Enterprise, alleging the China-based phishing network used Gemini and other AI tools to scale scam texts and fake sites. ]]></description>
<link>https://tsecurity.de/de/3599509/IT+Nachrichten/Google+Lawsuit%3A+China-Based+Scammers+Used+Gemini+to+Scale+Phishing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599509/IT+Nachrichten/Google+Lawsuit%3A+China-Based+Scammers+Used+Gemini+to+Scale+Phishing/</guid>
<pubDate>Mon, 15 Jun 2026 18:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years. Here’s What Cyber Criminals Are Actually Doing]]></title> 
<description><![CDATA[Every summer, hundreds of millions of people book flights, reserve hotels, and plan vacations online. And every summer, cyber criminals show up to take advantage of exactly that. Check Point Research tracked the threat landscape heading into the 2026 summer&hellip;
Read more &rarr;
The post Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years. Here&rsquo;s What Cyber Criminals Are Actually Doing appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3599255/IT+Sicherheit/Cybersecurity+Nachrichten/Travel+Phishing+and+Cyber+Attacks+are+Surging+in+2026%2C+Growing+122%25+over+the+last+3+years.+Here%E2%80%99s+What+Cyber+Criminals+Are+Actually+Doing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599255/IT+Sicherheit/Cybersecurity+Nachrichten/Travel+Phishing+and+Cyber+Attacks+are+Surging+in+2026%2C+Growing+122%25+over+the+last+3+years.+Here%E2%80%99s+What+Cyber+Criminals+Are+Actually+Doing/</guid>
<pubDate>Mon, 15 Jun 2026 15:07:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years. Here’s What Cyber Criminals Are Actually Doing]]></title> 
<description><![CDATA[Every summer, hundreds of millions of people book flights, reserve hotels, and plan vacations online. And every summer, cyber criminals show up to take advantage of exactly that. Check Point Research tracked the threat landscape heading into the 2026 summer travel season, and what they found should give travelers pause before they click &ldquo;confirm booking.&rdquo;&nbsp; The hospitality sector is under targeted attack&nbsp; The hospitality, travel, and recreation sector recorded 2,291 average weekly cyberattacks per organization in May 2026, a 24% increase compared to the same month last year. To put that in context, the global year-over-year rise across all industries [&hellip;]
The post Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years. Here&rsquo;s What Cyber Criminals Are Actually Doing appeared first on Check Point Blog. ]]></description>
<link>https://tsecurity.de/de/3599202/IT+Sicherheit/Cybersecurity+Nachrichten/Travel+Phishing+and+Cyber+Attacks+are+Surging+in+2026%2C+Growing+122%25+over+the+last+3+years.+Here%E2%80%99s+What+Cyber+Criminals+Are+Actually+Doing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599202/IT+Sicherheit/Cybersecurity+Nachrichten/Travel+Phishing+and+Cyber+Attacks+are+Surging+in+2026%2C+Growing+122%25+over+the+last+3+years.+Here%E2%80%99s+What+Cyber+Criminals+Are+Actually+Doing/</guid>
<pubDate>Mon, 15 Jun 2026 15:00:46 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Webinar: How behavioral AI stops phishing and account takeovers]]></title> 
<description><![CDATA[Modern phishing, BEC, and account takeover attacks increasingly bypass traditional email defenses and create operational strain for security teams. This webinar explores how behavioral AI can help automate detection, investigation, and remediation to reduce alert fatigue and accelerate response times. [...] ]]></description>
<link>https://tsecurity.de/de/3599156/IT+Sicherheit/Cybersecurity+Nachrichten/Webinar%3A+How+behavioral+AI+stops+phishing+and+account+takeovers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599156/IT+Sicherheit/Cybersecurity+Nachrichten/Webinar%3A+How+behavioral+AI+stops+phishing+and+account+takeovers/</guid>
<pubDate>Mon, 15 Jun 2026 14:12:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FBI takes out huge AI-powered phishing service: Outsider Enterprise was using over a million phishing URLs to steal credit card data and passwords]]></title> 
<description><![CDATA[Servers, Telegram bots, and money, all seized by the authorities. ]]></description>
<link>https://tsecurity.de/de/3599094/IT+Nachrichten/FBI+takes+out+huge+AI-powered+phishing+service%3A+Outsider+Enterprise+was+using+over+a+million+phishing+URLs+to+steal+credit+card+data+and+passwords/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599094/IT+Nachrichten/FBI+takes+out+huge+AI-powered+phishing+service%3A+Outsider+Enterprise+was+using+over+a+million+phishing+URLs+to+steal+credit+card+data+and+passwords/</guid>
<pubDate>Mon, 15 Jun 2026 14:25:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[PhishLumos: Exposing phishing campaigns that evade detection by hiding content]]></title> 
<description><![CDATA[Phishing remains one of the most stubbornly persistent threats in cybersecurity: humans are tired, distracted, trusting, and susceptible to urgency and authority in ways that no amount of awareness training can completely overcome. The security community has largely accepted this reality and shifted focus toward automated detection systems that can intercept and block phishing threats before users see them. But attackers have adapted here, too. Modern phishing campaigns increasingly employ cloaking techniques, serving benign content &hellip; More &rarr;
The post PhishLumos: Exposing phishing campaigns that evade detection by hiding content appeared first on Help Net Security. ]]></description>
<link>https://tsecurity.de/de/3598848/IT+Sicherheit/Cybersecurity+Nachrichten/PhishLumos%3A+Exposing+phishing+campaigns+that+evade+detection+by+hiding+content/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598848/IT+Sicherheit/Cybersecurity+Nachrichten/PhishLumos%3A+Exposing+phishing+campaigns+that+evade+detection+by+hiding+content/</guid>
<pubDate>Mon, 15 Jun 2026 12:52:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[PhishLumos: Exposing phishing campaigns that evade detection by hiding content]]></title> 
<description><![CDATA[Phishing remains one of the most stubbornly persistent threats in cybersecurity: humans are tired, distracted, trusting, and susceptible to urgency and authority in ways that no amount of awareness training can completely overcome. The security community has largely accepted this&hellip;
Read more &rarr;
The post PhishLumos: Exposing phishing campaigns that evade detection by hiding content appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3598845/IT+Sicherheit/Cybersecurity+Nachrichten/PhishLumos%3A+Exposing+phishing+campaigns+that+evade+detection+by+hiding+content/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598845/IT+Sicherheit/Cybersecurity+Nachrichten/PhishLumos%3A+Exposing+phishing+campaigns+that+evade+detection+by+hiding+content/</guid>
<pubDate>Mon, 15 Jun 2026 13:04:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service]]></title> 
<description><![CDATA[The platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses. The post FBI, Google Dismantle &lsquo;Outsider Enterprise&rsquo; Phishing Service appeared first on SecurityWeek. This article has been indexed from&hellip;
Read more &rarr;
The post FBI, Google Dismantle &lsquo;Outsider Enterprise&rsquo; Phishing Service appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3598751/IT+Sicherheit/Cybersecurity+Nachrichten/FBI%2C+Google+Dismantle+%E2%80%98Outsider+Enterprise%E2%80%99+Phishing+Service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598751/IT+Sicherheit/Cybersecurity+Nachrichten/FBI%2C+Google+Dismantle+%E2%80%98Outsider+Enterprise%E2%80%99+Phishing+Service/</guid>
<pubDate>Mon, 15 Jun 2026 12:06:46 +0200</pubDate>
</item>
<item> 
<title><![CDATA[SearchJack Adware Campaign Exposes 758,000 Users to Privacy and Phishing Risks]]></title> 
<description><![CDATA[A coordinated campaign of 23 seemingly legitimate Chrome extensions tracked as &ldquo;SearchJack&rdquo; has quietly hijacked the default search settings of roughly 758,000 users, routing queries through operator-controlled monetization middleware before returning results. At first glance the extensions promise useful features&hellip;
Read more &rarr;
The post SearchJack Adware Campaign Exposes 758,000 Users to Privacy and Phishing Risks appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3598750/IT+Sicherheit/Cybersecurity+Nachrichten/SearchJack+Adware+Campaign+Exposes+758%2C000+Users+to+Privacy+and+Phishing+Risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598750/IT+Sicherheit/Cybersecurity+Nachrichten/SearchJack+Adware+Campaign+Exposes+758%2C000+Users+to+Privacy+and+Phishing+Risks/</guid>
<pubDate>Mon, 15 Jun 2026 12:06:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[SearchJack Adware Campaign Exposes 758,000 Users to Privacy and Phishing Risks]]></title> 
<description><![CDATA[A coordinated campaign of 23 seemingly legitimate Chrome extensions tracked as &ldquo;SearchJack&rdquo; has quietly hijacked the default search settings of roughly 758,000 users, routing queries through operator-controlled monetization middleware before returning results. At first glance the extensions promise useful features satellite imagery, productivity tools, news readers, maps but their true purpose is affiliate search monetization, [&hellip;]
The post SearchJack Adware Campaign Exposes 758,000 Users to Privacy and Phishing Risks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3598680/IT+Sicherheit/Cybersecurity+Nachrichten/SearchJack+Adware+Campaign+Exposes+758%2C000+Users+to+Privacy+and+Phishing+Risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598680/IT+Sicherheit/Cybersecurity+Nachrichten/SearchJack+Adware+Campaign+Exposes+758%2C000+Users+to+Privacy+and+Phishing+Risks/</guid>
<pubDate>Mon, 15 Jun 2026 11:40:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service]]></title> 
<description><![CDATA[The platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses.
The post FBI, Google Dismantle &lsquo;Outsider Enterprise&rsquo; Phishing Service appeared first on SecurityWeek. ]]></description>
<link>https://tsecurity.de/de/3598644/IT+Sicherheit/Cybersecurity+Nachrichten/FBI%2C+Google+Dismantle+%E2%80%98Outsider+Enterprise%E2%80%99+Phishing+Service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598644/IT+Sicherheit/Cybersecurity+Nachrichten/FBI%2C+Google+Dismantle+%E2%80%98Outsider+Enterprise%E2%80%99+Phishing+Service/</guid>
<pubDate>Mon, 15 Jun 2026 11:31:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cybersicherheit: 3,8 Millionen Kreditkarten in Phishing-Operation gestohlen]]></title> 
<description><![CDATA[Der Trojaner NarwahlRAT bedroht KakaoTalk-Nutzer. Neue NarwahlRAT-Kampagne: Nordkoreanische Hacker zielen auf S&uuml;dkorea. Cybersicherheit - A stylized,&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3598497/IT+Sicherheit/Cybersecurity+Nachrichten/Cybersicherheit%3A+3%2C8+Millionen+Kreditkarten+in+Phishing-Operation+gestohlen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598497/IT+Sicherheit/Cybersecurity+Nachrichten/Cybersicherheit%3A+3%2C8+Millionen+Kreditkarten+in+Phishing-Operation+gestohlen/</guid>
<pubDate>Mon, 15 Jun 2026 09:11:23 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cybersecurity-Krise: FBI zerschlägt Phishing-Plattform mit 1,9 Mrd. Schaden - BornCity]]></title> 
<description><![CDATA[Hacker nutzen Sicherheitsl&uuml;cke in Oracle PeopleSoft f&uuml;r Angriffe auf &uuml;ber 100 Einrichtungen. Besonders Hochschulen sind betroffen. ]]></description>
<link>https://tsecurity.de/de/3598476/IT+Sicherheit/Hacker/Cybersecurity-Krise%3A+FBI+zerschl%C3%A4gt+Phishing-Plattform+mit+1%2C9+Mrd.+Schaden+-+BornCity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598476/IT+Sicherheit/Hacker/Cybersecurity-Krise%3A+FBI+zerschl%C3%A4gt+Phishing-Plattform+mit+1%2C9+Mrd.+Schaden+-+BornCity/</guid>
<pubDate>Mon, 15 Jun 2026 09:36:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Google Sues Operators of AI-Powered ‘Outsider’ Phishing Kit Linked to 1.5 Million URLs]]></title> 
<description><![CDATA[Google has launched a lawsuit against the operators behind the Outsider AI phishing kit. This alleged AI phishing kit, the company says, has been used to create convincing phishing websites using artificial intelligence tools, including Google&#039;s Gemini. &nbsp;

The legal action, filed by Alphabet-owned Google in a federal court in Manhattan, targets the developers of the&nbsp;Outsider&nbsp;phishing platform. According to the complaint, the software enables users to replicate hundreds of trusted websites and&nbsp;provides&nbsp;detailed guidance on generating phishing pages designed to steal personal and financial information.&nbsp;&nbsp;

Google alleges that the&nbsp;AI phishing kit&nbsp;leverages&nbsp;AI capabilities, including Gemini, to make fraudulent websites more sophisticated and harder to&nbsp;identify.&nbsp;
Google Alleges the Outsider AI Phishing Kit Enabled AI-Powered Cybercrime&nbsp;
In its lawsuit, Google claims that the operation of the Outsider AI phishing kit has facilitated large-scale cybercrime by giving bad actors access to tools that simplify the creation of phishing campaigns. The company alleges that the&nbsp;AI phishing kit&nbsp;can imitate legitimate websites while offering step-by-step instructions that help users generate convincing phishing pages through AI-assisted processes.&nbsp;

The lawsuit places particular emphasis on alleged&nbsp;Gemini misuse, arguing that Google&#039;s AI tools were exploited to support phishing activities.&nbsp;According to Google, the developers behind&nbsp;Outsider&nbsp;used AI technologies in ways that violate the company&#039;s policies and contribute to online fraud.&nbsp;

Google also alleges that the individuals responsible for the Outsider AI phishing kit are anonymous cybercriminals based in China. The company claims these actors abused services such as Google Cloud and Google Drive while also misusing Google&#039;s trademarks to create a false sense of legitimacy around their operations.&nbsp;
More Than 1.5&nbsp;Million&nbsp;URLs Linked to the AI Phishing Kit&nbsp;
The scale of the alleged operation is one of the most significant aspects of the lawsuit. Google reported that it&nbsp;identified&nbsp;more than 1.5 million URLs associated with the&nbsp;Outsider AI phishing kit&nbsp;between November and April.&nbsp;

The large number of detected URLs suggests that the phishing infrastructure was extensive and capable of reaching a substantial number of potential victims. Google&#039;s findings highlight how rapidly phishing operations can expand when aided by automation and AI-driven tools.&nbsp;

As concerns about&nbsp;Gemini misuse&nbsp;and AI-enabled cybercrime continue to grow, security experts have warned that phishing attacks are becoming increasingly difficult for users to distinguish from legitimate communications.&nbsp;
Google Partners With FBI and Telecom Providers&nbsp;
Google says it is taking a coordinated approach to disrupt the&nbsp;Outsider&nbsp;network. In a blog post, Google General Counsel&nbsp;Halimah&nbsp;DeLaine&nbsp;Prado&nbsp;stated&nbsp;that the company is working alongside the&nbsp;Federal Bureau of Investigation (FBI)&nbsp;as well as major telecommunications companies including&nbsp;AT&amp;T,&nbsp;T-Mobile, and&nbsp;Verizon.&nbsp;

According to&nbsp;DeLaine&nbsp;Prado, the collaboration aims to dismantle the infrastructure supporting the&nbsp;Outsider AI phishing kit. The effort combines legal action, industry cooperation, and technical measures to address what Google views as an evolving cybersecurity threat.&nbsp;

The partnership reflects a broader trend within the technology and telecommunications sectors, where organizations are joining forces to combat sophisticated phishing operations and online fraud schemes.&nbsp;
Rising Concerns Over Gemini Misuse and AI-Driven Scams&nbsp;
The lawsuit also draws attention to wider concerns across the cybersecurity industry about the misuse of artificial intelligence. Experts have warned that AI tools can help criminals create more persuasive messages, realistic websites, and effective social engineering campaigns.&nbsp;

Commenting on the issue,&nbsp;Brett Leatherman, Assistant Director of the FBI&#039;s Cyber Division, said that criminals are increasingly turning to AI to make fraudulent activity more convincing and more difficult to detect.&nbsp;

Leatherman emphasized the importance of public-private partnerships in disrupting cybercriminal operations, pointing to collaborations such as the one between Google and the FBI as a key&nbsp;component&nbsp;in combating modern digital threats.&nbsp;

The allegations surrounding&nbsp;Gemini misuse&nbsp;serve as another example of how AI technologies, while beneficial in many legitimate applications, can also be exploited by malicious actors&nbsp;seeking&nbsp;to improve the effectiveness of phishing attacks.&nbsp;
Legislative Efforts to Combat AI-Powered Fraud&nbsp;
Beyond its lawsuit against&nbsp;Outsider, Google is also&nbsp;advocating for&nbsp;policy measures aimed at reducing online&nbsp;scams.&nbsp;DeLaine&nbsp;Prado noted that the company supports seven bills currently pending in the U.S. Congress that are intended to address scamming activities.&nbsp;

Google&#039;s backing of the proposed legislation signals a broader effort to combine legal, technological, and policy-based responses to the rise of AI-enabled cybercrime. The company argues that tackling threats such as the&nbsp;Outsider AI phishing kit&nbsp;requires cooperation across government agencies, technology providers, law enforcement organizations, and lawmakers.&nbsp;

As AI tools continue to evolve, the lawsuit against Outsider highlights the growing challenge facing the cybersecurity sector. The case not only focuses on the alleged abuse of Google&#039;s services and trademarks but also raises larger questions about preventing Gemini misuse and limiting the role of AI in sophisticated phishing campaigns.&nbsp; ]]></description>
<link>https://tsecurity.de/de/3598473/IT+Sicherheit/Cybersecurity+Nachrichten/Google+Sues+Operators+of+AI-Powered+%E2%80%98Outsider%E2%80%99+Phishing+Kit+Linked+to+1.5+Million+URLs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598473/IT+Sicherheit/Cybersecurity+Nachrichten/Google+Sues+Operators+of+AI-Powered+%E2%80%98Outsider%E2%80%99+Phishing+Kit+Linked+to+1.5+Million+URLs/</guid>
<pubDate>Mon, 15 Jun 2026 10:12:25 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Interpol zerschlägt Phishing-Plattform Sniper Dz]]></title> 
<description><![CDATA[
    Interpol hat die Phishing-Plattform Sniper Dz abgeschaltet und 201 Verd&auml;chtige verhaftet. Die Gruppe erbeutete Daten von zehntausenden Opfern.

Tags: #Cyber Crime | #Interpol | #Phishing ]]></description>
<link>https://tsecurity.de/de/3598381/IT+Sicherheit/Cybersecurity+Nachrichten/Interpol+zerschl%C3%A4gt+Phishing-Plattform+Sniper+Dz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598381/IT+Sicherheit/Cybersecurity+Nachrichten/Interpol+zerschl%C3%A4gt+Phishing-Plattform+Sniper+Dz/</guid>
<pubDate>Mon, 15 Jun 2026 09:18:59 +0200</pubDate>
</item>
<item> 
<title><![CDATA[APT37 Hackers Use NarwhalRAT Malware With MS-Themed Phishing and Dead-Drop C2]]></title> 
<description><![CDATA[APT37 is using NarwhalRAT in a tightly engineered intrusion chain that starts with Microsoft-themed spear-phishing, pivots through malicious LNK files and PowerShell, and ends with a Python-based backdoor with dead-drop C2 via pCloud. The campaign is notable for its layered&hellip;
Read more &rarr;
The post APT37 Hackers Use NarwhalRAT Malware With MS-Themed Phishing and Dead-Drop C2 appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3598210/IT+Sicherheit/Cybersecurity+Nachrichten/APT37+Hackers+Use+NarwhalRAT+Malware+With+MS-Themed+Phishing+and+Dead-Drop+C2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598210/IT+Sicherheit/Cybersecurity+Nachrichten/APT37+Hackers+Use+NarwhalRAT+Malware+With+MS-Themed+Phishing+and+Dead-Drop+C2/</guid>
<pubDate>Mon, 15 Jun 2026 08:09:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[APT37 Hackers Use NarwhalRAT Malware With MS-Themed Phishing and Dead-Drop C2]]></title> 
<description><![CDATA[APT37 is using NarwhalRAT in a tightly engineered intrusion chain that starts with Microsoft-themed spear-phishing, pivots through malicious LNK files and PowerShell, and ends with a Python-based backdoor with dead-drop C2 via pCloud. The campaign is notable for its layered tradecraft: social engineering, LOLBin abuse, scheduled-task persistence, in-memory execution, and selective data theft are all [&hellip;]
The post APT37 Hackers Use NarwhalRAT Malware With MS-Themed Phishing and Dead-Drop C2 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3598167/IT+Sicherheit/Cybersecurity+Nachrichten/APT37+Hackers+Use+NarwhalRAT+Malware+With+MS-Themed+Phishing+and+Dead-Drop+C2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598167/IT+Sicherheit/Cybersecurity+Nachrichten/APT37+Hackers+Use+NarwhalRAT+Malware+With+MS-Themed+Phishing+and+Dead-Drop+C2/</guid>
<pubDate>Mon, 15 Jun 2026 07:55:26 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Warum Phishing ein Risiko bleibt: Nur jeder Sechste erkennt betrügerische E-Mails sicher]]></title> 
<description><![CDATA[W&auml;hrend sich viele Besch&auml;ftigte in Deutschland gut gegen Social Engineering gewappnet sehen, fehlt es ihnen im Ernstfall an entscheidender Handlungssicherheit. Das offenbart die aktuelle Studie &bdquo;Cybersicherheit in Zahlen&ldquo; von G DATA CyberDefense, Statista und brand eins. So sagen zwei Drittel der Befragten, dass sie gut oder sehr gut auf Social Engineering-Angriffe vorbereitet sind. Aber nur 17 Prozent sind &uuml;berzeugt, gef&auml;hrliche E-Mails zu erkennen.&nbsp;&nbsp; ]]></description>
<link>https://tsecurity.de/de/3598145/IT+Sicherheit/Cybersecurity+Nachrichten/Warum+Phishing+ein+Risiko+bleibt%3A+Nur+jeder+Sechste+erkennt+betr%C3%BCgerische+E-Mails+sicher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598145/IT+Sicherheit/Cybersecurity+Nachrichten/Warum+Phishing+ein+Risiko+bleibt%3A+Nur+jeder+Sechste+erkennt+betr%C3%BCgerische+E-Mails+sicher/</guid>
<pubDate>Thu, 07 May 2026 10:05:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[UNK_DeadDrop-Phishingkampagne zielt auf Entwickler ab]]></title> 
<description><![CDATA[
    Cyberkriminelle setzen zunehmend auf raffinierte Methoden, um gezielt Softwareentwickler anzugreifen. Sicherheitsforscher von Proofpoint haben eine Kampagne analysiert, bei der vermeintliche Stellenangebote, Code-Reviews und technische Testaufgaben als K&ouml;der dienen. 

Tags: #Kryptow&auml;hrung | #Phishing ]]></description>
<link>https://tsecurity.de/de/3598096/IT+Sicherheit/Cybersecurity+Nachrichten/UNK_DeadDrop-Phishingkampagne+zielt+auf+Entwickler+ab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598096/IT+Sicherheit/Cybersecurity+Nachrichten/UNK_DeadDrop-Phishingkampagne+zielt+auf+Entwickler+ab/</guid>
<pubDate>Mon, 15 Jun 2026 07:20:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Anthropic Models Blocked, FBI Takes Down $1.9B Phishing Network, Critical Splunk Flaw, and more]]></title> 
<description><![CDATA[The U.S. government orders Anthropic to shut down foreign access to its Fable 5 and Mythos 5 AI models after the Pentagon labels the company a supply-chain risk. David Shipley examines what may be &nbsp;behind the decision and what it&hellip;
Read more &rarr;
The post Anthropic Models Blocked, FBI Takes Down $1.9B Phishing Network, Critical Splunk Flaw, and more appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3598094/IT+Sicherheit/Cybersecurity+Nachrichten/Anthropic+Models+Blocked%2C+FBI+Takes+Down+%241.9B+Phishing+Network%2C+Critical+Splunk+Flaw%2C+and+more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598094/IT+Sicherheit/Cybersecurity+Nachrichten/Anthropic+Models+Blocked%2C+FBI+Takes+Down+%241.9B+Phishing+Network%2C+Critical+Splunk+Flaw%2C+and+more/</guid>
<pubDate>Mon, 15 Jun 2026 07:34:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Über eine Million URLs stillgelegt: FBI zerschlägt riesigen KI-gestützten Phishing-Dienst]]></title> 
<description><![CDATA[Die Zerschlagung erfolgte im Rahmen der FBI-Operation &bdquo;Riptide&ldquo;, die auf die Bek&auml;mpfung gro&szlig;er Cybercrime-Infrastrukturen abzielt. Dabei&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3597669/IT+Sicherheit/Cybersecurity+Nachrichten/%C3%9Cber+eine+Million+URLs+stillgelegt%3A+FBI+zerschl%C3%A4gt+riesigen+KI-gest%C3%BCtzten+Phishing-Dienst/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597669/IT+Sicherheit/Cybersecurity+Nachrichten/%C3%9Cber+eine+Million+URLs+stillgelegt%3A+FBI+zerschl%C3%A4gt+riesigen+KI-gest%C3%BCtzten+Phishing-Dienst/</guid>
<pubDate>Sun, 14 Jun 2026 21:39:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cyberkriminalität: FBI zerschlägt KI-Phishing-Netzwerk mit 1,7 Mrd. Schaden]]></title> 
<description><![CDATA[... cybercrime. 14.06.2026 - Bild: &uuml;ber boerse-global.de. Die US-Bundespolizei hat gemeinsam mit Google und Sicherheitsexperten ein chinesisches&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3597530/IT+Sicherheit/Cybersecurity+Nachrichten/Cyberkriminalit%C3%A4t%3A+FBI+zerschl%C3%A4gt+KI-Phishing-Netzwerk+mit+1%2C7+Mrd.+Schaden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597530/IT+Sicherheit/Cybersecurity+Nachrichten/Cyberkriminalit%C3%A4t%3A+FBI+zerschl%C3%A4gt+KI-Phishing-Netzwerk+mit+1%2C7+Mrd.+Schaden/</guid>
<pubDate>Sun, 14 Jun 2026 20:33:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Über eine Million URLs stillgelegt: FBI zerschlägt riesigen KI-gestützten Phishing-Dienst]]></title> 
<description><![CDATA[Dem FBI ist gemeinsam mit Google, dem Sicherheitsunternehmen Black Lotus Labs und anderen Beteiligten ein bedeutender Schlag gegen eine der gr&ouml;&szlig;ten bekannten Phishing-as-a-Service-Plattformen gelungen. Die Beh&ouml;rden nahmen dabei tausende Phishing-Websites und mehr als eine Million f&uuml;r die Angriffe genutzte URLs vom Netz. ]]></description>
<link>https://tsecurity.de/de/3597508/IT+Nachrichten/%C3%9Cber+eine+Million+URLs+stillgelegt%3A+FBI+zerschl%C3%A4gt+riesigen+KI-gest%C3%BCtzten+Phishing-Dienst/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597508/IT+Nachrichten/%C3%9Cber+eine+Million+URLs+stillgelegt%3A+FBI+zerschl%C3%A4gt+riesigen+KI-gest%C3%BCtzten+Phishing-Dienst/</guid>
<pubDate>Sun, 14 Jun 2026 20:55:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing, Fakeshops und Schadsoftware: Online-Betrug rund um die Fußball-WM - Berliner Zeitung]]></title> 
<description><![CDATA[... Cybercrime. Phishing, Fakeshops und Schadsoftware: Online-Betrug rund ... Cybercrime. Dobrindt warnt: Deutschland geh&ouml;rt zu den weltweiten Top&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3597412/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing%2C+Fakeshops+und+Schadsoftware%3A+Online-Betrug+rund+um+die+Fu%C3%9Fball-WM+-+Berliner+Zeitung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597412/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing%2C+Fakeshops+und+Schadsoftware%3A+Online-Betrug+rund+um+die+Fu%C3%9Fball-WM+-+Berliner+Zeitung/</guid>
<pubDate>Sun, 14 Jun 2026 14:59:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Chinesische PhaaS-Plattformen professionalisieren Phishing-Angriffe mit KI und Echtzeit-Tools]]></title> 
<description><![CDATA[Infopoint Security. Men&uuml;. IT-Security &middot; Events &middot; &Uuml;ber Uns &middot; Kontakt &middot; IT-Security ... Data Supply Chain Security: Das untersch&auml;tzte Risiko externer B2B&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3597272/IT+Sicherheit/Cybersecurity+Nachrichten/Chinesische+PhaaS-Plattformen+professionalisieren+Phishing-Angriffe+mit+KI+und+Echtzeit-Tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597272/IT+Sicherheit/Cybersecurity+Nachrichten/Chinesische+PhaaS-Plattformen+professionalisieren+Phishing-Angriffe+mit+KI+und+Echtzeit-Tools/</guid>
<pubDate>Sun, 14 Jun 2026 14:08:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FBI disrupts massive AI-powered phishing service using a million URLs]]></title> 
<description><![CDATA[In a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing websites used to steal credit card data and passwords. [...] ]]></description>
<link>https://tsecurity.de/de/3597231/IT+Sicherheit/Cybersecurity+Nachrichten/FBI+disrupts+massive+AI-powered+phishing+service+using+a+million+URLs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597231/IT+Sicherheit/Cybersecurity+Nachrichten/FBI+disrupts+massive+AI-powered+phishing+service+using+a+million+URLs/</guid>
<pubDate>Sun, 14 Jun 2026 16:36:23 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cyberkriminalität: Phishing-Angriffe um das 14-Fache gestiegen - BornCity]]></title> 
<description><![CDATA[Auch f&uuml;r Unternehmen steigen die Anforderungen an die IT-Sicherheit ... Es verpflichtet rund 30.000 Unternehmen zu strengen IT-Sicherheitsstandards und&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3596955/IT+Sicherheit/Cybersecurity+Nachrichten/Cyberkriminalit%C3%A4t%3A+Phishing-Angriffe+um+das+14-Fache+gestiegen+-+BornCity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596955/IT+Sicherheit/Cybersecurity+Nachrichten/Cyberkriminalit%C3%A4t%3A+Phishing-Angriffe+um+das+14-Fache+gestiegen+-+BornCity/</guid>
<pubDate>Sun, 14 Jun 2026 12:26:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[INTERPOL stoppt Sniper Dz: Phishing-as-a-Service für 45.000 Opfer außer Betrieb]]></title> 
<description><![CDATA[Stichw&ouml;rter Arrests Compliance Cybercrime Cybersecurity Data Fraud Hacker Hosting Infrastructure Interpol IT-Sicherheit Monitoring Networks&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3596168/IT+Sicherheit/Cybersecurity+Nachrichten/INTERPOL+stoppt+Sniper+Dz%3A+Phishing-as-a-Service+f%C3%BCr+45.000+Opfer+au%C3%9Fer+Betrieb/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596168/IT+Sicherheit/Cybersecurity+Nachrichten/INTERPOL+stoppt+Sniper+Dz%3A+Phishing-as-a-Service+f%C3%BCr+45.000+Opfer+au%C3%9Fer+Betrieb/</guid>
<pubDate>Sat, 13 Jun 2026 14:43:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Der Anstieg von CalPhishing-Angriffen im Gesundheitssektor - Health-ISAC]]></title> 
<description><![CDATA[Cybersicherheit f&uuml;r Klinikpersonal &middot; Identity ... Was F&uuml;hrungskr&auml;fte im Gesundheitswesen in den Jahren 2026-2027 &uuml;ber Cybersicherheit wissen m&uuml;ssen&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3595338/IT+Sicherheit/Cybersecurity+Nachrichten/Der+Anstieg+von+CalPhishing-Angriffen+im+Gesundheitssektor+-+Health-ISAC/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595338/IT+Sicherheit/Cybersecurity+Nachrichten/Der+Anstieg+von+CalPhishing-Angriffen+im+Gesundheitssektor+-+Health-ISAC/</guid>
<pubDate>Fri, 12 Jun 2026 02:13:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[INTERPOL stoppt Sniper Dz: Phishing-as-a-Service für 45.000 Opfer außer Betrieb]]></title> 
<description><![CDATA[ALGERIEN / LONDON (IT BOLTWISE) &ndash; INTERPOL hat im Rahmen der Operation Ramz die Phishing-as-a-Service-Plattform Sniper Dz zerschlagen und den zentralen Administrator festnehmen lassen. Die Aktion lief &uuml;ber mehrere Monate zwischen Oktober 2025 und Februar 2026 und umfasste Beh&ouml;rden aus 13 L&auml;ndern der MENA-Region. Sniper Dz, das offenbar seit mindestens 2015 aktiv war und sich [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;INTERPOL stoppt Sniper Dz: Phishing-as-a-Service f&uuml;r 45.000 Opfer au&szlig;er Betrieb&laquo; lesen
Dieser Beitrag INTERPOL stoppt Sniper Dz: Phishing-as-a-Service f&uuml;r 45.000 Opfer au&szlig;er Betrieb erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3594796/IT+Sicherheit/Cybersecurity+Nachrichten/INTERPOL+stoppt+Sniper+Dz%3A+Phishing-as-a-Service+f%C3%BCr+45.000+Opfer+au%C3%9Fer+Betrieb/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594796/IT+Sicherheit/Cybersecurity+Nachrichten/INTERPOL+stoppt+Sniper+Dz%3A+Phishing-as-a-Service+f%C3%BCr+45.000+Opfer+au%C3%9Fer+Betrieb/</guid>
<pubDate>Sat, 13 Jun 2026 02:41:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa]]></title> 
<description><![CDATA[ ]]></description>
<link>https://tsecurity.de/de/3594677/IT+Sicherheit/Cybersecurity+Nachrichten/China-Linked+TA4922+Expands+Phishing+Attacks+to+U.K.%2C+Germany%2C+Italy%2C+and+South+Africa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594677/IT+Sicherheit/Cybersecurity+Nachrichten/China-Linked+TA4922+Expands+Phishing+Attacks+to+U.K.%2C+Germany%2C+Italy%2C+and+South+Africa/</guid>
<pubDate>Thu, 04 Jun 2026 15:35:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing]]></title> 
<description><![CDATA[Google on Friday said it&#039;s pursuing legal action against a Chinese cybercrime network, accusing it of using its Gemini artificial intelligence (AI) agent to send phishing text messages targeting Americans.

The network is said to be behind the development and management of a phishing-as-a-service (PhaaS) software kit called Outsider, per the tech giant.

&quot;The operation weaponized Gemini to help ]]></description>
<link>https://tsecurity.de/de/3594444/IT+Sicherheit/Cybersecurity+Nachrichten/Google+Sues+Chinese+Smishing+Network+Accused+of+Using+Gemini+AI+in+Phishing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594444/IT+Sicherheit/Cybersecurity+Nachrichten/Google+Sues+Chinese+Smishing+Network+Accused+of+Using+Gemini+AI+in+Phishing/</guid>
<pubDate>Fri, 12 Jun 2026 20:59:32 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing]]></title> 
<description><![CDATA[Google on Friday said it&rsquo;s pursuing legal action against a Chinese cybercrime network, accusing it of using its Gemini artificial intelligence (AI) agent to send phishing text messages targeting Americans. The network is said to be behind the development and&hellip;
Read more &rarr;
The post Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3594426/IT+Sicherheit/Cybersecurity+Nachrichten/Google+Sues+Chinese+Smishing+Network+Accused+of+Using+Gemini+AI+in+Phishing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594426/IT+Sicherheit/Cybersecurity+Nachrichten/Google+Sues+Chinese+Smishing+Network+Accused+of+Using+Gemini+AI+in+Phishing/</guid>
<pubDate>Fri, 12 Jun 2026 21:34:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[NordVPN’s next-gen antivirus aces independent testing with a 96% phishing block rate]]></title> 
<description><![CDATA[NordVPN&#039;s next-generation antivirus has just blocked 96% of phishing sites in an independent AV-Comparatives test, proving the privacy app is a formidable all-in-one security suite. ]]></description>
<link>https://tsecurity.de/de/3593914/IT+Nachrichten/NordVPN%E2%80%99s+next-gen+antivirus+aces+independent+testing+with+a+96%25+phishing+block+rate/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593914/IT+Nachrichten/NordVPN%E2%80%99s+next-gen+antivirus+aces+independent+testing+with+a+96%25+phishing+block+rate/</guid>
<pubDate>Fri, 12 Jun 2026 17:17:45 +0200</pubDate>
</item>
<item> 
<title><![CDATA[INTERPOL stoppt Sniper Dz: Phishing-as-a-Service-Plattform mit 45.000 Opfern-Zieldaten]]></title> 
<description><![CDATA[ALGERIEN / LONDON (IT BOLTWISE) &ndash; Eine von INTERPOL gef&uuml;hrte Operation hat die &uuml;ber Jahre aktive Phishing-as-a-Service-Plattform Sniper Dz weitgehend zerschlagen und den Administrator festnehmen lassen. Die Beh&ouml;rden sprechen von 201 Festnahmen in 13 L&auml;ndern und von Zehntausenden identifizierten Domains, die mit dem Dienst verkn&uuml;pft waren. Laut einer Analyse wurden Opferdaten in gro&szlig;em Umfang gesammelt [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;INTERPOL stoppt Sniper Dz: Phishing-as-a-Service-Plattform mit 45.000 Opfern-Zieldaten&laquo; lesen
Dieser Beitrag INTERPOL stoppt Sniper Dz: Phishing-as-a-Service-Plattform mit 45.000 Opfern-Zieldaten erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3593462/IT+Sicherheit/Cybersecurity+Nachrichten/INTERPOL+stoppt+Sniper+Dz%3A+Phishing-as-a-Service-Plattform+mit+45.000+Opfern-Zieldaten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593462/IT+Sicherheit/Cybersecurity+Nachrichten/INTERPOL+stoppt+Sniper+Dz%3A+Phishing-as-a-Service-Plattform+mit+45.000+Opfern-Zieldaten/</guid>
<pubDate>Fri, 12 Jun 2026 14:37:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cybercriminals are moving away from mass phishing campaigns]]></title> 
<description><![CDATA[Phishing activity declined by roughly 20% in both 2024 and 2025, according to research from Zscaler&rsquo;s ThreatLabz team. The drop followed years of growth that pushed phishing activity above 2 billion hits in 2023. &ldquo;Phishing volume measured by blocked emails&hellip;
Read more &rarr;
The post Cybercriminals are moving away from mass phishing campaigns appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3593239/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercriminals+are+moving+away+from+mass+phishing+campaigns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593239/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercriminals+are+moving+away+from+mass+phishing+campaigns/</guid>
<pubDate>Fri, 12 Jun 2026 13:04:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cybercriminals are moving away from mass phishing campaigns]]></title> 
<description><![CDATA[Phishing activity declined by roughly 20% in both 2024 and 2025, according to research from Zscaler&rsquo;s ThreatLabz team. The drop followed years of growth that pushed phishing activity above 2 billion hits in 2023. &ldquo;Phishing volume measured by blocked emails is no longer a reliable proxy for phishing risk.&rdquo; Researchers found greater use of targeted phishing campaigns designed to resemble routine business communications. The services sector recorded a 65.5% year-over-year increase in phishing activity, making &hellip; More &rarr;
The post Cybercriminals are moving away from mass phishing campaigns appeared first on Help Net Security. ]]></description>
<link>https://tsecurity.de/de/3593194/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercriminals+are+moving+away+from+mass+phishing+campaigns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593194/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercriminals+are+moving+away+from+mass+phishing+campaigns/</guid>
<pubDate>Fri, 12 Jun 2026 12:47:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator]]></title> 
<description><![CDATA[An INTERPOL-led operation last month resulted in the disruption of Sniper Dz, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB said Thursday.

The effort, codenamed Operation Ramz, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests.

Included among them was Guedz, the primary ]]></description>
<link>https://tsecurity.de/de/3593091/IT+Sicherheit/Cybersecurity+Nachrichten/INTERPOL+Operation+Takes+Down+Sniper+Dz+Phishing+Platform%2C+Arrests+Administrator/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593091/IT+Sicherheit/Cybersecurity+Nachrichten/INTERPOL+Operation+Takes+Down+Sniper+Dz+Phishing+Platform%2C+Arrests+Administrator/</guid>
<pubDate>Fri, 12 Jun 2026 10:52:55 +0200</pubDate>
</item>
<item> 
<title><![CDATA[INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator]]></title> 
<description><![CDATA[An INTERPOL-led operation last month resulted in the disruption of Sniper Dz, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB said Thursday. The effort, codenamed Operation Ramz, took place between October 2025 and February 2026, and saw authorities from 13 countries in&hellip;
Read more &rarr;
The post INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3593079/IT+Sicherheit/Cybersecurity+Nachrichten/INTERPOL+Operation+Takes+Down+Sniper+Dz+Phishing+Platform%2C+Arrests+Administrator/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593079/IT+Sicherheit/Cybersecurity+Nachrichten/INTERPOL+Operation+Takes+Down+Sniper+Dz+Phishing+Platform%2C+Arrests+Administrator/</guid>
<pubDate>Fri, 12 Jun 2026 12:10:17 +0200</pubDate>
</item>
<item> 
<title><![CDATA[OpenClaw-Angriffe: Prompt-Injection und Agent-Phishing liefern Code und Geheimnisse]]></title> 
<description><![CDATA[LONDON (IT BOLTWISE) &ndash; Zwei unabh&auml;ngige Sicherheitsstudien zeigen, wie der selbst gehostete KI-Agent OpenClaw &uuml;ber scheinbar harmlose Kontakte und normale E-Mails in sch&auml;dliche Aktionen gedr&auml;ngt werden kann. Dabei k&ouml;nnen versteckte Anweisungen dazu f&uuml;hren, dass Code ausgef&uuml;hrt wird oder vertrauliche Daten aus dem System herauswandern. Imperva meldet eine bereits gefixte Schwachstelle in Version 2026.4.23, w&auml;hrend Varonis [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;OpenClaw-Angriffe: Prompt-Injection und Agent-Phishing liefern Code und Geheimnisse&laquo; lesen
Dieser Beitrag OpenClaw-Angriffe: Prompt-Injection und Agent-Phishing liefern Code und Geheimnisse erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3592086/IT+Sicherheit/Cybersecurity+Nachrichten/OpenClaw-Angriffe%3A+Prompt-Injection+und+Agent-Phishing+liefern+Code+und+Geheimnisse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592086/IT+Sicherheit/Cybersecurity+Nachrichten/OpenClaw-Angriffe%3A+Prompt-Injection+und+Agent-Phishing+liefern+Code+und+Geheimnisse/</guid>
<pubDate>Fri, 12 Jun 2026 01:54:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[OpenClaw-Tests zeigen Prompt- und Agent-Phishing: Fix in Version 2026.4.23]]></title> 
<description><![CDATA[LONDON (IT BOLTWISE) &ndash; Zwei Sicherheitsstudien belegen, dass der selbst gehostete KI-Agent OpenClaw &uuml;ber scheinbar harmlose Kontakte und normale E-Mails sowohl fremden Code ausf&uuml;hren als auch Daten abflie&szlig;en lassen kann. W&auml;hrend Imperva vor allem eine Schwachstelle beim Zusammenbau von Eingaben in den Prompt beschreibt, ordnet Varonis das Problem als Agent-Phishing ein, bei dem der Agent [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;OpenClaw-Tests zeigen Prompt- und Agent-Phishing: Fix in Version 2026.4.23&laquo; lesen
Dieser Beitrag OpenClaw-Tests zeigen Prompt- und Agent-Phishing: Fix in Version 2026.4.23 erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3591904/IT+Sicherheit/Cybersecurity+Nachrichten/OpenClaw-Tests+zeigen+Prompt-+und+Agent-Phishing%3A+Fix+in+Version+2026.4.23/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591904/IT+Sicherheit/Cybersecurity+Nachrichten/OpenClaw-Tests+zeigen+Prompt-+und+Agent-Phishing%3A+Fix+in+Version+2026.4.23/</guid>
<pubDate>Thu, 11 Jun 2026 23:51:45 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing Attack Volume Down 20%, but Risk Still Rising]]></title> 
<description><![CDATA[Hackers are valuing quality over quantity, using AI to upgrade their phishing attacks rather than multiplying them. ]]></description>
<link>https://tsecurity.de/de/3591686/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing+Attack+Volume+Down+20%25%2C+but+Risk+Still+Rising/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591686/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing+Attack+Volume+Down+20%25%2C+but+Risk+Still+Rising/</guid>
<pubDate>Fri, 12 Jun 2026 02:58:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[MaaS, Supply-Chain und Agent-Phishing: Sicherheitslage zeigt neue Credential- und Kompromisswege]]></title> 
<description><![CDATA[LONDON (IT BOLTWISE) &ndash; Eine Woche, in der nicht der Exploit im Vordergrund steht, sondern die Kette: gestohlene Identit&auml;ten, professionell verpackte Malware-as-a-Service und immer besser getarnte Social-Engineering-Flows. Besonders auff&auml;llig ist, dass Infostealer und RATs mittlerweile wie Software-Produkte vertrieben werden, w&auml;hrend Krypto-, Browser- und Token-Abfl&uuml;sse den Zugriff auf Cloud- und Kontosysteme dominieren. Dazu kommt Agent-Phishing, bei [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;MaaS, Supply-Chain und Agent-Phishing: Sicherheitslage zeigt neue Credential- und Kompromisswege&laquo; lesen
Dieser Beitrag MaaS, Supply-Chain und Agent-Phishing: Sicherheitslage zeigt neue Credential- und Kompromisswege erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3591621/IT+Sicherheit/Cybersecurity+Nachrichten/MaaS%2C+Supply-Chain+und+Agent-Phishing%3A+Sicherheitslage+zeigt+neue+Credential-+und+Kompromisswege/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591621/IT+Sicherheit/Cybersecurity+Nachrichten/MaaS%2C+Supply-Chain+und+Agent-Phishing%3A+Sicherheitslage+zeigt+neue+Credential-+und+Kompromisswege/</guid>
<pubDate>Thu, 11 Jun 2026 20:56:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Decade-Long SniperDz Phishing Network Disrupted in Operation Ramz]]></title> 
<description><![CDATA[Group-IB, INTERPOL and Algerian Police dismantle decade-old SniperDZ phishing network used to steal credentials, with its alleged developer arrested. ]]></description>
<link>https://tsecurity.de/de/3591289/IT+Sicherheit/Cybersecurity+Nachrichten/Decade-Long+SniperDz+Phishing+Network+Disrupted+in+Operation+Ramz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591289/IT+Sicherheit/Cybersecurity+Nachrichten/Decade-Long+SniperDz+Phishing+Network+Disrupted+in+Operation+Ramz/</guid>
<pubDate>Thu, 11 Jun 2026 18:18:37 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Decade-Long SniperDz Phishing Network Disrupted in Operation Ramz]]></title> 
<description><![CDATA[Group-IB, INTERPOL and Algerian Police dismantle decade-old SniperDZ phishing network used to steal credentials, with its alleged developer arrested. This article has been indexed from Hackread &ndash; Cybersecurity News, Data Breaches, AI and More Read the original article: Decade-Long SniperDz&hellip;
Read more &rarr;
The post Decade-Long SniperDz Phishing Network Disrupted in Operation Ramz appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3591282/IT+Sicherheit/Cybersecurity+Nachrichten/Decade-Long+SniperDz+Phishing+Network+Disrupted+in+Operation+Ramz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591282/IT+Sicherheit/Cybersecurity+Nachrichten/Decade-Long+SniperDz+Phishing+Network+Disrupted+in+Operation+Ramz/</guid>
<pubDate>Thu, 11 Jun 2026 18:32:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Signal Users Targeted in Sophisticated Phishing Campaigns Aimed at Stealing Chat Backups]]></title> 
<description><![CDATA[&nbsp; Recently uncovered cyber threats now focus on people relying on Signal&rsquo;s encrypted messaging service. Fake notifications, appearing legitimate at first glance, lead recipients to counterfeit pages through deceptive URLs. These attempts aim straight at stored conversation archives linked to&hellip;
Read more &rarr;
The post Signal Users Targeted in Sophisticated Phishing Campaigns Aimed at Stealing Chat Backups appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3590910/IT+Sicherheit/Cybersecurity+Nachrichten/Signal+Users+Targeted+in+Sophisticated+Phishing+Campaigns+Aimed+at+Stealing+Chat+Backups/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590910/IT+Sicherheit/Cybersecurity+Nachrichten/Signal+Users+Targeted+in+Sophisticated+Phishing+Campaigns+Aimed+at+Stealing+Chat+Backups/</guid>
<pubDate>Thu, 11 Jun 2026 16:32:28 +0200</pubDate>
</item>
<item> 
<title><![CDATA[The Fall of SniperDz: Takedown of a Decade-Long Phishing Empire]]></title> 
<description><![CDATA[ 
    
 
The developer and administrator behind SniperDz, one of the world&#039;s longest-running phishing-as-a-service (PhaaS) platforms, has been arrested. This significant victory for international cyber crime enforcement follows a coordinated operation involving INTERPOL, the Algerian National Police, and threat intelligence firm Group-IB. Group-IB announced the arrest and its role in the takedown in a press release on June 11, 2026. &nbsp; ]]></description>
<link>https://tsecurity.de/de/3590861/IT+Sicherheit/Cybersecurity+Nachrichten/The+Fall+of+SniperDz%3A+Takedown+of+a+Decade-Long+Phishing+Empire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590861/IT+Sicherheit/Cybersecurity+Nachrichten/The+Fall+of+SniperDz%3A+Takedown+of+a+Decade-Long+Phishing+Empire/</guid>
<pubDate>Thu, 11 Jun 2026 15:49:23 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing: Alarmierende Zahlen aus neuer Studie]]></title> 
<description><![CDATA[Egal ob Sparkasse, DHL oder PayPal: Kriminelle missbrauchen bekannte Namen f&uuml;r Phishing. Eine Analyse von Milliarden Betrugsversuchen zeigt, dass gef&auml;lschte Mails und Webseiten weiterhin die gr&ouml;&szlig;te Gefahr sind. ]]></description>
<link>https://tsecurity.de/de/3590832/IT+Nachrichten/Phishing%3A+Alarmierende+Zahlen+aus+neuer+Studie/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590832/IT+Nachrichten/Phishing%3A+Alarmierende+Zahlen+aus+neuer+Studie/</guid>
<pubDate>Thu, 11 Jun 2026 16:07:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Interpol Dismantles SniperDz Phishing-as-a-Service Platform]]></title> 
<description><![CDATA[New revelations by Group-IB expose the full scale of the decade-old SniperDz phishing operation ]]></description>
<link>https://tsecurity.de/de/3590366/IT+Sicherheit/Cybersecurity+Nachrichten/Interpol+Dismantles+SniperDz+Phishing-as-a-Service+Platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590366/IT+Sicherheit/Cybersecurity+Nachrichten/Interpol+Dismantles+SniperDz+Phishing-as-a-Service+Platform/</guid>
<pubDate>Thu, 11 Jun 2026 13:30:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Interpol Dismantles SniperDz Phishing-as-a-Service Platform]]></title> 
<description><![CDATA[New revelations by Group-IB expose the full scale of the decade-old SniperDz phishing operation This article has been indexed from www.infosecurity-magazine.com Read the original article: Interpol Dismantles SniperDz Phishing-as-a-Service Platform
Read more &rarr;
The post Interpol Dismantles SniperDz Phishing-as-a-Service Platform appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3590364/IT+Sicherheit/Cybersecurity+Nachrichten/Interpol+Dismantles+SniperDz+Phishing-as-a-Service+Platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590364/IT+Sicherheit/Cybersecurity+Nachrichten/Interpol+Dismantles+SniperDz+Phishing-as-a-Service+Platform/</guid>
<pubDate>Thu, 11 Jun 2026 13:32:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing-Test zeigt: KI verrät Passwörter und Kundendaten]]></title> 
<description><![CDATA[KI-Agenten arbeiten selbstst&auml;ndig und haben Zugriff auf sensible Daten. Das kann gef&auml;hrlich werden: In einem aktuellen Test gab ein solcher Agent Zugangs- und Kundendaten an vermeintliche Kollegen weiter. ]]></description>
<link>https://tsecurity.de/de/3590006/IT+Nachrichten/Phishing-Test+zeigt%3A+KI+verr%C3%A4t+Passw%C3%B6rter+und+Kundendaten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590006/IT+Nachrichten/Phishing-Test+zeigt%3A+KI+verr%C3%A4t+Passw%C3%B6rter+und+Kundendaten/</guid>
<pubDate>Thu, 11 Jun 2026 11:20:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Aged-domain acquisition: The tradecraft phishing operators are using to bypass your mail filter’s reputation score]]></title> 
<description><![CDATA[
		
					  
						




I&rsquo;ve spent the past two years working on incident response and threat intelligence, and the pattern I&rsquo;m about to describe is one I keep seeing show up in cases that should have been caught at the email gateway. The kit families change. The lure templates change. The constant is that phishing-as-a-service operators are buying aged legitimate domains and redeploying them to steal credentials from enterprise and government targets.



The most recent incident I worked involved a Sneaky2FA deployment running on 117 origin servers in Kansas City, Missouri, split across two hosting providers. The operator has been on the same infrastructure for over two years and runs lures against a mix of UK and US government, energy companies and US healthcare SMBs. The aged-domain tradecraft I&rsquo;m about to walk through is one way this operator stays inside enterprise environments that should be filtering them out. The certificate transparency logs tell the whole story, and they explain why the reputation classifier didn&rsquo;t catch it.



How age-weighted reputation became the blind spot



Most enterprise mail filters from major vendors, including Microsoft Defender for Office 365, Proofpoint, Mimecast and Cisco Talos, factor domain age heavily into their classification decisions. A freshly registered .com triggers immediate reputation penalties. A domain with years of stable hosting, consistent certificate issuance and clean DNS history gets treated as low risk. The logic made sense ten years ago, when newly minted abuse domains dominated phishing infrastructure and aged domains usually meant established small businesses.



I work with several enterprise environments that pay for the most expensive tiers of email security and still see phishing lures land in users&rsquo; inboxes. When I trace those lures back to their parent domains, an increasing percentage show the same pattern. Long-stable cert history through some point in 2024 or 2025. A several-month gap with no new certs issued. Then certs start appearing again for subdomains that have nothing to do with the original brand. The reputation score on these domains is high. The infrastructure behind them is criminal. The filter doesn&rsquo;t know the difference.



What aged-domain acquisition actually looks like



There are two reasonable ways for an operator to acquire an aged domain. They can drop-catch an expired registration, or they can hijack an active one through credential theft against the owner&rsquo;s registrar account. Drop-catching is cheaper and lower-risk. Services like DropCatch, SnapNames and GoDaddy Auctions exist precisely to acquire domains the moment they expire, and a determined operator can pay $50 to $500 for a domain with a decade of clean history.



The domain I want to walk through is one I documented in detail during the Sneaky2FA case: digitalscrapbookingfreebies.com. The certificate transparency record shows the takeover in full. From 2016 through July 2025, the cert history reads like a normal small-business cPanel-hosted blog. cPanel Inc. issued ECC certs every 60 to 90 days for the standard cpanel., mail., webdisk. and webmail. subdomains. Let&rsquo;s Encrypt R3 issued certs for the apex and www. every 90 days. The subjects stayed stable across nine years. Someone was running a hobby blog providing free scrapbooking assets to a small audience, and the cert pattern reflects that.



In April 2025, GoDaddy certs appear in the record. A new certificate authority showing up after eight uninterrupted years of cPanel-plus-Let&rsquo;s-Encrypt is the first hard signal that something changed at the registrar or hosting level. By July 2025, the last legitimate-pattern cert will be issued. Then six months of silence, no new certs, no renewals. In December 2025, fresh Let&rsquo;s Encrypt R13 certs surfaced for subdomains the original blog never had: beds, footboard, haushafin and locklear. By January 2026, another subdomain appeared: nativems-mfl09093004.digitalscrapbookingfreebies.com. That subdomain was the one I caught being actively used in phishing against a US state health agency.



The original owner of the scrapbooking blog is almost certainly a victim, too. They probably let the registration lapse, the operator drop-caught it and the domain entered criminal use under a privacy WHOIS that obscures the new ownership. Their nine years of reputation-building goodwill now serve as a credential-theft operation.



What made this case generalizable is that the same operator also runs a second-tier-2 lure domain acquired through fresh registration. The two strategies serve different targeting profiles. The operator uses fresh registrations when the subdomain itself can carry the credibility, like an SSO-themed subdomain mimicking a corporate authentication endpoint where the parent domain isn&rsquo;t doing much work. The operator uses aged-domain acquisitions when the domain reputation itself has to do the work, when the lure is going through an enterprise mail filter that scores by age. The selection is contextual.



Why your reputation classifier won&rsquo;t catch this



Reputation scoring assumes that domain history reflects domain ownership. When ownership transfers through drop-catch or hijack, that assumption breaks. The score doesn&rsquo;t reset. The new operator inherits the trust without inheriting any of the work that built it. Most reputation systems also weigh the length of clean history more heavily than recent changes to ownership patterns, which makes the problem worse. A nine-year-old domain that changes hands quietly stays scored as a nine-year-old domain.



The signals that would actually catch the takeover (a CA issuer change, a six-month cert gap, a sudden wordlist of new subdomains that has nothing to do with the original brand) aren&rsquo;t features in most age-weighted classifiers.



A better detection approach has to weigh hosting-pattern stability. A domain whose hosting infrastructure changes abruptly is more suspicious than a domain whose pattern continues uninterrupted, and the events you want to fire on are concrete: a new CA appearing after years of stable issuance, a gap in cert renewals followed by new issuance or a CDN change with no legitimate ownership reason. Most reputation systems don&rsquo;t track any of this because the score is a single number rather than a stability metric.



Subdomain wordlist anomaly is the second axis. When a long-stable domain about scrapbooking suddenly issues certs for a subdomain named nativems-mfl09093004, the disconnect between the original brand and the new naming is detectable behaviorally, even when every other signal fails.



The third piece is certificate transparency monitoring. CT logs are public, queryable and updated within hours. I reconstructed the entire digitalscrapbookingfreebies.com takeover timeline from public CT data alone. No commercial threat feed was required. Security teams who subscribe to CT log feeds for their blocklist candidates can surface operator-deployed subdomains within hours of issuance, which is often well before they show up in any commercial threat feed.



If I were running enterprise email security tomorrow, the first thing I&rsquo;d change is to stop treating domain age as a primary signal. Aged-domain acquisition is documented tradecraft now. Sekoia has surfaced it. Centripetal has surfaced it. My own research on this Sneaky2FA case adds another example. Any reputation system that weights age heavily has a known bypass, which means age should be one signal among several, not the dominant one.



The detection logic that does work is the one I described above: hosting-pattern stability, subdomain wordlist anomaly and CT log monitoring. A nine-year-old hobby blog suddenly hosting Microsoft-themed authentication pages is detectable behaviorally, even when domain age fails the analyst. Several CTI vendors are starting to surface this as a capability. Ask yours where they are on it and get a real answer, not a marketing one. CT log monitoring is cheap and surfaces operator infrastructure within hours of issuance, which is one of the higher leverage moves a small security team can make.



The operators figured out the blind spot. They&rsquo;re going to keep buying aged domains for as long as those domains keep working. Closing the gap doesn&rsquo;t take a new product line. It takes treating the signals we already collect with appropriate weight.



The full research from the Sneaky2FA case, including methodology, IOCs and the detection rules I wrote, is available on my GitHub.



This article is published as part of the Foundry Expert Contributor Network.Want to join?
 ]]></description>
<link>https://tsecurity.de/de/3589986/IT+Sicherheit/Cybersecurity+Nachrichten/Aged-domain+acquisition%3A+The+tradecraft+phishing+operators+are+using+to+bypass+your+mail+filter%E2%80%99s+reputation+score/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589986/IT+Sicherheit/Cybersecurity+Nachrichten/Aged-domain+acquisition%3A+The+tradecraft+phishing+operators+are+using+to+bypass+your+mail+filter%E2%80%99s+reputation+score/</guid>
<pubDate>Thu, 11 Jun 2026 11:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Neue Welle von gefälschten McAfee Phishing Mails verunsichert Verbraucher]]></title> 
<description><![CDATA[
    Cyberkriminelle nutzen gef&auml;lschte McAfee Verl&auml;ngerungsbenachrichtigungen und manipulative Browser Pop ups, um Anwender in betr&uuml;gerische Callcenter zu leiten.

Tags: #Cyber Crime | #McAfee | #Phishing E-Mail ]]></description>
<link>https://tsecurity.de/de/3589562/IT+Sicherheit/Cybersecurity+Nachrichten/Neue+Welle+von+gef%C3%A4lschten+McAfee+Phishing+Mails+verunsichert+Verbraucher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589562/IT+Sicherheit/Cybersecurity+Nachrichten/Neue+Welle+von+gef%C3%A4lschten+McAfee+Phishing+Mails+verunsichert+Verbraucher/</guid>
<pubDate>Thu, 11 Jun 2026 07:09:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Meta sperrt WhatsApp-Phishing von NSO Group und beantragt Contempt Order]]></title> 
<description><![CDATA[LONDON (IT BOLTWISE) &ndash; Meta meldet, dass es spear-phishing-Angriffe mit Verbindungen zum israelischen Spyware-Anbieter NSO Group auf WhatsApp erkannt und blockiert hat. Gleichzeitig geht der Konzern juristisch vor und beantragt eine Contempt Order, weil NSO Group eine dauerhafte Verf&uuml;gung verletzt haben soll. Im Zentrum stehen laut Meta betr&uuml;gerische Links zu externen Seiten au&szlig;erhalb von WhatsApp [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;Meta sperrt WhatsApp-Phishing von NSO Group und beantragt Contempt Order&laquo; lesen
Dieser Beitrag Meta sperrt WhatsApp-Phishing von NSO Group und beantragt Contempt Order erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3589359/IT+Sicherheit/Cybersecurity+Nachrichten/Meta+sperrt+WhatsApp-Phishing+von+NSO+Group+und+beantragt+Contempt+Order/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589359/IT+Sicherheit/Cybersecurity+Nachrichten/Meta+sperrt+WhatsApp-Phishing+von+NSO+Group+und+beantragt+Contempt+Order/</guid>
<pubDate>Thu, 11 Jun 2026 03:53:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FIFA-Phishing: Hacker erbeuten 270.000 Fan-Zugänge zur WM 2026 - Börse Express]]></title> 
<description><![CDATA[Hacker nutzen gef&auml;lschte FIFA-Karriereportale, um Bewerber um ihre Zugangsdaten zu bringen. Eine neue Welle professionell gestalteter&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3589335/IT+Sicherheit/Hacker/FIFA-Phishing%3A+Hacker+erbeuten+270.000+Fan-Zug%C3%A4nge+zur+WM+2026+-+B%C3%B6rse+Express/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589335/IT+Sicherheit/Hacker/FIFA-Phishing%3A+Hacker+erbeuten+270.000+Fan-Zug%C3%A4nge+zur+WM+2026+-+B%C3%B6rse+Express/</guid>
<pubDate>Thu, 11 Jun 2026 03:43:44 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Use Tax Phishing Emails to Deploy In-Memory Malware on Windows Systems]]></title> 
<description><![CDATA[Hackers are using fake tax notification emails to trick Windows users into downloading dangerous multi-stage malware that runs entirely in memory, leaving almost no trace behind. The campaign, tracked as&nbsp;Operation TaxShadow, has been active since at least May 20, 2026,&hellip;
Read more &rarr;
The post Hackers Use Tax Phishing Emails to Deploy In-Memory Malware on Windows Systems appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3588758/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Use+Tax+Phishing+Emails+to+Deploy+In-Memory+Malware+on+Windows+Systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588758/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Use+Tax+Phishing+Emails+to+Deploy+In-Memory+Malware+on+Windows+Systems/</guid>
<pubDate>Wed, 10 Jun 2026 21:34:17 +0200</pubDate>
</item>
<item> 
<title><![CDATA[OpenClaw AI Agent Leaks Sensitive Credentials in New Phishing Attack Simulation]]></title> 
<description><![CDATA[AI agents are becoming a core part of how companies manage their inboxes, triaging messages, pulling up files, and even replying to emails on behalf of employees. What researchers have now confirmed is that these agents can be tricked just&hellip;
Read more &rarr;
The post OpenClaw AI Agent Leaks Sensitive Credentials in New Phishing Attack Simulation appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3588755/IT+Sicherheit/Cybersecurity+Nachrichten/OpenClaw+AI+Agent+Leaks+Sensitive+Credentials+in+New+Phishing+Attack+Simulation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588755/IT+Sicherheit/Cybersecurity+Nachrichten/OpenClaw+AI+Agent+Leaks+Sensitive+Credentials+in+New+Phishing+Attack+Simulation/</guid>
<pubDate>Wed, 10 Jun 2026 21:34:32 +0200</pubDate>
</item>
<item> 
<title><![CDATA[OpenClaw AI agent tricked into phishing attacks, with user data compromised]]></title> 
<description><![CDATA[Varonis has a suggestion on how to make AI agents more careful. ]]></description>
<link>https://tsecurity.de/de/3588669/IT+Nachrichten/OpenClaw+AI+agent+tricked+into+phishing+attacks%2C+with+user+data+compromised/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588669/IT+Nachrichten/OpenClaw+AI+agent+tricked+into+phishing+attacks%2C+with+user+data+compromised/</guid>
<pubDate>Wed, 10 Jun 2026 20:35:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FOCUS-Interview mit Rechtsanwältin Tanja Nauschütz: So schützen Sie sich vor Phishing ...]]></title> 
<description><![CDATA[Im aktuellen FOCUS (Ausgabe 21) wurde Rechtsanw&auml;ltin Tanja Nausch&uuml;tz als Expertin zu Phishing, Anlagebetrug, Fake-Shops und modernen Betrugsmaschen im&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3588517/IT+Sicherheit/Cybersecurity+Nachrichten/FOCUS-Interview+mit+Rechtsanw%C3%A4ltin+Tanja+Nausch%C3%BCtz%3A+So+sch%C3%BCtzen+Sie+sich+vor+Phishing+.../</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588517/IT+Sicherheit/Cybersecurity+Nachrichten/FOCUS-Interview+mit+Rechtsanw%C3%A4ltin+Tanja+Nausch%C3%BCtz%3A+So+sch%C3%BCtzen+Sie+sich+vor+Phishing+.../</guid>
<pubDate>Wed, 10 Jun 2026 18:26:05 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Use Tax Phishing Emails to Deploy In-Memory Malware on Windows Systems]]></title> 
<description><![CDATA[Hackers are using fake tax notification emails to trick Windows users into downloading dangerous multi-stage malware that runs entirely in memory, leaving almost no trace behind. The campaign, tracked as&nbsp;Operation TaxShadow, has been active since at least May 20, 2026, targeting individuals by impersonating official Indian government tax authorities. The emails are crafted to create [&hellip;]
The post Hackers Use Tax Phishing Emails to Deploy In-Memory Malware on Windows Systems appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3588492/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Use+Tax+Phishing+Emails+to+Deploy+In-Memory+Malware+on+Windows+Systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588492/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Use+Tax+Phishing+Emails+to+Deploy+In-Memory+Malware+on+Windows+Systems/</guid>
<pubDate>Wed, 10 Jun 2026 19:11:05 +0200</pubDate>
</item>
<item> 
<title><![CDATA[OpenClaw AI Agent Leaks Sensitive Credentials in New Phishing Attack Simulation]]></title> 
<description><![CDATA[AI agents are becoming a core part of how companies manage their inboxes, triaging messages, pulling up files, and even replying to emails on behalf of employees. What researchers have now confirmed is that these agents can be tricked just like humans, and sometimes more easily. A new phishing simulation has shown that an AI [&hellip;]
The post OpenClaw AI Agent Leaks Sensitive Credentials in New Phishing Attack Simulation appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3588408/IT+Sicherheit/Cybersecurity+Nachrichten/OpenClaw+AI+Agent+Leaks+Sensitive+Credentials+in+New+Phishing+Attack+Simulation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588408/IT+Sicherheit/Cybersecurity+Nachrichten/OpenClaw+AI+Agent+Leaks+Sensitive+Credentials+in+New+Phishing+Attack+Simulation/</guid>
<pubDate>Wed, 10 Jun 2026 18:55:51 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FIFA WM 2026: 19.000 Fake-Domains und KI-Phishing bedrohen Fans - BornCity]]></title> 
<description><![CDATA[KI und QR-Codes: Die neuen Waffen der Hacker. Seit Januar 2026 haben Kriminelle &uuml;ber 10.000 neue WM-bezogene Internetadressen registriert &ndash; rund 2.000&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3588329/IT+Sicherheit/Hacker/FIFA+WM+2026%3A+19.000+Fake-Domains+und+KI-Phishing+bedrohen+Fans+-+BornCity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588329/IT+Sicherheit/Hacker/FIFA+WM+2026%3A+19.000+Fake-Domains+und+KI-Phishing+bedrohen+Fans+-+BornCity/</guid>
<pubDate>Wed, 10 Jun 2026 17:50:59 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cybersecurity Software Fails to Detect Fifth of Brower-Based Phishing Attacks]]></title> 
<description><![CDATA[Menlo Security research warns that as enterprise applications become increasingly browser based, traditional cybersecurity tools leave them vulnerable to cyber threats ]]></description>
<link>https://tsecurity.de/de/3588190/IT+Sicherheit/Cybersecurity+Nachrichten/Cybersecurity+Software+Fails+to+Detect+Fifth+of+Brower-Based+Phishing+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588190/IT+Sicherheit/Cybersecurity+Nachrichten/Cybersecurity+Software+Fails+to+Detect+Fifth+of+Brower-Based+Phishing+Attacks/</guid>
<pubDate>Wed, 10 Jun 2026 17:30:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cybersecurity Software Fails to Detect Fifth of Brower-Based Phishing Attacks]]></title> 
<description><![CDATA[Menlo Security research warns that as enterprise applications become increasingly browser based, traditional cybersecurity tools leave them vulnerable to cyber threats This article has been indexed from www.infosecurity-magazine.com Read the original article: Cybersecurity Software Fails to Detect Fifth of Brower-Based&hellip;
Read more &rarr;
The post Cybersecurity Software Fails to Detect Fifth of Brower-Based Phishing Attacks appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3588187/IT+Sicherheit/Cybersecurity+Nachrichten/Cybersecurity+Software+Fails+to+Detect+Fifth+of+Brower-Based+Phishing+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588187/IT+Sicherheit/Cybersecurity+Nachrichten/Cybersecurity+Software+Fails+to+Detect+Fifth+of+Brower-Based+Phishing+Attacks/</guid>
<pubDate>Wed, 10 Jun 2026 17:34:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing: Banken nutzen halbseidene Domains]]></title> 
<description><![CDATA[Namhafte Banken wie die Sparkassen warnen zwar vor Phishing, nutzen aber selbst Phishing-artige Domains. Es ginge sicher besser. ]]></description>
<link>https://tsecurity.de/de/3587765/IT+Nachrichten/Phishing%3A+Banken+nutzen+halbseidene+Domains/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587765/IT+Nachrichten/Phishing%3A+Banken+nutzen+halbseidene+Domains/</guid>
<pubDate>Wed, 10 Jun 2026 14:57:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials]]></title> 
<description><![CDATA[A new Browser-in-the-Browser (BitB) phishing campaign is targeting Microsoft 365 users with fake login popups designed to closely mimic legitimate browser authentication windows, according to Palo Alto Networks Unit 42. The attack relies on a fake browser window embedded within a webpage. Victims who click a Microsoft sign-in button are presented with what appears to be a standard authentication prompt, complete with a spoofed Microsoft OAuth URL and a login form. Phishing page displaying a &hellip; More &rarr;
The post New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials appeared first on Help Net Security. ]]></description>
<link>https://tsecurity.de/de/3587716/IT+Sicherheit/Cybersecurity+Nachrichten/New+Browser-in-the-Browser+phishing+uses+fake+login+popups+to+steal+Microsoft+365+credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587716/IT+Sicherheit/Cybersecurity+Nachrichten/New+Browser-in-the-Browser+phishing+uses+fake+login+popups+to+steal+Microsoft+365+credentials/</guid>
<pubDate>Wed, 10 Jun 2026 14:53:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing: Banken nutzen halbseidene Domains]]></title> 
<description><![CDATA[Namhafte Banken wie die Sparkassen warnen zwar vor Phishing, nutzen aber selbst Phishing-artige Domains. Es ginge sicher besser. ]]></description>
<link>https://tsecurity.de/de/3587714/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing%3A+Banken+nutzen+halbseidene+Domains/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587714/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing%3A+Banken+nutzen+halbseidene+Domains/</guid>
<pubDate>Wed, 10 Jun 2026 14:57:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials]]></title> 
<description><![CDATA[A new Browser-in-the-Browser (BitB) phishing campaign is targeting Microsoft 365 users with fake login popups designed to closely mimic legitimate browser authentication windows, according to Palo Alto Networks Unit 42. The attack relies on a fake browser window embedded within&hellip;
Read more &rarr;
The post New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3587704/IT+Sicherheit/Cybersecurity+Nachrichten/New+Browser-in-the-Browser+phishing+uses+fake+login+popups+to+steal+Microsoft+365+credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587704/IT+Sicherheit/Cybersecurity+Nachrichten/New+Browser-in-the-Browser+phishing+uses+fake+login+popups+to+steal+Microsoft+365+credentials/</guid>
<pubDate>Wed, 10 Jun 2026 15:05:28 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FIFA World Cup 2026 Scams Are Already Active: Fake Domains, Phishing Sites, and How to Stay Safe]]></title> 
<description><![CDATA[

The FIFA World Cup 2026 kicks off on June 11, and the world&#039;s biggest sporting event is drawing more than just fans &mdash; it is already attracting a wave of cybercriminals targeting ticket buyers, job seekers, streaming viewers, and corporate brands alike.&nbsp;


The FBI has issued a formal Public Service Announcement warning that threat actors are creating fraudulent versions of FIFA-affiliated websites to steal personal information, conduct financial fraud, and sell fake products and services.&nbsp;Cyble&nbsp;researchers independently analyzed the domains flagged by the FBI and confirmed that many remained active and operational at the time of publishing this report.&nbsp;


With 48 teams, 16 host cities across the United States, Canada, and Mexico, and an estimated global audience of billions, the FIFA World Cup 2026 is set to be the largest men&#039;s World Cup in history. That scale is precisely why&nbsp;cybercriminals&nbsp;are prying on&nbsp;it &mdash; and why the threat is arriving earlier and more aggressively than in&nbsp;previous&nbsp;tournaments.&nbsp;


How FIFA World Cup 2026 Scams Work&nbsp;


The FBI warns that threat actors are building fraudulent versions of FIFA&#039;s official website,&nbsp;www.fifa.com, designed to closely mimic the legitimate experience. These sites are engineered to collect personally identifiable information (PII), including full names, home addresses, phone numbers, email addresses, banking information, and payment card details.&nbsp;


The same fraudulent infrastructure is used to run a range of operations simultaneously:&nbsp;FIFA ticket&nbsp;scams, fake hospitality package sales, fraudulent job listings, and other forms of financial fraud.&nbsp;


The most common technical method is&nbsp;typosquatting&nbsp;&mdash; registering domains with subtle spelling changes or different extensions that trick users into believing they have landed on an official page. A single missing letter, a swapped extension, or a hyphenated variant can be enough to deceive even vigilant users, especially when the site is dressed&nbsp;with&nbsp;FIFA branding, tournament schedules, and professional-looking navigation menus.&nbsp;


The FBI flagged the following domains as fraudulent FIFA-related sites:&nbsp;






&nbsp;
&nbsp;


www.fifa[.]cab&nbsp;
www.fifa[.]pink&nbsp;


www.fifa[.]blue&nbsp;
www.fifa[.]pub&nbsp;


FIFA[.]city&nbsp;
Fifa[.]bio&nbsp;


fifa[.]beer&nbsp;
fifa[.]click&nbsp;


fifa[.]cam&nbsp;
fifa[.]ceo&nbsp;


fifa[.]help&nbsp;
filfa[.]org&nbsp;


fifa-online[.]com&nbsp;
https://fifa-2026[.]xyz&nbsp;


jobs-fifa[.]com&nbsp;
fifa-hr[.]com&nbsp;


fifa-careerhub[.]com&nbsp;
fifaworldcup-careers[.]com&nbsp;


fifa-hiring[.]com&nbsp;
fifahiring[.]com&nbsp;


fifa-ticket[.]live&nbsp;
fifastore.us[.]com&nbsp;


fifaworldcup26[.]sale&nbsp;
fifaworldcup26.xcover-staging[.]com&nbsp;


worldcup2026-tickets.com[.]mx&nbsp;
worldcup26ticket[.]com&nbsp;


2026fifaworldcuptickets[.]online&nbsp;
fwc2026[.]net&nbsp;


fwc2026.web[.]app&nbsp;
www.fifa2026p[.]com&nbsp;


fifa2026fworldcup[.]com&nbsp;
wvvw-fifa[.]com&nbsp;


ww-fifa[.]com&nbsp;
fifa-com[.]com&nbsp;


www.fifa-com[.]services&nbsp;
quiniela-fifa-2026.pages[.]dev&nbsp;






Source: FBI PSA &mdash; Domains defanged for safety&nbsp;


Cyble&nbsp;researchers tracked these domains and confirmed that many were still operational at the time of publishing. Notably, even when a&nbsp;malicious&nbsp;domain is taken down, new ones tend to appear&nbsp;almost instantaneously. The fraudulent infrastructure is not a one-time campaign &mdash; it&nbsp;is continuously regenerating.&nbsp;


Fake FIFA Hospitality, Ticket, and Sale Sites&nbsp;


One of the most convincing examples&nbsp;identified&nbsp;by&nbsp;Cyble&nbsp;researchers was&nbsp;ww-fifa[.]com&nbsp;&mdash; a classic&nbsp;typosquatting&nbsp;attack that removes a single &quot;w&quot; from the legitimate FIFA URL. The site presents itself as an official FIFA World Cup 2026 portal, complete with tournament branding, navigation menus, ticket information, and hospitality package offers.&nbsp;


Fake FIFA World Cup 2026 Hospitality Domain (Source:&nbsp;Cyble)


Visitors to this site are encouraged to&nbsp;purchase&nbsp;premium packages that include tickets, food, beverages, lounge access, and related services &mdash; all fraudulent.&nbsp;


Cyble&nbsp;researchers&nbsp;identified&nbsp;several indicators that expose the site as illegitimate:&nbsp;



Duplicate page titles appearing twice in the browser tab&nbsp;




Missing or broken images throughout the site&nbsp;




Navigation links leading to attacker-controlled pages&nbsp;




Ticket purchase prompts requesting personal and financial information with no legitimate payment processing&nbsp;



What makes these sites especially dangerous&nbsp;is the sophistication of the presentation. Unlike the crude phishing pages of a decade ago, modern FIFA 2026&nbsp;scam&nbsp;sites replicate the visual design of official sports portals convincingly enough to pass a casual inspection.&nbsp;


Security Vendors Have Already Flagged FIFA-Related Domains&nbsp;


Cyble&nbsp;researchers analyzed the domain&nbsp;fifa[.]help&nbsp;using&nbsp;VirusTotal&nbsp;and found that, at the time of analysis,&nbsp;15 out of 92 security vendors&nbsp;had classified it as malicious. Vendor classifications included phishing, fraud, and related threat categories.&nbsp;


Fake FIFA 2026 domain&nbsp;scoring (Source:&nbsp;VirusTotal)


While a detection rate of 15/92 may seem modest, it&nbsp;represents&nbsp;significant early-stage flagging. Many security vendors lag in classifying newly registered domains, so the fact that multiple established providers had already flagged this domain confirms a credible&nbsp;threat.&nbsp;&nbsp;


As these domains age and accumulate more malicious activity reports, detection rates will rise &mdash; but by then, victims will already have been targeted.&nbsp;


Fake FIFA Recruitment Sites Are Also Active&nbsp;


Not all FIFA World Cup 2026&nbsp;scams&nbsp;target ticket buyers or fans.&nbsp;Cyble&nbsp;researchers&nbsp;identified&nbsp;an entirely separate fraud vector targeting job seekers: the domain&nbsp;fifaworldcup-careers[.]com, which presents itself as a FIFA employment portal for World Cup-related positions.&nbsp;


Subdomain related to&nbsp;fifaworldcup-careers[.]com (Source:&nbsp;VirusTotal)


VirusTotal&nbsp;data revealed:&nbsp;



www.fifaworldcup-careers[.]com&nbsp;was flagged by&nbsp;8 out of 91 vendors&nbsp;




The root domain was flagged by&nbsp;14 out of 91 vendors&nbsp;




The domain resolved to multiple IP addresses, including 3.71.180.249, 13.249.91.65, and 13.249.91.101&nbsp;



The use of multiple IP addresses suggests the domain may be&nbsp;operating&nbsp;behind content delivery or load-balancing infrastructure, which makes takedowns significantly more difficult to execute.&nbsp;


WHOIS data shows the domain was registered and updated in mid-to-late April 2026, with the registrant&#039;s identity hidden behind a privacy shield. Two SSL certificates were also issued on April 15 and April 16, including a wildcard certificate covering *.fifaworldcup-careers[.]com &mdash; a sign of deliberate, technically capable infrastructure setup rather than an opportunistic amateur operation.&nbsp;


Why this matters:&nbsp;Job seekers searching for World Cup-related employment &mdash; hospitality roles, security staff, event coordinators, media positions &mdash; are a highly vulnerable and&nbsp;largely overlooked&nbsp;audience. These individuals are&nbsp;not on guard for&nbsp;ticket&nbsp;scams; they are in application mode, and&nbsp;they will&nbsp;willingly&nbsp;submit&nbsp;full personal information, resumes, and even government ID to what they believe is a legitimate employer.&nbsp;


How to Avoid FIFA World Cup 2026 Ticket Scams&nbsp;


As fans search for how to watch the FIFA World Cup 2026 or purchase tickets, the FBI recommends the following precautions:&nbsp;



Type&nbsp;fifa.com&nbsp;directly into your browser&#039;s address bar &mdash; never rely on search results or links in messages&nbsp;




Avoid sponsored search results, which can be&nbsp;purchased&nbsp;by attackers to appear above legitimate results&nbsp;




Confirm that the URL is exactly&nbsp;www.fifa.com&nbsp;before entering any information&nbsp;




Use saved bookmarks or browser favorites when revisiting FIFA websites&nbsp;




Access FIFA subdomains only through the official homepage, not by typing them directly&nbsp;




Be cautious of websites with broken graphics, poor-quality branding, or duplicate content&nbsp;




Do not provide sensitive information unless the site&#039;s legitimacy has been independently verified&nbsp;




Review URLs carefully before clicking any advertisements&nbsp;



These steps are especially important for avoiding FIFA 2026 ticket price&nbsp;scams, where attackers create a false sense of urgency through fake discounts, exclusive hospitality&nbsp;offers, or&nbsp;limited-time&nbsp;deals that pressure users into making fast payment decisions.&nbsp;


How to Watch FIFA World Cup 2026 Safely&nbsp;


Scammers are targeting not only ticket buyers but viewers as well. Fraudulent streaming platforms are expected to proliferate as the tournament approaches, exploiting the high demand for match access &mdash; particularly from fans in regions where official broadcasts are expensive or limited.&nbsp;


To reduce risk when looking for FIFA World Cup 2026 streaming options:&nbsp;



Use only official FIFA channels and licensed regional broadcasters for tournament information&nbsp;




Watch matches exclusively through broadcasters licensed for your region&nbsp;




Avoid streaming links shared through unsolicited emails, social media messages, or WhatsApp groups&nbsp;




Verify URLs carefully before creating accounts or entering any payment information&nbsp;




Be cautious of websites offering heavily discounted subscription packages or &quot;exclusive&quot; access to all matches&nbsp;



Many fake streaming platforms use the same tactics seen in&nbsp;FIFA ticket&nbsp;scams: they exploit demand for tournament content to harvest personal and financial information, either&nbsp;immediately&nbsp;or through credential-stuffing attacks down the line.&nbsp;


What To Do If You Become a Victim of a FIFA World Cup 2026 Scam&nbsp;


The FBI expects&nbsp;additional&nbsp;spoofed domains to appear throughout the tournament period &mdash; before, during, and after matches. If you&nbsp;encounter&nbsp;a suspected FIFA World Cup 2026&nbsp;scam, document as much information as possible before the site disappears, including:&nbsp;



The fraudulent domain name&nbsp;




Screenshots of the website&nbsp;




Any communication records (emails, SMS, chat logs)&nbsp;




Payment details if a transaction occurred&nbsp;




Cryptocurrency wallet addresses, if applicable&nbsp;



Victims can file a complaint with the&nbsp;Internet Crime Complaint Center (IC3) at ic3.gov&nbsp;and should include the fake domain involved, details of all interactions with the site, information&nbsp;submitted&nbsp;to the scammers, payment records, receiving financial institution information, and any&nbsp;cryptocurrency&nbsp;transaction details.&nbsp;


Reporting promptly not only helps your case but also contributes to the broader effort to get these domains flagged and taken down faster.&nbsp;


Protect Your Brand from Fake FIFA World Cup 2026 Phishing Campaigns&nbsp;


Major global events like the FIFA World Cup create a concentrated window of opportunity for cybercriminals to launch phishing campaigns, register fraudulent domains, and impersonate trusted brands. As the active FIFA-related&nbsp;scam&nbsp;infrastructure&nbsp;identified&nbsp;by&nbsp;Cyble&nbsp;researchers&nbsp;demonstrates, this is not a theoretical risk &mdash; it is a live and expanding threat landscape.&nbsp;


Organizations&nbsp;operating&nbsp;in travel, hospitality, ticketing, media, and any sector&nbsp;adjacent to&nbsp;the FIFA World Cup 2026 need proactive&nbsp;brand protection&nbsp;measures in place now &mdash; not after the first incident.&nbsp;





Cyble&#039;s Brand Intelligence solution&nbsp;helps organizations detect malicious domains,&nbsp;phishing websites, brand impersonation attempts, and other forms of digital abuse in real time. Combined with&nbsp;Dark Web&nbsp;and Cyber Crime Monitoring and Takedown &amp; Disruption services, security teams can&nbsp;identify&nbsp;threats early, investigate malicious activity, and accelerate the removal of fraudulent infrastructure before it causes financial or reputational damage.&nbsp;


Don&#039;t&nbsp;react &mdash; deploy now.&nbsp;


Check out how&nbsp;Cyble&nbsp;helps organizations detect,&nbsp;monitor, and&nbsp;disrupt&nbsp;phishing&nbsp;campaigns, fraudulent domains, and brand abuse before&nbsp;they lead to&nbsp;financial loss&nbsp;or reputational damage.&nbsp;


Frequently Asked Questions&nbsp;




1.&nbsp;How do I know if a FIFA World Cup 2026 ticket website is legitimate?
The only official platform for FIFA World Cup 2026 tickets is accessible through&nbsp;www.fifa.com. Always type this address directly into your browser. Legitimate FIFA ticket pages will never ask you to log in through a third-party site or pay via cryptocurrency or wire transfer.&nbsp;


2.&nbsp;Are FIFA World Cup 2026 jobs being posted on fake websites?
Yes.&nbsp;Cyble&nbsp;researchers&nbsp;identified&nbsp;at least one domain &mdash;&nbsp;fifaworldcup-careers[.]com &mdash; that impersonates a FIFA employment portal targeting job seekers for World Cup positions. Always verify any job listing through the official FIFA website or a recognized recruitment agency.&nbsp;


3.&nbsp;What should I do if I accidentally visited a fake FIFA site?&nbsp;&nbsp;
Do not enter any personal information. Close the browser tab&nbsp;immediately. If you&nbsp;already&nbsp;entered information, change any reused passwords,&nbsp;monitor&nbsp;your financial accounts for unusual activity, and file a report at ic3.gov.&nbsp;


4.&nbsp;Can I safely use Google to search for FIFA World Cup 2026 tickets?&nbsp;&nbsp;
You can&nbsp;search, but&nbsp;be cautious. The FBI specifically warns against clicking sponsored search results, which attackers can&nbsp;purchase&nbsp;to appear at the top of results pages. Always manually navigate to&nbsp;www.fifa.com&nbsp;after your search rather than clicking links.&nbsp;


5.&nbsp;How many fake FIFA 2026 domains are there?&nbsp;&nbsp;
The FBI flagged over 40 fraudulent domains in its PSA.&nbsp;Cyble&nbsp;researchers confirmed that many of these&nbsp;remain&nbsp;active. Given that new fraudulent domains are registered continuously, the actual number of fake FIFA-related domains in circulation is expected to grow significantly as the tournament approaches.&nbsp;



The post FIFA World Cup 2026 Scams Are Already Active: Fake Domains, Phishing Sites, and How to Stay Safe appeared first on Cyble. ]]></description>
<link>https://tsecurity.de/de/3587597/IT+Sicherheit/Cybersecurity+Nachrichten/FIFA+World+Cup+2026+Scams+Are+Already+Active%3A+Fake+Domains%2C+Phishing+Sites%2C+and+How+to+Stay+Safe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587597/IT+Sicherheit/Cybersecurity+Nachrichten/FIFA+World+Cup+2026+Scams+Are+Already+Active%3A+Fake+Domains%2C+Phishing+Sites%2C+and+How+to+Stay+Safe/</guid>
<pubDate>Wed, 10 Jun 2026 14:10:37 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Autonomous AI agents duped into leaking sensitive data in phishing test]]></title> 
<description><![CDATA[
		
					  
						




AI agents given access to corporate email and business applications could become a new phishing target for attackers, according to cybersecurity researchers, after a test agent built on OpenClaw was tricked into sharing cloud credentials and customer data with an external attacker.



Varonis Threat Labs said it built an OpenClaw AI agent called Pinchy to test whether autonomous agents could fall for the same kinds of phishing attacks that have long targeted employees. Varonis tested the agent in a controlled Google Workspace environment, giving it access to a Gmail inbox with mock AWS credentials, CRM exports, internal conversations, and calendar invites.



The test used two configurations: a generic productivity profile and a stricter profile that included email safety instructions telling the agent to be cautious of phishing and verify sender identities before acting on sensitive requests. Varonis said the agent still failed in some scenarios, particularly when requests appeared to come from colleagues and were framed as routine or urgent business tasks.



&ldquo;In some cases, Pinchy not only failed at spotting the phishing attacks, it also performed risky actions that could potentially compromise a real-world organization,&rdquo; the cybersecurity firm said in its report.



In one test, Pinchy forwarded AWS IAM keys, database passwords, and SSH access details to an external Gmail account after receiving what appeared to be a routine request from a colleague for staging credentials.



In another test, an attacker asked the agent to send the latest customer export for a quarterly business review presentation. Pinchy retrieved and forwarded a CRM export containing details on 247 enterprise customers, including company names, contact information, contract dates, customer tiers, and roughly $1.28 million in monthly recurring revenue data.



But the results were not entirely negative. According to Varonis, the agent performed better against more technical phishing attempts, including a malicious OAuth consent flow disguised as a timesheet platform. In that case, Pinchy inspected the redirect address, identified the destination as suspicious, and stopped before granting consent.



&ldquo;That contrast is what makes the earlier failures structurally important,&rdquo; Varonis said. &ldquo;The agent had enough technical reasoning to recognize sophisticated phishing infrastructure. The weak point was social trust and identity verification.&rdquo;



The findings come as companies move AI agents beyond chat interfaces and into workflows where they can retrieve documents, process messages, and act across business software.



An architecture problem



The OpenClaw test points less to a failure of the AI model itself than to the way the agent was configured and deployed, said Devashri Datta, a cybersecurity researcher.



&ldquo;The security tests actually proved that the AI models did their jobs well on a purely technical level,&rdquo; Datta said.



The bigger problem was that the agent treated email as both a source of information and a source of instructions, creating what Datta described as a classic IT mistake: mixing the data lane with the control lane.



&ldquo;It didn&rsquo;t hand over a password because someone asked nicely; it executed what looked like a legitimate operational task,&rdquo; Datta said. &ldquo;In any secure system, you never let the data path give administrative orders.&rdquo;



Other analysts said the model should not be taken out of the equation entirely. The risk is not confined to one layer of the technology stack, said Keith Prabhu, founder and CEO at Confidis. The test showed problems in the model&rsquo;s ability to judge trust and in the way agent frameworks and enterprise governance handled autonomous access.



&ldquo;Historically, security architectures segregate any orchestration pipeline into authorization, execution, auditing, and escalation,&rdquo; Prabhu said. &ldquo;However, this is collapsed into one single pipeline in AI agents, which may lead to them becoming victims of such phishing attacks.&rdquo;



Enterprises need enforceable controls



Enterprises should treat AI agents as high-privilege identities, because they can ingest untrusted content while also taking actions across business systems, according to Sunil Varkey, a cybersecurity adviser and former CISO.



That combination raises the stakes for enterprises, particularly when agents can read emails, documents, web pages, and SaaS comments while also sending messages, exporting data, calling APIs or updating records, he said.



&ldquo;Frameworks like OpenClaw often lack robust enforcement of identity verification, tool-level permissions, and resistance to prompt injection,&rdquo; Varkey said. &ldquo;However, the decisive factor in the Varonis tests was over-privileged access, missing human oversight, and absent runtime guardrails.&rdquo;



Akshat Tyagi, associate practice leader at HFS Research, said enterprises should focus not only on what an agent can access, but also on what it is allowed to send outside the organization.



&ldquo;Instructions are not controls,&rdquo; Tyagi said. &ldquo;If an agent can email sensitive data outside the company just because someone asked convincingly, the problem is not the model alone.&rdquo;



AI agents should have their own identities, with access that can be limited and monitored, Tyagi said. Requests involving credentials or customer data sharing should trigger human review rather than be left to the agent&rsquo;s judgment.
 ]]></description>
<link>https://tsecurity.de/de/3587361/IT+Sicherheit/Cybersecurity+Nachrichten/Autonomous+AI+agents+duped+into+leaking+sensitive+data+in+phishing+test/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587361/IT+Sicherheit/Cybersecurity+Nachrichten/Autonomous+AI+agents+duped+into+leaking+sensitive+data+in+phishing+test/</guid>
<pubDate>Wed, 10 Jun 2026 12:45:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tax Phishing Emails Deliver In-Memory Malware to Windows Systems]]></title> 
<description><![CDATA[Cybercriminals are leveraging tax-themed phishing emails to deploy sophisticated in-memory malware on Windows systems, bypassing traditional disk-based detection mechanisms. The attack cascade begins when victims receive phishing emails containing malicious attachments disguised as official tax documents, W-2 forms, or rejected tax form notifications from legitimate entities like Intuit QuickBooks or HM Revenue &amp; Customs. When [&hellip;]
The post Tax Phishing Emails Deliver In-Memory Malware to Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3587235/IT+Sicherheit/Cybersecurity+Nachrichten/Tax+Phishing+Emails+Deliver+In-Memory+Malware+to+Windows+Systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587235/IT+Sicherheit/Cybersecurity+Nachrichten/Tax+Phishing+Emails+Deliver+In-Memory+Malware+to+Windows+Systems/</guid>
<pubDate>Wed, 10 Jun 2026 11:55:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tax Phishing Emails Deliver In-Memory Malware to Windows Systems]]></title> 
<description><![CDATA[Cybercriminals are leveraging tax-themed phishing emails to deploy sophisticated in-memory malware on Windows systems, bypassing traditional disk-based detection mechanisms. The attack cascade begins when victims receive phishing emails containing malicious attachments disguised as official tax documents, W-2 forms, or rejected&hellip;
Read more &rarr;
The post Tax Phishing Emails Deliver In-Memory Malware to Windows Systems appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3587227/IT+Sicherheit/Cybersecurity+Nachrichten/Tax+Phishing+Emails+Deliver+In-Memory+Malware+to+Windows+Systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587227/IT+Sicherheit/Cybersecurity+Nachrichten/Tax+Phishing+Emails+Deliver+In-Memory+Malware+to+Windows+Systems/</guid>
<pubDate>Wed, 10 Jun 2026 12:03:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Meta fordert Gerichtsbeschluss gegen NSO wegen neuer WhatsApp-Phishingversuche]]></title> 
<description><![CDATA[WASHINGTON / LONDON (IT BOLTWISE) &ndash; Meta versucht erneut, NSO Group juristisch zu stoppen: Nach Berichten &uuml;ber einen spear-phishing-angriff mit NSO-Bezug fordert das Unternehmen einen Contempt-Vorwurf vor Gericht. Im Kern geht es um die Frage, ob kommerzielle &Uuml;berwachungssoftware auch dann noch Messaging-Apps gef&auml;hrdet, wenn Gerichte formell Verbote aussprechen. Meta betont zugleich, dass WhatsApp die Kampagne [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;Meta fordert Gerichtsbeschluss gegen NSO wegen neuer WhatsApp-Phishingversuche&laquo; lesen
Dieser Beitrag Meta fordert Gerichtsbeschluss gegen NSO wegen neuer WhatsApp-Phishingversuche erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3586872/IT+Sicherheit/Cybersecurity+Nachrichten/Meta+fordert+Gerichtsbeschluss+gegen+NSO+wegen+neuer+WhatsApp-Phishingversuche/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586872/IT+Sicherheit/Cybersecurity+Nachrichten/Meta+fordert+Gerichtsbeschluss+gegen+NSO+wegen+neuer+WhatsApp-Phishingversuche/</guid>
<pubDate>Wed, 10 Jun 2026 10:08:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Meta warnt vor erneutem NSO-ähnlichem WhatsApp-Spear-Phishing und stärkt Kontosperren]]></title> 
<description><![CDATA[LONDON (IT BOLTWISE) &ndash; Meta meldet erneut blockierte Spear-Phishing-Versuche im WhatsApp-Umfeld, die mit dem israelischen Spyware-Anbieter NSO Group in Verbindung stehen. Gleichzeitig geht das Unternehmen per Gerichtsantrag gegen NSO Group vor, weil eine fr&uuml;here Verf&uuml;gung das Anvisieren von WhatsApp untersagte. F&uuml;r Nutzer empfiehlt Meta, Apps aktuell zu halten und &bdquo;Strict account settings&ldquo; zu aktivieren, um [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;Meta warnt vor erneutem NSO-&auml;hnlichem WhatsApp-Spear-Phishing und st&auml;rkt Kontosperren&laquo; lesen
Dieser Beitrag Meta warnt vor erneutem NSO-&auml;hnlichem WhatsApp-Spear-Phishing und st&auml;rkt Kontosperren erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3586806/IT+Sicherheit/Cybersecurity+Nachrichten/Meta+warnt+vor+erneutem+NSO-%C3%A4hnlichem+WhatsApp-Spear-Phishing+und+st%C3%A4rkt+Kontosperren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586806/IT+Sicherheit/Cybersecurity+Nachrichten/Meta+warnt+vor+erneutem+NSO-%C3%A4hnlichem+WhatsApp-Spear-Phishing+und+st%C3%A4rkt+Kontosperren/</guid>
<pubDate>Wed, 10 Jun 2026 09:25:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tax-Themed Phishing Emails Deliver In-Memory Malware to Windows Users]]></title> 
<description><![CDATA[Cybersecurity researchers have uncovered a highly sophisticated phishing campaign that uses tax-themed emails to deliver advanced in-memory malware to Windows users. The malicious operation relies heavily on social engineering and government impersonation to trick victims into compromising their own systems. Cyfirma threat analysts recently detailed this multi-stage attack framework, highlighting its ability to bypass conventional [&hellip;]
The post Tax-Themed Phishing Emails Deliver In-Memory Malware to Windows Users appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3586805/IT+Sicherheit/Cybersecurity+Nachrichten/Tax-Themed+Phishing+Emails+Deliver+In-Memory+Malware+to+Windows+Users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586805/IT+Sicherheit/Cybersecurity+Nachrichten/Tax-Themed+Phishing+Emails+Deliver+In-Memory+Malware+to+Windows+Users/</guid>
<pubDate>Wed, 10 Jun 2026 09:25:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[OpenClaw AI Agent Leaks Credentials in Phishing Simulation]]></title> 
<description><![CDATA[Autonomous email agents can become high‑impact phishing victims, leaking cloud credentials and sensitive business data even when wrapped in explicit safety instructions. In a controlled lab deployment on the OpenClaw agent platform, an AI agent dubbed &ldquo;Pinchy&rdquo; failed multiple classic&hellip;
Read more &rarr;
The post OpenClaw AI Agent Leaks Credentials in Phishing Simulation appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3586800/IT+Sicherheit/Cybersecurity+Nachrichten/OpenClaw+AI+Agent+Leaks+Credentials+in+Phishing+Simulation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586800/IT+Sicherheit/Cybersecurity+Nachrichten/OpenClaw+AI+Agent+Leaks+Credentials+in+Phishing+Simulation/</guid>
<pubDate>Wed, 10 Jun 2026 09:34:24 +0200</pubDate>
</item>
<item> 
<title><![CDATA[OpenClaw AI Agent Leaks Credentials in Phishing Simulation]]></title> 
<description><![CDATA[Autonomous email agents can become high‑impact phishing victims, leaking cloud credentials and sensitive business data even when wrapped in explicit safety instructions. In a controlled lab deployment on the OpenClaw agent platform, an AI agent dubbed &ldquo;Pinchy&rdquo; failed multiple classic phishing simulations, including one in which it forwarded AWS IAM keys, database passwords, and SSH [&hellip;]
The post OpenClaw AI Agent Leaks Credentials in Phishing Simulation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3586774/IT+Sicherheit/Cybersecurity+Nachrichten/OpenClaw+AI+Agent+Leaks+Credentials+in+Phishing+Simulation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586774/IT+Sicherheit/Cybersecurity+Nachrichten/OpenClaw+AI+Agent+Leaks+Credentials+in+Phishing+Simulation/</guid>
<pubDate>Wed, 10 Jun 2026 09:18:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Researchers Expose OpenClaw AI Agent Credential Leak During Phishing Simulation]]></title> 
<description><![CDATA[AI agents are rapidly taking over enterprise inboxes to triage emails, pull internal data, and automate replies. However, placing autonomous systems in the most vulnerable part of an organization comes with serious risks. A new 2026 report from Varonis Threat Labs reveals that AI agents can easily fall for the same phishing tricks that target [&hellip;]
The post Researchers Expose OpenClaw AI Agent Credential Leak During Phishing Simulation appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3586771/IT+Sicherheit/Cybersecurity+Nachrichten/Researchers+Expose+OpenClaw+AI+Agent+Credential+Leak+During+Phishing+Simulation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586771/IT+Sicherheit/Cybersecurity+Nachrichten/Researchers+Expose+OpenClaw+AI+Agent+Credential+Leak+During+Phishing+Simulation/</guid>
<pubDate>Wed, 10 Jun 2026 09:24:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[phishing, fraud, cyber security, hacking, steal, crime, scam, cyber, security, hacker, thief ...]]></title> 
<description><![CDATA[phishing, fraud, cyber security, hacking, steal, crime, scam, cyber, security, hacker, thief, password, attack, theft, identity, information,&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3586630/IT+Sicherheit/Hacker/phishing%2C+fraud%2C+cyber+security%2C+hacking%2C+steal%2C+crime%2C+scam%2C+cyber%2C+security%2C+hacker%2C+thief+.../</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586630/IT+Sicherheit/Hacker/phishing%2C+fraud%2C+cyber+security%2C+hacking%2C+steal%2C+crime%2C+scam%2C+cyber%2C+security%2C+hacker%2C+thief+.../</guid>
<pubDate>Wed, 10 Jun 2026 03:15:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[KI-Phishing überflutet SOCs: Wie Tier-1-Teams mit Beweisketten schneller triagieren]]></title> 
<description><![CDATA[LONDON (IT BOLTWISE) &ndash; KI-gest&uuml;tztes Phishing erzeugt inzwischen nicht nur mehr Angriffe, sondern auch mehr verwertbare Arbeit f&uuml;r Tier 1: Jede neue E-Mail-Variante produziert zus&auml;tzliche Alerts. Der Kerntrend lautet deshalb nicht &bdquo;mehr manuell pr&uuml;fen&ldquo;, sondern schneller zu einer belastbaren Beurteilung zu kommen. Der Beitrag zeigt, wie interaktive Sandbox-Analysen, behavior-basierte Sichtbarkeit und vorstrukturierte Escalation-Reports den SOC-Alltag [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;KI-Phishing &uuml;berflutet SOCs: Wie Tier-1-Teams mit Beweisketten schneller triagieren&laquo; lesen
Dieser Beitrag KI-Phishing &uuml;berflutet SOCs: Wie Tier-1-Teams mit Beweisketten schneller triagieren erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3586470/IT+Sicherheit/Cybersecurity+Nachrichten/KI-Phishing+%C3%BCberflutet+SOCs%3A+Wie+Tier-1-Teams+mit+Beweisketten+schneller+triagieren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586470/IT+Sicherheit/Cybersecurity+Nachrichten/KI-Phishing+%C3%BCberflutet+SOCs%3A+Wie+Tier-1-Teams+mit+Beweisketten+schneller+triagieren/</guid>
<pubDate>Wed, 10 Jun 2026 06:43:21 +0200</pubDate>
</item>
<item> 
<title><![CDATA[KI-Phishing überflutet SOCs: Tier-1-Überlast reduzieren]]></title> 
<description><![CDATA[LONDON (IT BOLTWISE) &ndash; KI-gest&uuml;tztes Phishing verwandelt jede neue Betrugsmasche in eine Flut von Alerts, die Tier 1 nur noch schwer priorisieren kann. Der Beitrag zeigt, wie SOC-Teams mit verhaltensbasierter Analyse in einer isolierten Sandbox schneller belastbare Ergebnisse gewinnen. Dazu kommt ein strukturiertes Handoff-Format f&uuml;r Tier 2 mit MITRE-ATT&amp;CK-Mapping und klaren Handlungsempfehlungen. Ziel ist, MTTR [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;KI-Phishing &uuml;berflutet SOCs: Tier-1-&Uuml;berlast reduzieren&laquo; lesen
Dieser Beitrag KI-Phishing &uuml;berflutet SOCs: Tier-1-&Uuml;berlast reduzieren erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3586444/IT+Sicherheit/Cybersecurity+Nachrichten/KI-Phishing+%C3%BCberflutet+SOCs%3A+Tier-1-%C3%9Cberlast+reduzieren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586444/IT+Sicherheit/Cybersecurity+Nachrichten/KI-Phishing+%C3%BCberflutet+SOCs%3A+Tier-1-%C3%9Cberlast+reduzieren/</guid>
<pubDate>Wed, 10 Jun 2026 06:25:23 +0200</pubDate>
</item>
<item> 
<title><![CDATA[OpenClaw AI agent found falling for phishing attacks, spills user data]]></title> 
<description><![CDATA[Phishing simulation on an OpenClaw email agent with various configuration profiles showed that it was susceptible to tactics&nbsp;commonly used to compromise human users. [...] ]]></description>
<link>https://tsecurity.de/de/3586045/IT+Sicherheit/Cybersecurity+Nachrichten/OpenClaw+AI+agent+found+falling+for+phishing+attacks%2C+spills+user+data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586045/IT+Sicherheit/Cybersecurity+Nachrichten/OpenClaw+AI+agent+found+falling+for+phishing+attacks%2C+spills+user+data/</guid>
<pubDate>Tue, 09 Jun 2026 23:20:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[New Browser-in-the-Browser Phishing Attack to Steal Microsoft 365 Logins]]></title> 
<description><![CDATA[A new and sophisticated Browser-in-the-Browser phishing campaign has been discovered targeting Microsoft 365 users, using a fake login popup that is nearly impossible to tell apart from the real thing. The attack is so convincing that even tech-savvy users can&hellip;
Read more &rarr;
The post New Browser-in-the-Browser Phishing Attack to Steal Microsoft 365 Logins appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3585611/IT+Sicherheit/Cybersecurity+Nachrichten/New+Browser-in-the-Browser+Phishing+Attack+to+Steal+Microsoft+365+Logins/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585611/IT+Sicherheit/Cybersecurity+Nachrichten/New+Browser-in-the-Browser+Phishing+Attack+to+Steal+Microsoft+365+Logins/</guid>
<pubDate>Tue, 09 Jun 2026 20:34:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[North Korean hackers are at it again — phishing scheme targets hundreds of workers to try and steal crypto and more]]></title> 
<description><![CDATA[Lazarus is getting company as UNK_DeadDrop starts luring devs with fake jobs, too. ]]></description>
<link>https://tsecurity.de/de/3585596/IT+Nachrichten/North+Korean+hackers+are+at+it+again+%E2%80%94+phishing+scheme+targets+hundreds+of+workers+to+try+and+steal+crypto+and+more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585596/IT+Nachrichten/North+Korean+hackers+are+at+it+again+%E2%80%94+phishing+scheme+targets+hundreds+of+workers+to+try+and+steal+crypto+and+more/</guid>
<pubDate>Tue, 09 Jun 2026 20:20:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[New Browser-in-the-Browser Phishing Attack to Steal Microsoft 365 Logins]]></title> 
<description><![CDATA[A new and sophisticated Browser-in-the-Browser phishing campaign has been discovered targeting Microsoft 365 users, using a fake login popup that is nearly impossible to tell apart from the real thing. The attack is so convincing that even tech-savvy users can fall for it without realizing their credentials have been stolen. The campaign works by embedding [&hellip;]
The post New Browser-in-the-Browser Phishing Attack to Steal Microsoft 365 Logins appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3585497/IT+Sicherheit/Cybersecurity+Nachrichten/New+Browser-in-the-Browser+Phishing+Attack+to+Steal+Microsoft+365+Logins/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585497/IT+Sicherheit/Cybersecurity+Nachrichten/New+Browser-in-the-Browser+Phishing+Attack+to+Steal+Microsoft+365+Logins/</guid>
<pubDate>Tue, 09 Jun 2026 19:59:56 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Industry Perspective by Cloudflare: Dismantling Tycoon 2FA, Inside a Global Phishing Takedown]]></title> 
<description><![CDATA[Author: natoccdcoe - Bewertung: 0x - Views:0 CyCon 2026 |  Session by Michiel Appelman, Principal Solutions Engineer, Cloudflare

In March 2026, Cloudflare coordinated with Microsoft and Europol to dismantle Tycoon 2FA, one of the most widely used phishing-as-a-service platforms. For $120 a month, any criminal could subscribe. The operation took down 24,000 domains and the serverless infrastructure that let the kit proxy live authentication sessions. Multi-factor authentication was useless against it.

This session uses the takedown as a lens into broader shifts in adversary operations. Tycoon 2FA did not succeed through technical sophistication. It succeeded because it&#039;s optimized for what Cloudflare&#039;s threat intelligence team calls the &quot;Measure of Effectiveness&quot; - the ratio of effort to outcome. The same logic explains why Chinese state actors now route command-and-control through Google Calendar, why session token theft has overtaken zero-day exploits as the primary access method, and why nation-state groups are pre-positioning inside critical infrastructure using tools that look identical to normal enterprise traffic.

#CCDCOE #CyCon2026 ]]></description>
<link>https://tsecurity.de/de/3585457/IT+Sicherheit/Cybersecurity+Videos/Industry+Perspective+by+Cloudflare%3A+Dismantling+Tycoon+2FA%2C+Inside+a+Global+Phishing+Takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585457/IT+Sicherheit/Cybersecurity+Videos/Industry+Perspective+by+Cloudflare%3A+Dismantling+Tycoon+2FA%2C+Inside+a+Global+Phishing+Takedown/</guid>
<pubDate>Tue, 09 Jun 2026 19:36:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[IONOS-Phishing-Welle: "SEPA-Lastschrift fehlgeschlagen"]]></title> 
<description><![CDATA[Kurzer Hinweis f&uuml;r Nutzer, die irgend einen Vertrag bei IONOS / 1&amp;1 haben. Ein Leser hat mich darauf hingewiesen, dass es zum 8. Juni 2026 eine massive Phishing-Welle gab, die bei deren E-Mail-Postf&auml;chern eingeschlagen ist. Es wird in einer Meldung &hellip; Weiterlesen &rarr;
Quelle ]]></description>
<link>https://tsecurity.de/de/3584986/IT+Nachrichten/IONOS-Phishing-Welle%3A+%22SEPA-Lastschrift+fehlgeschlagen%22/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584986/IT+Nachrichten/IONOS-Phishing-Welle%3A+%22SEPA-Lastschrift+fehlgeschlagen%22/</guid>
<pubDate>Tue, 09 Jun 2026 17:20:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[New BitB Phishing Attack Targets Microsoft 365 Logins]]></title> 
<description><![CDATA[A new Browser-in-the-Browser (BitB) phishing campaign is abusing fake OAuth login windows to steal Microsoft 365 credentials, and its design is polished enough to bypass casual visual checks. The attack uses a draggable popup that mimics a real browser dialog.&hellip;
Read more &rarr;
The post New BitB Phishing Attack Targets Microsoft 365 Logins appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3584509/IT+Sicherheit/Cybersecurity+Nachrichten/New+BitB+Phishing+Attack+Targets+Microsoft+365+Logins/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584509/IT+Sicherheit/Cybersecurity+Nachrichten/New+BitB+Phishing+Attack+Targets+Microsoft+365+Logins/</guid>
<pubDate>Tue, 09 Jun 2026 14:34:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[New BitB Phishing Attack Targets Microsoft 365 Logins]]></title> 
<description><![CDATA[A new Browser-in-the-Browser (BitB) phishing campaign is abusing fake OAuth login windows to steal Microsoft 365 credentials, and its design is polished enough to bypass casual visual checks. The attack uses a draggable popup that mimics a real browser dialog. However, it is embedded in the page itself and paired with a spoofed Microsoft OAuth [&hellip;]
The post New BitB Phishing Attack Targets Microsoft 365 Logins appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3584494/IT+Sicherheit/Cybersecurity+Nachrichten/New+BitB+Phishing+Attack+Targets+Microsoft+365+Logins/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584494/IT+Sicherheit/Cybersecurity+Nachrichten/New+BitB+Phishing+Attack+Targets+Microsoft+365+Logins/</guid>
<pubDate>Tue, 09 Jun 2026 14:08:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Woche 23: Stellensuchende im Visier – Phishing, Betrug und Schadsoftware im Bewerbungsprozess]]></title> 
<description><![CDATA[Bundesamt f&uuml;r Cybersicherheit BACS. Eidgen&ouml;ssisches Departement f&uuml;r Verteidigung, Bev&ouml;lkerungsschutz und Sport VBS. Rechtliche Grundlagen. ]]></description>
<link>https://tsecurity.de/de/3584346/IT+Sicherheit/Cybersecurity+Nachrichten/Woche+23%3A+Stellensuchende+im+Visier+%E2%80%93+Phishing%2C+Betrug+und+Schadsoftware+im+Bewerbungsprozess/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584346/IT+Sicherheit/Cybersecurity+Nachrichten/Woche+23%3A+Stellensuchende+im+Visier+%E2%80%93+Phishing%2C+Betrug+und+Schadsoftware+im+Bewerbungsprozess/</guid>
<pubDate>Tue, 09 Jun 2026 12:04:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[New Browser-in-the-Browser Phishing Attack Targets Microsoft 365 Login Credentials]]></title> 
<description><![CDATA[Cybercriminals have launched a highly deceptive phishing campaign targeting Microsoft 365 users. This operation utilizes a sophisticated technique known as a Browser-in-the-Browser (BitB) attack to steal sensitive corporate data. With cloud-based operations serving as the backbone for many modern businesses, compromising a single Microsoft account can give attackers the keys to an organization&rsquo;s entire network. [&hellip;]
The post New Browser-in-the-Browser Phishing Attack Targets Microsoft 365 Login Credentials appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3584143/IT+Sicherheit/Cybersecurity+Nachrichten/New+Browser-in-the-Browser+Phishing+Attack+Targets+Microsoft+365+Login+Credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584143/IT+Sicherheit/Cybersecurity+Nachrichten/New+Browser-in-the-Browser+Phishing+Attack+Targets+Microsoft+365+Login+Credentials/</guid>
<pubDate>Tue, 09 Jun 2026 12:19:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials]]></title> 
<description><![CDATA[Cybercriminals have found a clever new trick: turning the world&rsquo;s most popular AI tools into traps. By disguising phishing attacks with the branding of platforms like ChatGPT, Claude, and DeepSeek, threat actors are luring users into handing over login credentials,&hellip;
Read more &rarr;
The post Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3584088/IT+Sicherheit/Cybersecurity+Nachrichten/Threat+Actors+Abuse+ChatGPT%2C+Claude%2C+and+DeepSeek+Brands+as+Phishing+Lures+to+Steal+Credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584088/IT+Sicherheit/Cybersecurity+Nachrichten/Threat+Actors+Abuse+ChatGPT%2C+Claude%2C+and+DeepSeek+Brands+as+Phishing+Lures+to+Steal+Credentials/</guid>
<pubDate>Tue, 09 Jun 2026 12:05:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Sparkassen-Phishing mit angeblicher Aktualisierung der Daten]]></title> 
<description><![CDATA[Sparkassen-Kunden im Visier: Betr&uuml;ger verschicken Phishing-Mails zu angeblichen Sicherheitsupdates und versuchen, Online-Banking-Daten abzugreifen. ]]></description>
<link>https://tsecurity.de/de/3584080/IT+Nachrichten/Sparkassen-Phishing+mit+angeblicher+Aktualisierung+der+Daten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584080/IT+Nachrichten/Sparkassen-Phishing+mit+angeblicher+Aktualisierung+der+Daten/</guid>
<pubDate>Tue, 09 Jun 2026 11:42:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency]]></title> 
<description><![CDATA[

    2026-06-08 &bull; Proofpoint
     &bull; Carlos Rubio, Saher Naumaan
     &bull; win.overlord
    
    
    Open article on Malpedia
 ]]></description>
<link>https://tsecurity.de/de/3583972/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/Don%27t+Fear+the+Repo%3A+UNK_DeadDrop+Phishing+Campaign+Targets+Developers+to+Steal+Cryptocurrency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583972/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/Don%27t+Fear+the+Repo%3A+UNK_DeadDrop+Phishing+Campaign+Targets+Developers+to+Steal+Cryptocurrency/</guid>
<pubDate>Tue, 09 Jun 2026 11:17:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials]]></title> 
<description><![CDATA[Cybercriminals have found a clever new trick: turning the world&rsquo;s most popular AI tools into traps. By disguising phishing attacks with the branding of platforms like ChatGPT, Claude, and DeepSeek, threat actors are luring users into handing over login credentials, credit card numbers, and authentication tokens. The surge in AI adoption has given attackers fertile [&hellip;]
The post Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3583889/IT+Sicherheit/Cybersecurity+Nachrichten/Threat+Actors+Abuse+ChatGPT%2C+Claude%2C+and+DeepSeek+Brands+as+Phishing+Lures+to+Steal+Credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583889/IT+Sicherheit/Cybersecurity+Nachrichten/Threat+Actors+Abuse+ChatGPT%2C+Claude%2C+and+DeepSeek+Brands+as+Phishing+Lures+to+Steal+Credentials/</guid>
<pubDate>Tue, 09 Jun 2026 10:39:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[WhatsApp Discovers NSO Group-Linked Spearphishing Attempts]]></title> 
<description><![CDATA[Meta&rsquo;s WhatsApp demands contempt ruling after users report NSO Group-linked phishing This article has been indexed from www.infosecurity-magazine.com Read the original article: WhatsApp Discovers NSO Group-Linked Spearphishing Attempts
Read more &rarr;
The post WhatsApp Discovers NSO Group-Linked Spearphishing Attempts appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3583847/IT+Sicherheit/Cybersecurity+Nachrichten/WhatsApp+Discovers+NSO+Group-Linked+Spearphishing+Attempts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583847/IT+Sicherheit/Cybersecurity+Nachrichten/WhatsApp+Discovers+NSO+Group-Linked+Spearphishing+Attempts/</guid>
<pubDate>Tue, 09 Jun 2026 10:34:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[WhatsApp Discovers NSO Group-Linked Spearphishing Attempts]]></title> 
<description><![CDATA[Meta&rsquo;s WhatsApp demands contempt ruling after users report NSO Group-linked phishing ]]></description>
<link>https://tsecurity.de/de/3583818/IT+Sicherheit/Cybersecurity+Nachrichten/WhatsApp+Discovers+NSO+Group-Linked+Spearphishing+Attempts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583818/IT+Sicherheit/Cybersecurity+Nachrichten/WhatsApp+Discovers+NSO+Group-Linked+Spearphishing+Attempts/</guid>
<pubDate>Tue, 09 Jun 2026 10:15:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Neue Phishing-Angriffe auf WhatsApp gemeldet: Meta geht vor Gericht]]></title> 
<description><![CDATA[
    Meta beantragt eine gerichtliche Strafe gegen die NSO Group. Das Spionageunternehmen soll trotz Verbots neue Phishing-Angriffe auf WhatsApp ver&uuml;bt haben.

Tags: #Cyber Crime | #Meta | #WhatsApp ]]></description>
<link>https://tsecurity.de/de/3583579/IT+Sicherheit/Cybersecurity+Nachrichten/Neue+Phishing-Angriffe+auf+WhatsApp+gemeldet%3A+Meta+geht+vor+Gericht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583579/IT+Sicherheit/Cybersecurity+Nachrichten/Neue+Phishing-Angriffe+auf+WhatsApp+gemeldet%3A+Meta+geht+vor+Gericht/</guid>
<pubDate>Tue, 09 Jun 2026 07:25:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Exploit ChatGPT, Claude, DeepSeek Brands in Credential Phishing Attacks]]></title> 
<description><![CDATA[Threat actors are increasingly weaponizing the global fascination with large language models and generative AI by impersonating major AI brands ChatGPT, Anthropic&rsquo;s Claude, DeepSeek, and others to trick users into revealing credentials, payment information, and to install malware. These campaigns&hellip;
Read more &rarr;
The post Hackers Exploit ChatGPT, Claude, DeepSeek Brands in Credential Phishing Attacks appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3583570/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Exploit+ChatGPT%2C+Claude%2C+DeepSeek+Brands+in+Credential+Phishing+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583570/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Exploit+ChatGPT%2C+Claude%2C+DeepSeek+Brands+in+Credential+Phishing+Attacks/</guid>
<pubDate>Tue, 09 Jun 2026 07:34:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Exploit ChatGPT, Claude, DeepSeek Brands in Credential Phishing Attacks]]></title> 
<description><![CDATA[Threat actors are increasingly weaponizing the global fascination with large language models and generative AI by impersonating major AI brands ChatGPT, Anthropic&rsquo;s Claude, DeepSeek, and others to trick users into revealing credentials, payment information, and to install malware. These campaigns are not breaches of the vendor platforms; they are classic social engineering and distribution techniques [&hellip;]
The post Hackers Exploit ChatGPT, Claude, DeepSeek Brands in Credential Phishing Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3583553/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Exploit+ChatGPT%2C+Claude%2C+DeepSeek+Brands+in+Credential+Phishing+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583553/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Exploit+ChatGPT%2C+Claude%2C+DeepSeek+Brands+in+Credential+Phishing+Attacks/</guid>
<pubDate>Tue, 09 Jun 2026 07:09:25 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Betrugswelle zu WM 2026: Phishing-Domains, Banking-Malware und übernommene Konten]]></title> 
<description><![CDATA[LONDON (IT BOLTWISE) &ndash; Kurz vor dem WM-Start am 11. Juni trifft Fans bereits eine breite Betrugswelle: gef&auml;lschte FIFA-Websites, Banking-Malware in inoffiziellen Streaming-Apps und abgegriffene Zugangsdaten erm&ouml;glichen Konten&uuml;bernahmen. Sicherheitsforscher berichten von tausenden Lookalike-Domains, teilweise mit nahezu identischen Login-Seiten, die Passw&ouml;rter und MFA-Codes missbrauchen. F&uuml;r Unternehmen bedeutet das: Fr&uuml;hzeitige Erkennung von Credential-Diebstahl und ein Last- sowie [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;Betrugswelle zu WM 2026: Phishing-Domains, Banking-Malware und &uuml;bernommene Konten&laquo; lesen
Dieser Beitrag Betrugswelle zu WM 2026: Phishing-Domains, Banking-Malware und &uuml;bernommene Konten erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3582913/IT+Sicherheit/Cybersecurity+Nachrichten/Betrugswelle+zu+WM+2026%3A+Phishing-Domains%2C+Banking-Malware+und+%C3%BCbernommene+Konten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582913/IT+Sicherheit/Cybersecurity+Nachrichten/Betrugswelle+zu+WM+2026%3A+Phishing-Domains%2C+Banking-Malware+und+%C3%BCbernommene+Konten/</guid>
<pubDate>Mon, 08 Jun 2026 22:52:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FIFA-WM 2026: Betrugswelle mit Phishing-Domains, Banking-Malware und gestohlenen Logins]]></title> 
<description><![CDATA[LONDON / LONDON (IT BOLTWISE) &ndash; Vor dem offiziellen Start der FIFA-Weltmeisterschaft am 11. Juni warnen Sicherheitsforscher vor einer bereits laufenden Betrugswelle rund um Tickets, Streams und Reiseangebote. In kurzer Zeit wurden tausende t&auml;uschend echte FIFA-Domains beobachtet, darunter Kampagnen, die Login-Seiten kopieren und Konten &uuml;bernehmen. Parallel tauchen auf Android gef&auml;lschte Streaming-Apps mit Banking-Malware auf, die [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;FIFA-WM 2026: Betrugswelle mit Phishing-Domains, Banking-Malware und gestohlenen Logins&laquo; lesen
Dieser Beitrag FIFA-WM 2026: Betrugswelle mit Phishing-Domains, Banking-Malware und gestohlenen Logins erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3582908/IT+Sicherheit/Cybersecurity+Nachrichten/FIFA-WM+2026%3A+Betrugswelle+mit+Phishing-Domains%2C+Banking-Malware+und+gestohlenen+Logins/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582908/IT+Sicherheit/Cybersecurity+Nachrichten/FIFA-WM+2026%3A+Betrugswelle+mit+Phishing-Domains%2C+Banking-Malware+und+gestohlenen+Logins/</guid>
<pubDate>Mon, 08 Jun 2026 23:04:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[WhatsApp says it disrupted new NSO spyware phishing attacks]]></title> 
<description><![CDATA[WhatsApp has detected and stopped spear-phishing campaigns allegedly conducted by the NSO Group after investigating user reports of social engineering attacks. [...] ]]></description>
<link>https://tsecurity.de/de/3582547/IT+Sicherheit/Cybersecurity+Nachrichten/WhatsApp+says+it+disrupted+new+NSO+spyware+phishing+attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582547/IT+Sicherheit/Cybersecurity+Nachrichten/WhatsApp+says+it+disrupted+new+NSO+spyware+phishing+attacks/</guid>
<pubDate>Mon, 08 Jun 2026 20:40:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Meta Blocks NSO Group’s New WhatsApp Phishing Attack, Files Contempt Order]]></title> 
<description><![CDATA[Meta on Monday said it detected and blocked spear-phishing attempts linked to Israeli spyware vendor NSO Group. In addition, the tech giant said it&rsquo;s filing a federal court contempt order against the company for violating a permanent injunction that barred&hellip;
Read more &rarr;
The post Meta Blocks NSO Group&rsquo;s New WhatsApp Phishing Attack, Files Contempt Order appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3582417/IT+Sicherheit/Cybersecurity+Nachrichten/Meta+Blocks+NSO+Group%E2%80%99s+New+WhatsApp+Phishing+Attack%2C+Files+Contempt+Order/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582417/IT+Sicherheit/Cybersecurity+Nachrichten/Meta+Blocks+NSO+Group%E2%80%99s+New+WhatsApp+Phishing+Attack%2C+Files+Contempt+Order/</guid>
<pubDate>Mon, 08 Jun 2026 20:04:38 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Meta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order]]></title> 
<description><![CDATA[Meta on Monday said it detected and blocked spear-phishing attempts linked to Israeli spyware vendor NSO Group.

In addition, the tech giant said it&#039;s filing a federal court contempt order against the company for violating a permanent injunction that barred it from targeting WhatsApp and its users.

&quot;They tried to trick people into clicking on malicious links to drive them to external websites ]]></description>
<link>https://tsecurity.de/de/3582350/IT+Sicherheit/Cybersecurity+Nachrichten/Meta+Blocks+NSO+Group%27s+New+WhatsApp+Phishing+Attack%2C+Files+Contempt+Order/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582350/IT+Sicherheit/Cybersecurity+Nachrichten/Meta+Blocks+NSO+Group%27s+New+WhatsApp+Phishing+Attack%2C+Files+Contempt+Order/</guid>
<pubDate>Mon, 08 Jun 2026 19:08:44 +0200</pubDate>
</item>
<item> 
<title><![CDATA[AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload]]></title> 
<description><![CDATA[Phishing has always been a numbers game. AI has turned it into a volume machine.

Attackers can now create convincing emails, fake login pages, and tailored lures in minutes. Every polished message adds another case for Tier 1 to review, another link to inspect, and another alert that cannot be dismissed at a glance.

As the queue grows, a credential theft attempt or malware delivery can easily ]]></description>
<link>https://tsecurity.de/de/3581528/IT+Sicherheit/Cybersecurity+Nachrichten/AI+Phishing+Is+Crushing+SOCs+with+Alert+Volume%3A+How+to+Reduce+Tier+1+Overload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581528/IT+Sicherheit/Cybersecurity+Nachrichten/AI+Phishing+Is+Crushing+SOCs+with+Alert+Volume%3A+How+to+Reduce+Tier+1+Overload/</guid>
<pubDate>Mon, 08 Jun 2026 15:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload]]></title> 
<description><![CDATA[Phishing has always been a numbers game. AI has turned it into a volume machine. Attackers can now create convincing emails, fake login pages, and tailored lures in minutes. Every polished message adds another case for Tier 1 to review,&hellip;
Read more &rarr;
The post AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3581524/IT+Sicherheit/Cybersecurity+Nachrichten/AI+Phishing+Is+Crushing+SOCs+with+Alert+Volume%3A+How+to+Reduce+Tier+1+Overload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581524/IT+Sicherheit/Cybersecurity+Nachrichten/AI+Phishing+Is+Crushing+SOCs+with+Alert+Volume%3A+How+to+Reduce+Tier+1+Overload/</guid>
<pubDate>Mon, 08 Jun 2026 15:05:21 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Der ultimative Leitfaden zum Schutz vor Phishing-Angriffen]]></title> 
<description><![CDATA[Einleitung Phishing-Angriffe geh&ouml;ren mittlerweile zu den h&auml;ufigsten Cyberbedrohungen &uuml;berhaupt. Fast jeder Internetnutzer hat schon einmal eine verd&auml;chtige E-Mail, SMS oder [&hellip;]
Der Beitrag Der ultimative Leitfaden zum Schutz vor Phishing-Angriffen erschien zuerst auf WinTotal.de. ]]></description>
<link>https://tsecurity.de/de/3580955/IT+Betriebssysteme/Windows+Tipps/Der+ultimative+Leitfaden+zum+Schutz+vor+Phishing-Angriffen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580955/IT+Betriebssysteme/Windows+Tipps/Der+ultimative+Leitfaden+zum+Schutz+vor+Phishing-Angriffen/</guid>
<pubDate>Mon, 08 Jun 2026 11:20:28 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cybercriminals Exploit 2026 FIFA World Cup With Phishing, Fake Stores, and Ticket Scams]]></title> 
<description><![CDATA[The 2026 FIFA World Cup is not just a celebration of football. For cybercriminals, it is a business opportunity, and they have already gotten to work. Threat actors have been building fake FIFA stores, spinning up phishing pages, and launching&hellip;
Read more &rarr;
The post Cybercriminals Exploit 2026 FIFA World Cup With Phishing, Fake Stores, and Ticket Scams appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3580818/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercriminals+Exploit+2026+FIFA+World+Cup+With+Phishing%2C+Fake+Stores%2C+and+Ticket+Scams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580818/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercriminals+Exploit+2026+FIFA+World+Cup+With+Phishing%2C+Fake+Stores%2C+and+Ticket+Scams/</guid>
<pubDate>Mon, 08 Jun 2026 10:32:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Fake Stores and Phishing Campaigns Exploit 2026 FIFA World Cup Hype]]></title> 
<description><![CDATA[The 2026 FIFA World Cup, hosted across the United States, Mexico, and Canada, is expected to be one of the largest sporting events in history. This massive global hype has created a highly lucrative environment for financially motivated threat actors. Cybercriminals are actively exploiting this excitement to launch large-scale fraud operations. The FBI recently issued [&hellip;]
The post Fake Stores and Phishing Campaigns Exploit 2026 FIFA World Cup Hype appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3580767/IT+Sicherheit/Cybersecurity+Nachrichten/Fake+Stores+and+Phishing+Campaigns+Exploit+2026+FIFA+World+Cup+Hype/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580767/IT+Sicherheit/Cybersecurity+Nachrichten/Fake+Stores+and+Phishing+Campaigns+Exploit+2026+FIFA+World+Cup+Hype/</guid>
<pubDate>Mon, 08 Jun 2026 10:01:24 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cybercriminals Exploit 2026 FIFA World Cup With Phishing, Fake Stores, and Ticket Scams]]></title> 
<description><![CDATA[The 2026 FIFA World Cup is not just a celebration of football. For cybercriminals, it is a business opportunity, and they have already gotten to work. Threat actors have been building fake FIFA stores, spinning up phishing pages, and launching purchase scams at a scale that has security researchers watching closely. The tournament, hosted across [&hellip;]
The post Cybercriminals Exploit 2026 FIFA World Cup With Phishing, Fake Stores, and Ticket Scams appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3580766/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercriminals+Exploit+2026+FIFA+World+Cup+With+Phishing%2C+Fake+Stores%2C+and+Ticket+Scams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580766/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercriminals+Exploit+2026+FIFA+World+Cup+With+Phishing%2C+Fake+Stores%2C+and+Ticket+Scams/</guid>
<pubDate>Mon, 08 Jun 2026 10:04:28 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Exploit 2026 FIFA World Cup With Phishing and Ticket Scams]]></title> 
<description><![CDATA[Cybercriminals are already turning the 2026 FIFA World Cup into a fraud opportunity, using phishing pages, fake online stores, and ticket scams to steal money and personal data. The risk is rising because the tournament will attract huge global demand,&hellip;
Read more &rarr;
The post Hackers Exploit 2026 FIFA World Cup With Phishing and Ticket Scams appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3580511/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Exploit+2026+FIFA+World+Cup+With+Phishing+and+Ticket+Scams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580511/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Exploit+2026+FIFA+World+Cup+With+Phishing+and+Ticket+Scams/</guid>
<pubDate>Mon, 08 Jun 2026 07:32:17 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Exploit 2026 FIFA World Cup With Phishing and Ticket Scams]]></title> 
<description><![CDATA[Cybercriminals are already turning the 2026 FIFA World Cup into a fraud opportunity, using phishing pages, fake online stores, and ticket scams to steal money and personal data. The risk is rising because the tournament will attract huge global demand, fast purchases, and buyers who may act quickly before checking whether a site is real. [&hellip;]
The post Hackers Exploit 2026 FIFA World Cup With Phishing and Ticket Scams appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3580490/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Exploit+2026+FIFA+World+Cup+With+Phishing+and+Ticket+Scams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580490/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Exploit+2026+FIFA+World+Cup+With+Phishing+and+Ticket+Scams/</guid>
<pubDate>Mon, 08 Jun 2026 07:12:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[KI-Phishing: 82,6% aller Betrugsmails werden künstlich generiert - Börse Express]]></title> 
<description><![CDATA[Dieser kostenlose Report zeigt, welche psychologischen Tricks Hacker gezielt einsetzen, um Unternehmen zu sch&auml;digen. Gratis-Ratgeber zur Hacker-Abwehr&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3580274/IT+Sicherheit/Hacker/KI-Phishing%3A+82%2C6%25+aller+Betrugsmails+werden+k%C3%BCnstlich+generiert+-+B%C3%B6rse+Express/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580274/IT+Sicherheit/Hacker/KI-Phishing%3A+82%2C6%25+aller+Betrugsmails+werden+k%C3%BCnstlich+generiert+-+B%C3%B6rse+Express/</guid>
<pubDate>Mon, 08 Jun 2026 03:42:03 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing 2026: 82,6% KI-generiert – klassische Warnsignale weg - Ad-hoc-news.de]]></title> 
<description><![CDATA[Verd&auml;chtige Aktivit&auml;ten sofort bei Bank und nationalen Cybercrime-Portalen melden; Kartensteuerungsfunktionen in Banking-Apps zum Sperren und&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3580112/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing+2026%3A+82%2C6%25+KI-generiert+%E2%80%93+klassische+Warnsignale+weg+-+Ad-hoc-news.de/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580112/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing+2026%3A+82%2C6%25+KI-generiert+%E2%80%93+klassische+Warnsignale+weg+-+Ad-hoc-news.de/</guid>
<pubDate>Mon, 08 Jun 2026 00:15:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[WhatsApp-Sicherheit: KI-Phishing explodiert um 1.200 Prozent - BornCity]]></title> 
<description><![CDATA[In der Schweiz meldete das Bundesamt f&uuml;r Cybersicherheit eine Verdreifachung der Vorf&auml;lle innerhalb weniger Wochen. Die T&auml;ter nutzen Namen&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3580061/IT+Sicherheit/Cybersecurity+Nachrichten/WhatsApp-Sicherheit%3A+KI-Phishing+explodiert+um+1.200+Prozent+-+BornCity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580061/IT+Sicherheit/Cybersecurity+Nachrichten/WhatsApp-Sicherheit%3A+KI-Phishing+explodiert+um+1.200+Prozent+-+BornCity/</guid>
<pubDate>Sun, 07 Jun 2026 22:41:38 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing-Alarm: Hotelbuchungs-Betrüger nutzen Booking-Datenleck - BornCity]]></title> 
<description><![CDATA[Das Schweizer Bundesamt f&uuml;r Cybersicherheit (Bacs) meldet Anfang Juni 2026 eine alarmierende Zunahme von Phishing-Versuchen. Die T&auml;ter nutzen&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3579915/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing-Alarm%3A+Hotelbuchungs-Betr%C3%BCger+nutzen+Booking-Datenleck+-+BornCity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579915/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing-Alarm%3A+Hotelbuchungs-Betr%C3%BCger+nutzen+Booking-Datenleck+-+BornCity/</guid>
<pubDate>Sun, 07 Jun 2026 18:38:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Betrug eskaliert: KI-Phishing nimmt um 1.200 Prozent zu - BornCity]]></title> 
<description><![CDATA[Das Schweizer Bundesamt f&uuml;r Cybersicherheit (BACS) meldet eine Verdreifachung der Betrugsf&auml;lle bei Hotelbuchungen. Im Mai wurden 23 F&auml;lle&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3579280/IT+Sicherheit/Cybersecurity+Nachrichten/Betrug+eskaliert%3A+KI-Phishing+nimmt+um+1.200+Prozent+zu+-+BornCity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579280/IT+Sicherheit/Cybersecurity+Nachrichten/Betrug+eskaliert%3A+KI-Phishing+nimmt+um+1.200+Prozent+zu+-+BornCity/</guid>
<pubDate>Sun, 07 Jun 2026 04:41:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[TA4922 erweitert Phishing nach Europa und nutzt DLL-Side-Loading für RAT]]></title> 
<description><![CDATA[LONDON / LONDON (IT BOLTWISE) &ndash; Eine China-verbundene Cybercrime-Gruppe namens TA4922 weitet ihren Fokus auf Unternehmen in Gro&szlig;britannien, Deutschland, Italien und S&uuml;dafrika aus. Laut Branchenberichten kombiniert der Akteur einen &bdquo;rapid operational tempo&ldquo; mit st&auml;ndig wechselnden Malware-Werkzeugen wie ValleyRAT und Atlas RAT sowie neu beobachteten Loadern wie RomulusLoader und SilentRunLoader. Auff&auml;llig ist dabei, dass TA4922 zunehmend [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;TA4922 erweitert Phishing nach Europa und nutzt DLL-Side-Loading f&uuml;r RAT&laquo; lesen
Dieser Beitrag TA4922 erweitert Phishing nach Europa und nutzt DLL-Side-Loading f&uuml;r RAT erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3578532/IT+Sicherheit/Cybersecurity+Nachrichten/TA4922+erweitert+Phishing+nach+Europa+und+nutzt+DLL-Side-Loading+f%C3%BCr+RAT/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578532/IT+Sicherheit/Cybersecurity+Nachrichten/TA4922+erweitert+Phishing+nach+Europa+und+nutzt+DLL-Side-Loading+f%C3%BCr+RAT/</guid>
<pubDate>Sun, 07 Jun 2026 01:51:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing-Welle: Kriminelle nutzen Booking-Daten für WhatsApp-Betrug - BornCity]]></title> 
<description><![CDATA[Das Bundesamt f&uuml;r Cybersicherheit (BACS) und f&uuml;hrende Technologieunternehmen haben neue Warnungen vor einer dramatischen Zunahme von&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3578510/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing-Welle%3A+Kriminelle+nutzen+Booking-Daten+f%C3%BCr+WhatsApp-Betrug+-+BornCity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578510/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing-Welle%3A+Kriminelle+nutzen+Booking-Daten+f%C3%BCr+WhatsApp-Betrug+-+BornCity/</guid>
<pubDate>Sat, 06 Jun 2026 22:25:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[TA4922 weitet Phishing auf UK, Deutschland, Italien und Südafrika aus]]></title> 
<description><![CDATA[LONDON / LONDON (IT BOLTWISE) &ndash; TA4922, eine mutma&szlig;lich China-verkn&uuml;pfte Cybercrime-Gruppe, erweitert laut Proofpoint ihren Fokus auf europ&auml;ische Ziele. Im Zentrum stehen Phishing-Kampagnen mit Personal-, Unternehmens- und Steuerbezug, die Zugangsdaten stehlen und Schadsoftware ausliefern. Zus&auml;tzlich versuchen die Angreifer Gespr&auml;che aus E-Mail-Kan&auml;len in Messenger wie LINE, WhatsApp und Microsoft Teams zu verlagern, um Sicherheitskontrollen zu umgehen. [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;TA4922 weitet Phishing auf UK, Deutschland, Italien und S&uuml;dafrika aus&laquo; lesen
Dieser Beitrag TA4922 weitet Phishing auf UK, Deutschland, Italien und S&uuml;dafrika aus erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3578477/IT+Sicherheit/Cybersecurity+Nachrichten/TA4922+weitet+Phishing+auf+UK%2C+Deutschland%2C+Italien+und+S%C3%BCdafrika+aus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578477/IT+Sicherheit/Cybersecurity+Nachrichten/TA4922+weitet+Phishing+auf+UK%2C+Deutschland%2C+Italien+und+S%C3%BCdafrika+aus/</guid>
<pubDate>Sun, 07 Jun 2026 00:58:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Booking-Betrüger: Bund warnt vor Phishing mit Hotelbuchungen - Blick]]></title> 
<description><![CDATA[Es ist kein Einzelfall: Eine Welle solcher gezielter Angriffe rollt derzeit &uuml;ber die Schweiz, warnt das Bundesamt f&uuml;r Cybersicherheit (BACS). ]]></description>
<link>https://tsecurity.de/de/3576680/IT+Sicherheit/Cybersecurity+Nachrichten/Booking-Betr%C3%BCger%3A+Bund+warnt+vor+Phishing+mit+Hotelbuchungen+-+Blick/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576680/IT+Sicherheit/Cybersecurity+Nachrichten/Booking-Betr%C3%BCger%3A+Bund+warnt+vor+Phishing+mit+Hotelbuchungen+-+Blick/</guid>
<pubDate>Sat, 06 Jun 2026 00:29:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Bafin warnt: Diese Seite ist wahrscheinlich eine Phishing-Falle]]></title> 
<description><![CDATA[Viele Unternehmen bieten Hilfe dabei, Finanzen und Bankgesch&auml;fte zu regeln. Darunter tummeln sich auch Kriminelle, die von der Bafin gerade offengelgt wurden.
																					Dieser Artikel wurde einsortiert unter 
																	Aktuelle Betrugswarnungen. ]]></description>
<link>https://tsecurity.de/de/3575673/IT+Nachrichten/Bafin+warnt%3A+Diese+Seite+ist+wahrscheinlich+eine+Phishing-Falle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575673/IT+Nachrichten/Bafin+warnt%3A+Diese+Seite+ist+wahrscheinlich+eine+Phishing-Falle/</guid>
<pubDate>Fri, 05 Jun 2026 15:58:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[SME Cybersecurity Threat Intel: Why Phishing Now Beats Ransomware for UK Small Businesses]]></title> 
<description><![CDATA[Image Credit: Designed by FreePik via Magnific Latest Posts from SECURUS Communications FIREWALLS SMECYBERIINSIGHTS Do...
The post SME Cybersecurity Threat Intel: Why Phishing Now Beats Ransomware for UK Small Businesses appeared first on SME Cybersecurity News | SMECYBERInsights.co.uk. ]]></description>
<link>https://tsecurity.de/de/3574803/IT+Sicherheit/Cybersecurity+Nachrichten/SME+Cybersecurity+Threat+Intel%3A+Why+Phishing+Now+Beats+Ransomware+for+UK+Small+Businesses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574803/IT+Sicherheit/Cybersecurity+Nachrichten/SME+Cybersecurity+Threat+Intel%3A+Why+Phishing+Now+Beats+Ransomware+for+UK+Small+Businesses/</guid>
<pubDate>Fri, 05 Jun 2026 07:00:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cybercriminals Shift From Fake Login Pages to Infostealer Malware in Phishing Attacks]]></title> 
<description><![CDATA[Phishing attacks have always been one of the most common ways cybercriminals steal personal and business data. But something has quietly changed about how these attacks work. Instead of tricking people into typing passwords on fake websites, attackers are now&hellip;
Read more &rarr;
The post Cybercriminals Shift From Fake Login Pages to Infostealer Malware in Phishing Attacks appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3573624/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercriminals+Shift+From+Fake+Login+Pages+to+Infostealer+Malware+in+Phishing+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573624/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercriminals+Shift+From+Fake+Login+Pages+to+Infostealer+Malware+in+Phishing+Attacks/</guid>
<pubDate>Thu, 04 Jun 2026 20:34:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Klarna gegen Betrug: Neue Inbox soll Phishing stoppen]]></title> 
<description><![CDATA[Phishing-Mails und gef&auml;lschte SMS im Namen von Zahlungsdienstleistern sind mittlerweile so gut gemacht, dass Nutzer oft kaum noch einen Unterschied zum Original sehen. Klarna f&uuml;hrt deshalb eine neue Funktion namens Inbox ein, um die Sicherheit zu erh&ouml;hen. Das Prinzip hinter...Zum Beitrag: Klarna gegen Betrug: Neue Inbox soll Phishing stoppen

Wo du uns folgen kannst:
Facebook, Reddit, Google News, X, Threads


    Auf dem Laufenden bleiben?
    
    F&uuml;gt uns doch bei Google als bevorzugte Quelle hinzu!
 ]]></description>
<link>https://tsecurity.de/de/3573329/IT+Nachrichten/Klarna+gegen+Betrug%3A+Neue+Inbox+soll+Phishing+stoppen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573329/IT+Nachrichten/Klarna+gegen+Betrug%3A+Neue+Inbox+soll+Phishing+stoppen/</guid>
<pubDate>Thu, 04 Jun 2026 18:00:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cybercriminals Shift From Fake Login Pages to Infostealer Malware in Phishing Attacks]]></title> 
<description><![CDATA[Phishing attacks have always been one of the most common ways cybercriminals steal personal and business data. But something has quietly changed about how these attacks work. Instead of tricking people into typing passwords on fake websites, attackers are now dropping malware directly onto victims&rsquo; devices to do the stealing for them. This shift has [&hellip;]
The post Cybercriminals Shift From Fake Login Pages to Infostealer Malware in Phishing Attacks appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3573209/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercriminals+Shift+From+Fake+Login+Pages+to+Infostealer+Malware+in+Phishing+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573209/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercriminals+Shift+From+Fake+Login+Pages+to+Infostealer+Malware+in+Phishing+Attacks/</guid>
<pubDate>Thu, 04 Jun 2026 17:44:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Fake invoice phishing campaign caught mid-rollout]]></title> 
<description><![CDATA[Security researchers at Malwarebytes have intercepted a large-scale phishing operation while it was still being assembled, discovering incomplete email templates with placeholder fields where phone numbers and prices would normally appear. This article has been indexed from CyberMaterial Read the&hellip;
Read more &rarr;
The post Fake invoice phishing campaign caught mid-rollout appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3572672/IT+Sicherheit/Cybersecurity+Nachrichten/Fake+invoice+phishing+campaign+caught+mid-rollout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572672/IT+Sicherheit/Cybersecurity+Nachrichten/Fake+invoice+phishing+campaign+caught+mid-rollout/</guid>
<pubDate>Thu, 04 Jun 2026 15:05:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa]]></title> 
<description><![CDATA[A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa.

These efforts have been complemented by a &quot;rapid operational tempo&quot; and a continually evolving malware arsenal comprising known families like ValleyRAT (aka Winos 4.0) and Atlas RAT (aka AtlasCross RAT), as well as previously ]]></description>
<link>https://tsecurity.de/de/3572603/IT+Sicherheit/Cybersecurity+Nachrichten/China-Linked+TA4922+Expands+Phishing+Attacks+to+UK%2C+Germany%2C+Italy%2C+and+South+Africa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572603/IT+Sicherheit/Cybersecurity+Nachrichten/China-Linked+TA4922+Expands+Phishing+Attacks+to+UK%2C+Germany%2C+Italy%2C+and+South+Africa/</guid>
<pubDate>Thu, 04 Jun 2026 14:22:25 +0200</pubDate>
</item>
<item> 
<title><![CDATA[China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa]]></title> 
<description><![CDATA[A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa. These efforts have been complemented by a &ldquo;rapid operational tempo&rdquo; and a continually evolving malware&hellip;
Read more &rarr;
The post China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3572596/IT+Sicherheit/Cybersecurity+Nachrichten/China-Linked+TA4922+Expands+Phishing+Attacks+to+UK%2C+Germany%2C+Italy%2C+and+South+Africa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572596/IT+Sicherheit/Cybersecurity+Nachrichten/China-Linked+TA4922+Expands+Phishing+Attacks+to+UK%2C+Germany%2C+Italy%2C+and+South+Africa/</guid>
<pubDate>Thu, 04 Jun 2026 14:32:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing Campaigns Evolve as Cybercriminals Turn to Infostealer Malware]]></title> 
<description><![CDATA[Phishing tactics are undergoing a major transformation. While traditional phishing campaigns that rely on fake login pages have not disappeared, cybercriminals are increasingly favoring infostealer malware. Instead of actively tricking victims into entering their usernames and passwords, attackers deploy these malicious programs to collect sensitive information quietly. Once installed on a device, infostealers harvest passwords, [&hellip;]
The post Phishing Campaigns Evolve as Cybercriminals Turn to Infostealer Malware appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3572536/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing+Campaigns+Evolve+as+Cybercriminals+Turn+to+Infostealer+Malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572536/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing+Campaigns+Evolve+as+Cybercriminals+Turn+to+Infostealer+Malware/</guid>
<pubDate>Thu, 04 Jun 2026 14:08:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Q1 2026 Cyber Risk Report: Insights from 2.1 Million Malware and Phishing Investigations ]]></title> 
<description><![CDATA[Based on&nbsp;2,101,483&nbsp;malware and phishing investigations from Q1 2026,&nbsp;ANY.RUN&lsquo;s&nbsp;Cyber Risk&nbsp;report&nbsp;provides&nbsp;a real-world view of&nbsp;modern attack trends.&nbsp; It covers&nbsp;trending malware families,&nbsp;TTPs, and other&nbsp;technical observations,&nbsp;while&nbsp;also&nbsp;delivering&nbsp;executive insights CISOs and&nbsp;SOC&nbsp;teams can use to connect attacker behavior to business risk.&nbsp; Combining data-backed malware trends with strategic guidance for security leaders, the&nbsp;report&nbsp;reveals&nbsp;critical gaps in&nbsp;detection, response, and visibility that directly&nbsp;impact&nbsp;business resilience, and&nbsp;outlines&nbsp;solutions organizations can&nbsp;use [&hellip;]
The post Q1 2026&nbsp;Cyber Risk&nbsp;Report:&nbsp;Insights from 2.1&nbsp;Million&nbsp;Malware and Phishing Investigations&nbsp; appeared first on ANY.RUN&#039;s Cybersecurity Blog. ]]></description>
<link>https://tsecurity.de/de/3572345/IT+Sicherheit/Cybersecurity+Nachrichten/Q1+2026%C2%A0Cyber+Risk%C2%A0Report%3A%C2%A0Insights+from+2.1%C2%A0Million%C2%A0Malware+and+Phishing+Investigations%C2%A0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572345/IT+Sicherheit/Cybersecurity+Nachrichten/Q1+2026%C2%A0Cyber+Risk%C2%A0Report%3A%C2%A0Insights+from+2.1%C2%A0Million%C2%A0Malware+and+Phishing+Investigations%C2%A0/</guid>
<pubDate>Thu, 04 Jun 2026 13:18:51 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing Attacks Pivot to Infostealer Malware Over Fake Login Pages]]></title> 
<description><![CDATA[Cybercriminal tactics are evolving as phishing campaigns increasingly shift away from fake login pages toward infostealer malware designed to quietly harvest sensitive data from infected systems. While traditional credential-harvesting pages remain in use, threat actors are now prioritizing methods that reduce user interaction and increase data collection efficiency. Infostealers are purpose-built malware families that extract [&hellip;]
The post Phishing Attacks Pivot to Infostealer Malware Over Fake Login Pages appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3571899/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing+Attacks+Pivot+to+Infostealer+Malware+Over+Fake+Login+Pages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571899/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing+Attacks+Pivot+to+Infostealer+Malware+Over+Fake+Login+Pages/</guid>
<pubDate>Thu, 04 Jun 2026 10:27:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Kali365 Phishing-as-a-Service Campaign Broadens Attacks to Okta and MAX Messenger Users]]></title> 
<description><![CDATA[The Kali365 Phishing-as-a-Service (PhaaS) campaign is rapidly evolving beyond its initial scope, expanding its attack surface to target Okta, Xerox DocuShare, and users of Russia&rsquo;s state-backed MAX Messenger. Originally documented as a toolkit designed to abuse Microsoft&rsquo;s OAuth 2.0 device authorization flow to steal Entra ID tokens, Kali365 has matured into a multi-brand operation. By [&hellip;]
The post Kali365 Phishing-as-a-Service Campaign Broadens Attacks to Okta and MAX Messenger Users appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3571898/IT+Sicherheit/Cybersecurity+Nachrichten/Kali365+Phishing-as-a-Service+Campaign+Broadens+Attacks+to+Okta+and+MAX+Messenger+Users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571898/IT+Sicherheit/Cybersecurity+Nachrichten/Kali365+Phishing-as-a-Service+Campaign+Broadens+Attacks+to+Okta+and+MAX+Messenger+Users/</guid>
<pubDate>Thu, 04 Jun 2026 10:28:26 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Phishing Attacks Pivot to Infostealer Malware Over Fake Login Pages]]></title> 
<description><![CDATA[Cybercriminal tactics are evolving as phishing campaigns increasingly shift away from fake login pages toward infostealer malware designed to quietly harvest sensitive data from infected systems. While traditional credential-harvesting pages remain in use, threat actors are now prioritizing methods that&hellip;
Read more &rarr;
The post Phishing Attacks Pivot to Infostealer Malware Over Fake Login Pages appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3571891/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing+Attacks+Pivot+to+Infostealer+Malware+Over+Fake+Login+Pages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571891/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing+Attacks+Pivot+to+Infostealer+Malware+Over+Fake+Login+Pages/</guid>
<pubDate>Thu, 04 Jun 2026 10:34:32 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Looking for a live threat feed of phishing sites]]></title> 
<description><![CDATA[Can anyone steer me toward a feed of still active phishing sites? Not hashes or URLs that are all taken down. Working on an anti phishing tool that&#039;s so far successful at work and home browsing, but I&#039;d like to put it up against a wider variety of threats. Also, if this isn&#039;t the correct sub, I&#039;d love pointers to any other subs that I might be able to glean this from.    submitted by    /u/NeverInsightful   [link]   [comments] ]]></description>
<link>https://tsecurity.de/de/3571234/IT+Sicherheit/Cybersecurity+Nachrichten/Looking+for+a+live+threat+feed+of+phishing+sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571234/IT+Sicherheit/Cybersecurity+Nachrichten/Looking+for+a+live+threat+feed+of+phishing+sites/</guid>
<pubDate>Tue, 02 Jun 2026 05:03:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Wöchentliches Security-Update: PAN-OS-Bypass, Gogs-RCE ohne Patch und KI-Phishing im Beschleunigungsmodus]]></title> 
<description><![CDATA[LONDON (IT BOLTWISE) &ndash; In dieser Woche zeigt sich erneut, wie schnell aus einem &bdquo;mittel-sicheren&ldquo; Fehler ein operativ verwertbarer Einfall werden kann: PAN-OS/Prisma-Access wird laut Warnungen aktiv f&uuml;r Authentifizierungs-Byp&auml;sse missbraucht, w&auml;hrend bei Gogs ein kritischer Zero-Day bereits Remote Code Execution erm&ouml;glicht &ndash; ohne verf&uuml;gbaren Patch. Gleichzeitig sinkt mit KI-gest&uuml;tztem Social Engineering die H&uuml;rde f&uuml;r Phishing [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;W&ouml;chentliches Security-Update: PAN-OS-Bypass, Gogs-RCE ohne Patch und KI-Phishing im Beschleunigungsmodus&laquo; lesen
Dieser Beitrag W&ouml;chentliches Security-Update: PAN-OS-Bypass, Gogs-RCE ohne Patch und KI-Phishing im Beschleunigungsmodus erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3570551/IT+Sicherheit/Cybersecurity+Nachrichten/W%C3%B6chentliches+Security-Update%3A+PAN-OS-Bypass%2C+Gogs-RCE+ohne+Patch+und+KI-Phishing+im+Beschleunigungsmodus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570551/IT+Sicherheit/Cybersecurity+Nachrichten/W%C3%B6chentliches+Security-Update%3A+PAN-OS-Bypass%2C+Gogs-RCE+ohne+Patch+und+KI-Phishing+im+Beschleunigungsmodus/</guid>
<pubDate>Wed, 03 Jun 2026 20:27:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cybersecurity-Recap: PAN-OS-Auth-Bypass, Gogs-0-Day und KI-getriebene Phishing-Wellen]]></title> 
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) &ndash; In dieser Woche verdichten sich gleich mehrere Ausbruchsmuster: ein PAN-OS-Authentication-Bypass wird aktiv ausgenutzt, w&auml;hrend bei Gogs ein kritisches Zero-Day-Angriffsszenario ohne Patch bekannt wird. Parallel zeigt sich, wie moderne Kampagnen auch K&uuml;nstliche Intelligenz als Beschleuniger f&uuml;r Social Engineering und Angriffsinfrastruktur nutzen. Dazu kommen Abstellungen von Malware-Kommandozentralen, neue Timing-basierte Side-Channel-Forschung und [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;Cybersecurity-Recap: PAN-OS-Auth-Bypass, Gogs-0-Day und KI-getriebene Phishing-Wellen&laquo; lesen
Dieser Beitrag Cybersecurity-Recap: PAN-OS-Auth-Bypass, Gogs-0-Day und KI-getriebene Phishing-Wellen erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3570472/IT+Sicherheit/Cybersecurity+Nachrichten/Cybersecurity-Recap%3A+PAN-OS-Auth-Bypass%2C+Gogs-0-Day+und+KI-getriebene+Phishing-Wellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570472/IT+Sicherheit/Cybersecurity+Nachrichten/Cybersecurity-Recap%3A+PAN-OS-Auth-Bypass%2C+Gogs-0-Day+und+KI-getriebene+Phishing-Wellen/</guid>
<pubDate>Wed, 03 Jun 2026 19:52:42 +0200</pubDate>
</item>
</channel> 
</rss>
<!-- Generated in 0,67ms -->