Cybercriminals are using old-school "vishing" (voice phishing) phone calls to employees' personal devices, posing as IT helpdesk staff to steal…
Read More »phishing-as-a-service
Phishing has become the primary initial attack vector in over half of all cyber incidents investigated, a sharp increase from…
Read More »Google filed a lawsuit against a Chinese-operated network called Outsider Enterprise, accusing it of running a massive AI-driven scam operation…
Read More »A major international law enforcement operation called Operation Ramz, spanning 13 countries in the MENA region from October 2025 to…
Read More »Cybercriminals have compromised at least 350 hotels and accommodations across 50 countries to steal real booking details, using them in…
Read More »The FBI warns about Kali365, a phishing-as-a-service platform that targets Microsoft 365 accounts by abusing OAuth device code authentication to…
Read More »Bluekit is a new phishing-as-a-service platform offering over 40 ready-made templates for major services (email, cloud, crypto) and an AI…
Read More »Phishing exploits human psychology, using urgency and emotional timing to bypass rational thought and target individuals during vulnerable moments, making…
Read More »Account compromise incidents surged by 389% in 2025, with credential theft becoming the primary attack method, representing 75% of all…
Read More »A sophisticated phishing technique called Browser-in-the-Browser is resurging, embedding fake login windows within legitimate webpages to steal credentials by mimicking…
Read More »Phishing in 2025 became more sophisticated and identity-focused, with attacks increasingly occurring outside of email through channels like LinkedIn and…
Read More »The cybercrime landscape has evolved into a **subscription-based service model**, where even low-skill individuals can rent sophisticated hacking tools and…
Read More »Sneaky2FA phishing platform now uses browser-in-the-browser attacks to create convincing fake Microsoft login windows that adapt to victims' systems, bypassing…
Read More »The Tycoon 2FA phishing kit enables attackers to easily bypass multi-factor authentication by using automated tools and fake login portals,…
Read More »Google has uncovered and taken legal action against the massive "Lighthouse" text message scam operation, which has targeted individuals in…
Read More »Google has filed a lawsuit to dismantle the Lighthouse phishing-as-a-service platform, which has enabled global cybercriminals to execute SMS phishing…
Read More »The Quantum Route Redirect phishing-as-a-service platform enables even unskilled cybercriminals to launch widespread credential theft campaigns across 90 countries, significantly…
Read More »Microsoft and Cloudflare dismantled the RaccoonO365 phishing-as-a-service scheme, which harvested thousands of Microsoft 365 credentials through deceptive campaigns. The operation…
Read More »Microsoft and Cloudflare dismantled the RaccoonO365 phishing-as-a-service operation, seizing 338 websites and crippling its infrastructure. The phishing kit bypassed multi-factor…
Read More »

















