threat-intel ISC Stormcast For Wednesday, May 27th, 2026 https://isc.sans.edu/podcastdetail/9946, (Wed, May 27th) The SANS Internet Storm Center's Stormcast for May 27th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The broadcast detailed ongoing campaigns involving phishing attacks… SANS Internet Storm Center · May 27, 2026 Medium phishingmalwareemail
phishing FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required The FBI has issued a warning about Kali365, a phishing-as-a-service kit that allows attackers to compromise Microsoft 365 accounts without needing passwords, even when MFA is enabled. This kit leverages device code flow,… Graham Cluley · May 26, 2026 High USCAGBmfadevice-code-flowphishing
threat-intel Iranian APT Targets Aviation, Software Companies With Updated Tools The Iranian APT group, known as Nimbus Manticore, has been aggressively updating its tactics and tools to target aviation and software companies globally. The group, linked to Charming Kitten and the IRGC, is employing… SecurityWeek · May 26, 2026 High AEIRSAaptphishingappdomain
threat-intel BTMOB: A stealthy RAT burrowing deep into Android devices BTMOB is a stealthy Android remote access trojan (RAT) that’s rapidly evolving and spreading through phishing campaigns and a ‘malware-as-a-service’ model. It allows attackers to steal data, take control of devices, and… WeLiveSecurity · May 26, 2026 High ARandroidmalwareremote access trojan
malware Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning Iranian state-sponsored threat actor Nimbus Manticore (UNC1549) has launched a new campaign utilizing the MiniFast backdoor, developed with potential AI assistance, to target organizations in the aviation and software se… The Hacker News · May 26, 2026 High SAAUIRphishingbackdoorappdomain hijacking
phishing FBI warns of Kali365 phishing service targeting Microsoft 365 accounts The FBI has issued a warning about Kali365, a phishing-as-a-service (PhaaS) platform, being used to target Microsoft 365 accounts. This platform leverages device code authentication to bypass multi-factor authentication… BleepingComputer · May 25, 2026 High USphishingoauthmfa
phishing FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks The FBI has issued a warning about Kali365, a Telegram-based phishing-as-a-service platform, following its use in April attacks targeting Microsoft 365 accounts. This service lowers the barrier to entry for cybercriminal… The Record · May 22, 2026 High USphishingoauthmfa
phishing Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware The Ghostwriter threat actor, linked to Belarus, has been conducting a phishing campaign targeting Ukrainian government entities since the spring of 2026. This campaign utilizes lures related to the Prometheus online lea… The Hacker News · May 22, 2026 High UKBERUphishingmalwarecobalt strike
threat-intel Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise As the 2026 FIFA World Cup approaches, scammers are exploiting fans’ desire for tickets and merchandise by creating convincing fake websites mimicking FIFA’s official channels. These sites use tactics like typosquatting… WeLiveSecurity · May 22, 2026 High phishingsocial engineeringdomain spoofing
threat-intel ISC Stormcast For Friday, May 22nd, 2026 https://isc.sans.edu/podcastdetail/9942, (Fri, May 22nd) The SANS Internet Storm Center's Stormcast for May 22nd, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 22, 2026 Medium phishingvulnerabilitythreat-intelligence
threat-intel Belarus-linked hackers use fake training certificates to target Ukrainian officials A Belarus-linked hacking group, GhostWriter (UNC1151/Storm-0257), is conducting a new espionage campaign targeting Ukrainian government officials. The operation utilizes sophisticated phishing emails disguised as trainin… The Record · May 21, 2026 High UABYphishingmalwareespionage
ransomware Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet This article details the evolving landscape of cryptocurrency drainer operations, specifically focusing on the rise of "Drainer-as-a-Service" (DaaS) platforms like "Lucifer." These operations, rather than relying on dire… BleepingComputer · May 21, 2026 High USdrainerdaascryptocurrency
threat-intel ISC Stormcast For Thursday, May 21st, 2026 https://isc.sans.edu/podcastdetail/9940, (Thu, May 21st) The SANS Internet Storm Center's Stormcast for May 21st, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 21, 2026 Medium phishingvulnerabilitythreat intelligence
threat-intel ISC Stormcast For Wednesday, May 20th, 2026 https://isc.sans.edu/podcastdetail/9938, (Wed, May 20th) The SANS Internet Storm Center's Stormcast for May 20th, 2026 highlighted several ongoing and emerging cyber threats. The broadcast detailed a concerning increase in phishing campaigns targeting financial institutions an… SANS Internet Storm Center · May 20, 2026 Medium phishingddosmalware
threat-intel The New Phishing Click: How OAuth Consent Bypasses MFA In February 2026, a phishing-as-a-service platform, EvilTokens, compromised over 340 Microsoft 365 organizations across five countries by exploiting OAuth consent screens. Attackers gained access to valid refresh tokens… The Hacker News · May 19, 2026 High USGBoauthconsentphishing
threat-intel ISC Stormcast For Tuesday, May 19th, 2026 https://isc.sans.edu/podcastdetail/9936, (Tue, May 19th) The SANS Internet Storm Center's Stormcast for May 19th, 2026 highlighted a concerning increase in observed malicious activity across the internet. Specifically, the report detailed heightened phishing campaigns and a no… SANS Internet Storm Center · May 19, 2026 Medium phishingbotnetddos
threat-intel INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests INTERPOL’s Operation Ramz was a coordinated international effort involving 13 MENA countries to combat cybercrime, resulting in 201 arrests and the disruption of phishing and malware operations. The operation targeted in… The Hacker News · May 18, 2026 High AEALBHcybercrimephishingmalware
phishing How to Reduce Phishing Exposure Before It Turns into Business Disruption This article discusses the increasing risk posed by phishing attacks, particularly due to their ability to quickly escalate into significant business disruptions. It highlights the challenges SOC teams face in identifyin… The Hacker News · May 18, 2026 High USphishingsandboxcredential theft
threat-intel Why geopolitical turmoil is a gift for scammers, and how to stay safe Geopolitical turmoil is being exploited by scammers to increase the success of their fraudulent schemes. The article details a range of scams – from fake charities and romance fraud to investment scams and sensational fa… WeLiveSecurity · May 15, 2026 Medium IRMIscamsfraudcybercrime
threat-intel ISC Stormcast For Friday, May 15th, 2026 https://isc.sans.edu/podcastdetail/9934, (Fri, May 15th) The SANS Internet Storm Center's Stormcast for May 15th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 15, 2026 Medium phishingvulnerabilitythreat intelligence