Public entries tagged #phishing

New phishing campaign alert.

The Federal Bureau of Investigation warns criminals are impersonating city and county officials to request fraudulent zoning permit payments.

Attackers leverage public permit records to craft convincing emails.
Verify payment requests carefully.

Source: ic3.gov/PSA/2026/PSA260309

Follow @technadu for infosec updates.

Continue reading →

⚠️ Attackers are hijacking Microsoft accounts without stealing passwords.

OAuth Device Code tricks users into approving logins on M365 pages, granting token-based access to corporate email and files.

How to defend against this breach vector👇
any.run/cybersecurity-blog/oau

Continue reading →

Dutch intelligence agencies warn of a phishing campaign targeting Signal and WhatsApp accounts of government officials and military personnel.

Attackers impersonate support channels to obtain verification codes and hijack accounts.

technadu.com/russian-cybercrim

Continue reading →

A researcher infiltrated phishing panels targeting European banks after analyzing a phishing email impersonating Argenta.
Weak IP-based auth and plaintext logs exposed attacker infrastructure.
Tools like Burp Suite helped access the panel and disrupt campaigns.
Phishing kits remain dangerously accessible.

Source: inti.io/p/how-i-infiltrated-ph

Follow TechNadu for infosec updates.

Continue reading →

An EU court adviser suggests banks should immediately refund phishing victims after unauthorized transactions are reported.

Under the EU Payment Services Directive, refunds should come first - unless there’s evidence of customer fraud.

technadu.com/immediate-restitu

Should banks bear greater responsibility for phishing losses?

Continue reading →

Pivot across Mastodon instances via default trust and UI logic gaps. Zero complex exploits, pure OSINT and SE to target remote users. Elite vector for user acquisition in high-LTV fediverse niches. Read to harden trust boundaries or refine initial access. Offensive insights, defensive value.

Continue reading →

Subscribe to #phishing entries via RSS feed