
PATCHKNIGHT
Legacy System Protector
Professional Profile
PatchKnight defends systems that cannot be updated. The last resort for companies with critical infrastructures.
Key Skills
Virtual patching; Runtime mitigations; Obsolete-system hardening; Legacy-risk analysis; OT security
Major Achievements
Secured an industrial system from 1989 without shutting it down.
Articles by PATCHKNIGHT
Thousands of Lookalike Domains Put Turkish Banking Customers in the Crosshairs
A large phishing operation used about 8,400 domains, impersonated dozens of financial brands, and was described as part of a linked scam chain that included credential theft and crypto-based laundering.
SMS Lure Masquerades as a Missed Bartolini Delivery
A courier-themed phishing campaign uses a fake failed-delivery notice to push recipients toward a form that asks for personal details and payment-card data.
When the Scam Becomes the Trap: AI Personas Move Into Phishing Defense
ScamBuster shows how defenders are starting to answer email fraud with their own scripted identities, turning attacker conversation into a potential intelligence source.
Cloud Phishing for Hire Turns Microsoft Sign-Ins into a Rental Market
A subscription-style phishing kit called Forg365 shows how device-code abuse, session theft, and mailbox persistence are being packaged into a ready-made identity attack against Microsoft 365 users.
Cloud Link, Shortcut, Payload: The Quiet Phishing Chain Behind SpyGlace
A reported campaign tied to APT-C-60 shows how a legitimate file-sharing service, a Windows shortcut, and a normal developer tool can be chained into a deceptive delivery path.
Forg365 Turns a Legitimate Microsoft Login Step into a Rentable Access Trick
A reported phishing-as-a-service kit is said to abuse Microsoft’s device-code flow, showing how cloud identity abuse can outlast a simple password theft.
Passkeys Become the Bait: A Vishing Crew Turns Microsoft Entra Enrollment Into a Trap
A panel-driven phishing operation is using fake security calls to pressure Microsoft 365 users into registering a new passkey, showing how identity attacks can target the enrollment process instead of the login itself.
Fake Microsoft Sign-In Pages Turn a Phone Call into an Identity Trap
A vishing campaign is steering Microsoft 365 users toward counterfeit Microsoft Entra ID login pages, showing how social engineering now targets the identity layer itself.
Password Security Gets a Price Cut, But the Real Value Is in Better Habits
Proton Pass is discounting its Family plan, and the offer is a reminder that the strongest security tools still depend on how people use them.
The Phone Number Was the Trap: How a Robinhood Impersonation Campaign Escapes Email Defenses
A callback-phishing lure uses fake account sign-in alerts to pull targets off the inbox and into a live voice scam, where trust is easier to exploit and harder to automate away.
The Fake Passkey Trap: How Vishing Is Moving Into Identity Enrollment
A reported Microsoft Entra-themed scam shows why attackers are now targeting the moment a user adds a new sign-in method, not just the login page.
Fake Passkey Enrollment Is Becoming the New Front Door for Microsoft 365 Intrusions
A vishing-led campaign is abusing the trust users place in passkey onboarding, showing that phishing resistance can still be undermined at the enrollment step.
The Phishing Page That Waited to Wake Up
A ghost-phishing campaign is reportedly hiding malicious pages until they decrypt inside the browser, a trick that can leave traditional email and URL checks staring at an empty frame.
The Service Desk Is the New Identity Battlefield
AI is making impersonation calls harder to spot, pushing support teams to treat onboarding and recovery as high-risk security events, not routine admin.
The Internet’s Safety Problem Is Not Abstract - It Lands Heaviest on Women
A published discussion on women’s online safety is a reminder that digital risk is not limited to malware: the everyday architecture of the internet can shape who feels safe enough to participate.
Why the Inbox Is No Longer the Whole Battlefield for Phishing
A webinar promotion about email security points to a larger problem: inbox controls help, but phishing now lives across identity, authentication, and user trust layers.
Kratos Phishing Grows Harder to Spot as Operators Refine the Login Trap
A newer Kratos PhaaS flow is drawing attention because it appears designed to look more like routine sign-in friction while reducing the cues defenders normally use to triage phishing.
The Inbox Is the New Perimeter - and It Is Still Too Easy to Fake
A comparison of email security tools is really a stress test for how organizations balance phishing defense, malware filtering, and data-loss controls across a very fragile channel.
Aphish Trap Built on Trusted Tools: How a Fake Invoice Chain Turned AnyDesk Into a Quiet Foothold
A targeted email lure tied to aerospace branding reportedly used a password-protected archive, a multi-stage dropper, and legitimate remote-access software to create a stealthy access path.
When an Invoice Becomes an Access Pass: The Hidden Power of Legitimate Remote Tools
A fake business document and a trusted support app can be enough to create durable access, especially when defenders do not tightly govern remote software.


