Martes 28 Julio 2026 15:26:54 GMT+02:00

Netcrook

InicioManifiesto
Noticias
Techcrook
Geocrook
WikicrookEquipoAppContactoLogin
EnglishItaliano

#phishing


When Confidential Messages Leave the Office, the Phone Becomes the Perimeter

Published: 28 July 2026 10:45Category: Security Awareness & Social EngineeringGeo: Europe / ItalyAuthor: PATCHKNIGHT

Italian SMEs and public offices are facing a quieter but harder problem: protecting sensitive communications as smartphones, cloud services, and collaboration apps pull them beyond traditional boundaries.

When One Remote Tool Falls, Another May Still Be Waiting

Published: 28 July 2026 08:18Category: Cyber Intelligence & Threat TrendsAuthor: GHOSTCOMPLY

A phishing-led intrusion pattern shows how legitimate admin software can be turned into a backup access channel that survives partial cleanup.

Hotel Wi-Fi Turns into a Cloud Identity Snare

Published: 28 July 2026 02:05Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

ReliaQuest-linked findings point to compromised hospitality gateways being used against Microsoft 365 sign-ins, showing how network control can become an identity attack surface.

Hotel Wi-Fi Became the Trapdoor to Microsoft 365

Published: 27 July 2026 18:14Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A compromise at the network edge can turn a routine travel login into a credential-and-token capture event, with cloud identity as the real target.

ShinyHunters Claim Puts EY Breach in the Spotlight, But the Path Remains Unproven

Published: 27 July 2026 18:08Category: Breaches & Data LeaksGeo: Europe / United KingdomAuthor: BYTESHIELD

The alleged credential theft tied to Ernst & Young is a reminder that supply-chain claims can signal risk even before the technical details are confirmed.

Autonomous AI Moves From Lab Curiosity to Espionage Tool in a Thai Government Case

Published: 27 July 2026 17:01Category: Cyber Warfare & Nation-State OperationsGeo: Asia / ThailandAuthor: AGONY

Researchers identified a cyber-espionage campaign targeting Thailand’s Ministry of Finance in which hackers reportedly used an autonomous AI agent, a signal that agentic systems are entering offensive tradecraft.

Fake Teams Update, Real Remote Access: The BlueDash Playbook

Published: 27 July 2026 16:46Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A counterfeit Microsoft Teams update flow is being used to push legitimate remote management tools onto victim systems, blurring the line between phishing and admin software abuse.

When the Lobby Hotspot Turns Hostile: Public Wi-Fi Gear and the Microsoft 365 Trap

Published: 27 July 2026 14:24Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

Compromised wireless gateways can become a quiet interception layer for travelers, turning ordinary cloud sign-ins into credential risk without ever touching the inbox itself.

Inside the Benefits File Heist: Why Dental Data Is Now High-Value Criminal Currency

Published: 27 July 2026 12:11Category: Breaches & Data LeaksGeo: North America / USAAuthor: BYTESHIELD

A breach at DentaQuest puts a spotlight on a less visible target class: the claims and benefits systems that can concentrate identity, billing, and health-related records in one place.

Fake Download Traps Turn Windows Search Into a Malware Magnet

Published: 27 July 2026 12:04Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A large impersonation campaign used clone domains, copied branding, and AI-written pages to make bogus Windows app sites look routine and trustworthy.

The Promo Trap Hidden in Plain Sight: Why a Streaming Discount Can Become a Security Story

Published: 27 July 2026 10:36Category: Technology, Innovation & Digital InfrastructureGeo: Europe / ItalyAuthor: TRUSTBREAKER

Disney+ is running a time-limited offer in Italy, and the technical fine print around renewal, identity, and cancellation is where the real risk lives.

When a Stolen Chat Becomes the Next Attack Vector

Published: 27 July 2026 10:34Category: Cyber Warfare & Nation-State OperationsGeo: Asia / North KoreaAuthor: AGONY

A trust-based campaign tied to BlueNoroff shows how compromised messaging accounts and fake meetings can turn one breach into the next.

When a Meeting Invite Becomes a Malware Stage: BlueNoroff’s Browser Trap

Published: 27 July 2026 08:13Category: Security Awareness & Social EngineeringGeo: Asia / North KoreaAuthor: PATCHKNIGHT

A fake video-call lure, webcam permission prompts, and Defender tampering show how modern phishing can behave like a targeted intrusion chain rather than a simple credential scam.

Education Data Claim Lands on an Extortion Wall, But the Breach Remains Unproven

Published: 26 July 2026 14:19Category: Ransomware & ExtortionGeo: Europe / United KingdomAuthor: LOGICFALCON

A victim listing names the UK Department for Education and describes two contact datasets, but the public claim still falls short of confirmed compromise.

The QR Trap: How Quishing Turns Email Into a Mobile Ambush

Published: 26 July 2026 10:04Category: Security Awareness & Social EngineeringAuthor: PATCHKNIGHT

QR-code phishing is growing fast because it moves the scam out of text filters and into the scan step, where a personal phone may become the attacker’s real launchpad.

Insurance Phishing Has Learned to Move at the Speed of a Login

Published: 25 July 2026 14:08Category: Security Awareness & Social EngineeringGeo: Middle East / BahrainAuthor: NEURALSHIELD

CTM360-linked research points to a shift from delayed credential theft to real-time account hijacking, a change that shrinks the defender’s window from hours to seconds.

Stolen Browser Sessions Are Pushing Ransomware Past MFA

Published: 25 July 2026 12:08Category: CybercrimeAuthor: CIPHERWARDEN

Stealer logs are being used to support ransomware access paths that can bypass MFA in some environments.

Scripted and Hidden: The Phantom Stealer Chain Riding on Business Trust

Published: 25 July 2026 10:03Category: Malware & BotnetsAuthor: IRONQUERY

A phishing lure impersonating a logistics workflow and a two-step script chain show how credential theft now depends less on flashy exploits and more on ordinary Windows tools.

Trusted Labels, Hidden Payloads: How a Fake Logistics Email Became a Malware Delivery Trap

Published: 25 July 2026 08:04Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A phishing run dressed up as shipping notices and tax-audit mail shows how attackers can turn everyday business trust into a credential-theft pipeline.

The Phishing Link That Could Have Turned an AI Workspace Into a Rogue Operator

Published: 24 July 2026 19:14Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A reported flaw in ChatGPT Workspace Agents shows how one click can become an agent-launch event, not just a browser detour.