Dimanche 12 Juillet 2026 16:51:52 GMT+02:00

Netcrook

AccueilManifeste
Actualités
Techcrook
Geocrook
WikicrookÉquipeAppContactLogin
EnglishItaliano

Security Awareness & Social Engineering


Forg365 Turns a Legitimate Microsoft Login Step into a Rentable Access Trick

Published: 10 July 2026 19:35Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A reported phishing-as-a-service kit is said to abuse Microsoft’s device-code flow, showing how cloud identity abuse can outlast a simple password theft.

Forg365 Turns Microsoft 365 Phishing Into a Bought-and-Sold Access Business

Published: 10 July 2026 18:24Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A Telegram-linked phishing service shows how identity theft now borrows the mechanics of SaaS, combining device-code abuse, token persistence, and AI-written lures.

Passkeys Become the Bait: A Vishing Crew Turns Microsoft Entra Enrollment Into a Trap

Published: 10 July 2026 14:46Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A panel-driven phishing operation is using fake security calls to pressure Microsoft 365 users into registering a new passkey, showing how identity attacks can target the enrollment process instead of the login itself.

Fake Microsoft Sign-In Pages Turn a Phone Call into an Identity Trap

Published: 10 July 2026 14:24Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A vishing campaign is steering Microsoft 365 users toward counterfeit Microsoft Entra ID login pages, showing how social engineering now targets the identity layer itself.

Password Security Gets a Price Cut, But the Real Value Is in Better Habits

Published: 10 July 2026 12:51Category: Security Awareness & Social EngineeringGeo: Europe / SwitzerlandAuthor: PATCHKNIGHT

Proton Pass is discounting its Family plan, and the offer is a reminder that the strongest security tools still depend on how people use them.

When Antivirus Starts Hunting Lies: Avast’s AI Pitch Shows Where Scam Defense Is Headed

Published: 10 July 2026 12:42Category: Security Awareness & Social EngineeringGeo: Europe / Czech RepublicAuthor: NEURALSHIELD

A discount may be the headline hook, but the technical story is the shift from malware blocking to detecting phishing, fake websites, and synthetic media before users act.

The Phone Number Was the Trap: How a Robinhood Impersonation Campaign Escapes Email Defenses

Published: 10 July 2026 10:18Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A callback-phishing lure uses fake account sign-in alerts to pull targets off the inbox and into a live voice scam, where trust is easier to exploit and harder to automate away.

The Phone Call Was the Trap: Robinhood-Style Alerts Turn Trust into a Weapon

Published: 10 July 2026 10:16Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A callback-phishing campaign uses fake sign-in warnings to push recipients away from inbox checks and into attacker-controlled voice channels.

Phone Calls, Fake Managers, and the Cloud Trail to SharePoint

Published: 10 July 2026 02:08Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A reported extortion crew called Helix illustrates how voice phishing, device-code abuse, and MFA weak spots can turn identity trust into a path toward SharePoint data.

Forg365 and the New Business of Stealing Microsoft 365 Sessions

Published: 10 July 2026 02:06Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A freshly described phishing service shows how cloud-account theft is becoming a packaged identity operation, blending relay tactics, OAuth abuse, and AI-assisted lures.

Forg365 and the New Face of Microsoft 365 Theft: Phishing for Sessions, Not Just Passwords

Published: 09 July 2026 18:24Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A reported phishing-as-a-service kit blends AiTM relays, device-code abuse, and AI-written lures, showing how identity attacks are being packaged for reuse.

The Fake Passkey Trap: How Vishing Is Moving Into Identity Enrollment

Published: 09 July 2026 15:24Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A reported Microsoft Entra-themed scam shows why attackers are now targeting the moment a user adds a new sign-in method, not just the login page.

The Helpdesk That Wasn't: How Teams Chats Are Becoming the New Phishing Front

Published: 09 July 2026 10:32Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A fake support conversation, paired with targeted email pressure, shows how trusted collaboration tools can be used to sell a malicious download without any confirmed exploit in the platform itself.

Fake Passkey Enrollment Is Becoming the New Front Door for Microsoft 365 Intrusions

Published: 09 July 2026 10:17Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A vishing-led campaign is abusing the trust users place in passkey onboarding, showing that phishing resistance can still be undermined at the enrollment step.

The Phishing Page That Waited to Wake Up

Published: 08 July 2026 18:47Category: Security Awareness & Social EngineeringAuthor: PATCHKNIGHT

A ghost-phishing campaign is reportedly hiding malicious pages until they decrypt inside the browser, a trick that can leave traditional email and URL checks staring at an empty frame.

The Service Desk Is the New Identity Battlefield

Published: 08 July 2026 18:38Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

AI is making impersonation calls harder to spot, pushing support teams to treat onboarding and recovery as high-risk security events, not routine admin.

The Internet’s Safety Problem Is Not Abstract - It Lands Heaviest on Women

Published: 08 July 2026 16:19Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A published discussion on women’s online safety is a reminder that digital risk is not limited to malware: the everyday architecture of the internet can shape who feels safe enough to participate.

Why the Inbox Is No Longer the Whole Battlefield for Phishing

Published: 08 July 2026 16:10Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A webinar promotion about email security points to a larger problem: inbox controls help, but phishing now lives across identity, authentication, and user trust layers.

ClickFix Is Winning by Making the Victim Press Enter

Published: 08 July 2026 14:32Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A sharp rise in ClickFix detections shows how browser lures, fake errors, and trust-themed prompts are turning ordinary users into the execution path.

Tax-Branded Phishing Goes Multi-Stage, Ending in Two Remote-Control Malware Families

Published: 08 July 2026 10:57Category: Security Awareness & Social EngineeringGeo: Asia / IndiaAuthor: NEURALSHIELD

A phishing lure impersonating India’s tax authority reportedly used fake government branding and a six-step delivery path to reach in-memory RAT-style payloads.