Skip to content
tag — phishing

grep -rl "phishing" ./articles

#phishing

8 articles

The call is about your passkey. The break-in uses routes a passkey alone does not close

2026-09-15Security

Microsoft says extortion groups tied to ShinyHunters and Helix are phoning staff about urgent passkey or single sign-on updates, then steering them into relayed sign-ins or device-code approvals. Once in, they register an MFA method of their own, map the tenant through Microsoft Graph and take files at under 1,000 an hour to stay unremarkable.

The Trezor phishing needed no stolen password. Brevo's SSO let the attacker sign in as the people they invited

2026-09-15Security

Phishing that reached 347,000 Trezor newsletter subscribers came from Trezor's genuine Brevo account, so it passed every sender check. Brevo's post-mortem says the attacker created an account, switched on single sign-on, invited real Brevo users into it, and was then let into every organisation those users could reach. Early coverage spoke of stolen login details. Brevo's account involves none.

The malware reads its orders out of an FTP welcome message, before it even logs in

2026-08-23Security

MalwareHunterTeam spotted the technique in July and SOCRadar says it is still running. A phishing ZIP drops a shortcut file, the shortcut connects to an FTP server and takes commands from the greeting banner, and either E4del or PINHOLE lands. Novel — and SOCRadar notes that being novel is also what makes it visible.