Home/ Blog/ Topics/ Phishing & social engineering
Topic

Phishing & social engineering

Credential theft, business email compromise, and the human-targeted attacks that open the door for everything else.

Security news

ShinyHunters beat MFA at ReliaQuest. Device trust stopped it.

ShinyHunters vished a ReliaQuest employee and got the MFA push approved, but device-trust rules blocked the theft.

Security news

A breach at shipping partner Ceva Logistics exposed customer data for Steam, ING and other brands

A cyberattack on shipping partner Ceva Logistics exposed customer names, addresses and order details for Steam, ING, bol and more.

Security news

Fake IT help-desk calls are stealing Microsoft 365 and Okta data

A vishing crew posing as IT help desk on personal phones steals Microsoft 365 and Okta sessions, then renames to dodge IOC lists. Here is how to detect it.

Security news

Device-code phishing jumped 1,500% in 2026: attackers take over Microsoft 365 accounts with no password or MFA

Device-code phishing rose 1,500% in 2026, letting attackers mint Microsoft 365 tokens with no password or MFA. Here is how to detect and block the OAuth flow.

Security news

Scattered Spider keeps winning because your help desk, not a CVE, is the way in

An extradited Scattered Spider suspect breached a retailer in under three hours through a help-desk password reset. Here is the identity control that stops it.

Security news

AI keeps inventing web addresses that do not exist. Attackers now buy them first.

Unit 42 found attackers registering the fake web domains AI models hallucinate, turning a chatbot's answer into a phishing and supply chain threat.

Security news

Hotels are running malware on a legitimate Node.js runtime, and that beats allowlisting

TonRAT runs on a genuine Node.js runtime on hotel front-desk machines, hides its C2 on the TON blockchain, and slips past allowlists. Here is what to hunt.

Security news

A rigged 7-Zip archive can erase the Windows warning on downloaded files, and there is no fix yet

A crafted RAR5 archive lets 7-Zip 26.02 strip the Mark-of-the-Web, defeating Windows SmartScreen warnings. No patch exists yet.

Security news

Signal's recovery key never expires, and Russian intelligence is now phishing for it

Russian intelligence is phishing Signal users for the Backup Recovery Key, a secret that decrypts a whole message history and that no reset or new account can

Security news

ClickFix is now shared attack infrastructure, and the lure is the wrong thing to detect

Three unrelated crews adopted ClickFix delivery in a single quarter. The lure keeps changing; the execution chain does not. Here is where to detect it.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.