mitre-t1566
1740 articles with this tag
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
India’s STPI serves TerminalFix-style attack via fake Cloudflare check
Crypto customers targeted by scammers after email marketing provider breach
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Android malware creates a hidden copy of your banking app
Attackers use passkey-themed scams to hijack Microsoft 365 accounts
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Attackers are weaponizing the gap between Chromium fixes and Chrome patches
A real Carnival Cruise Line email was serving customers malware
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Detect and disrupt AI-themed attacks with Microsoft Defender
BlueMoon exploit kit turns Chrome and Windows flaws into attacks
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
Attackers call employees’ personal phones to break into Microsoft 365 accounts
Copyright scammers get Instagram accounts suspended and demand payment
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Anatomy of a Silent Domain Takeover
BigBear phishing crew nets thousands of Microsoft 365 credentials
ASCII smuggling isn't just an AI security risk
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Cybercriminals are building phishing pages that exist only inside victims’ browsers
Revolut scam wave steals £180,000 from Jersey residents in just four weeks
Passkey-themed social engineering leads to identity and cloud compromise
Cybercriminals are building phishing pages that exist only inside victims’ browsers
Gigabud banking trojan uses app cloning to evade fraud detection
DoppelCart operation uses over 119,000 fake domains to steal payment card details
Russian national extradited to US for alleged bank fraud scheme
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Passkey-themed social engineering leads to identity and cloud compromise
REVSTEALER ramps up: analysis of up-and-coming infostealer
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Gigabud Uses Android App Cloning to Evade Fraud Detection
Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
BigBear 2.0 phishing campaign compromises MFA-protected Microsoft accounts
Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab
New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
CRPx0 ransomware: what you need to know
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Russian national extradited to US for alleged involvement in bank-account takeover scheme
NCSC-2026-0347 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Azure
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Inside Knight Office, a New M365 AiTM Phishing Kit
Daisy-Chaining Trust: Investigating Faronics Deploy Abuse
BigBear phishing crew nets thousands of Microsoft 365 credentials
Trezor customers hit with phishing calls and letters after shipping-partner breach
IT help-desk vishing tricks executives into handing over Microsoft 365 access
BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
Trezor Supply Chain Breach Now Impacts 81,000 Customers
Hacking AI customer service agents (Bug Bounty Village DEF CON 34)
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast
Million-dollar phishing campaign uses invisible Unicode characters to bypass email filters
ASCII smuggling challenges email phishing filters, Microsoft warns
ASCII smuggling isn't just an AI security risk
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
‘Empty envelope’ email attacks target company leaders
X Money rollout linked to password-reset attacks
Large Enterprises Targeted in Fake Merger & Acquisition Scams
Phishing campaign targets widely used RMM platforms in 46 countries
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
ASCII smuggling crosses over from AI prompt injection to phishing evasion
New 'Spring Ring' operation uses vishing via Microsoft Teams
StreamRat Android malware spreads through Meta and TikTok ads
Outsider Phishing Kit Survives Takedown With 700 New Pages
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
'Breeze Comet' Tears Into Brazilian & Global Financial Systems
QR Phishing With No Image: Text-Only QR Codes for Inboxes w/ Images Disabled
FBI warns of sophisticated phishing attacks targeting high-profile individuals
New PackClient RAT sold on Telegram
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
Revolut scam wave steals £180,000 from Jersey residents in just four weeks
Mobile Banking Fraud 2026: Malware Is Actively Targeting Mobile Banking Apps in the US and Canada
Attackers are going after prominent individuals through OAuth phishing, FBI warns
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
FBI raises alarm over deceptive phishing campaign targeting prominent people
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
Mobile Fraud in 2026: Malware is Actively Targeting Mobile Banking Apps in Asia-Pacific & Japan
Fake Claude Opus 5 app delivers malware and wipes its own tracks
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
Healthcare Giant McKesson Investigates Data Breach Incident
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
McKesson discloses data breach after ShinyHunters claims theft of 284 million records
McKesson copes with fallout from data theft extortion attack
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
McKesson confirms cyber incident after ShinyHunters claims patient-data theft
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets