Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
2+ day, 14+ hour ago (630+ words) A new phishing campaign is moving fake login pages into victims’ browsers. Rather than sending people to a malicious website, its operators use browser-generated blob URLs to assemble the page in local memory, leaving less for security tools to inspect…...
Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
2+ day, 18+ hour ago (629+ words) Mac users seeking AI tools face a malware trap. Attackers are using fake Claude and ChatGPT installers and sponsored search results to push MacSync, a macOS password stealer. The campaign relies on persuasion instead of a software flaw. A visitor…...
New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
2+ day, 17+ hour ago (557+ words) A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and disrupted, this campaign delivers malicious…...
Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
2+ day, 21+ hour ago (593+ words) The campaigns do not require a macOS vulnerability; instead, they abuse user trust by persuading victims to paste attacker-controlled commands into Terminal, sidestepping traditional file-centric protections. However, Russian-language artifacts observed in some samples do not establish attribution to a particular…...
Russian hackers may have used fake CAPTCHA to hack Ukrainian government computers
3+ day, 14+ hour ago (361+ words) A suspicious cyberattack using fake CAPTCHA checks to target a Ukrainian government organisation has been linked to Moscow, according to a new report. US tech giant Cisco said its cybersecurity researchers noticed unusual activity in the organisation's computer systems in…...
Bithumb warns of malware disguised as fake AI auto-trading tools, launches September cybersecurity campaign
3+ day, 4+ hour ago (445+ words) Bithumb is moving to prevent damage from malware disguised as artificial intelligence (AI) auto-trading programs or investment analysis tools. Bithumb said on Wednesday it will run a malware damage prevention campaign using "fake AI auto-trading programs and investment analysis tools…...
FBI warns of cyber actors deceiving individuals through ‘OAuth consent phishing’ | AHA News
3+ day, 8+ hour ago (185+ words) FBI warns of cyber actors deceiving individuals through ‘OAuth consent phishing’ American Hospital Association An FBI alert released Sept. 1 warns of cyber actors impersonating government officials, media and other public individuals on a commercial messaging app to target victims by…...
New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
3+ day, 18+ hour ago (434+ words) Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. Future phishing campaigns may no longer involve a detectable physical web page. The attack flow…...
Singpass passkey that turns mobile devices into digital keys to counter scams now available to Android users
3+ day, 21+ hour ago (469+ words) Published Sep 09, 2026, 11:37 AM Updated Sep 09, 2026, 11:41 AM SINGAPORE - A new mode of national authentication initially rolled out to Apple iPhone users has now been extended to Android phone users. National authentication system Singpass’ new passkey feature aims to foil phishing scams…...
Phishing attacks in 2026
4+ day, 14+ hour ago (339+ words) For years, IT departments trained employees to spot a phishing scam using a simple checklist: look for bad grammar, check the sender’s email address for slight misspellings and never click suspicious links. For a long time, that advice worked. But…...