Direct Send: How Attackers Weaponize Your Infrastructure Against You

Lead Analysts: Prabhakaran Ravichandhiran, Jeewan Singh Jalal

Warning: Chameleon SEO Poisoning Spreads Phishing Pages

Cloaked SEO poisoning attacks surged by 40% in the second quarter of 2026, according to researchers at Fortra. This tactic, also known as “Chameleon SEO poisoning,” uses cloaked search ...

The .vu Surge: How Threat Actors Are Exploiting Vanuatu's Domain Extension

Lead Analysts: Prabhakaran Ravichandhiran, Jeewan Singh Jalal, Karthikeyan Dharmaraj and Sripathi Kumar

New Phishing Kit Gives Threat Actors Live View Into Attacks

A new phishing platform called “JWR” gives attackers real-time control over social engineering attacks, according to researchers at Cisco Talos. The kit livestreams the phishing page to ...

Voice Phishing Attacks Target Hedge Fund Employees

Google’s Threat Intelligence Group (GTIG) is tracking a voice phishing (vishing) campaign that’s targeting hedge funds and financial firms. The researchers attribute the attacks to ...

Warning: Malicious AI Tools Are Spreading in the Criminal Underground

Criminals are now selling malicious AI tools for use in cyberattacks, according to researchers at Trellix. These tools dramatically lower the barrier for unskilled crooks to launch ...

Report: Phishing Remains the Primary Initial Access Vector

Phishing is still the top initial access vector, accounting for more than half of cyberattacks observed during Q2 2026, according to a new report from Cisco Talos.

Report: Vishing and Device Code Phishing Are Surging

Social engineering remains a central part of modern cyberattacks, according to a new report from CrowdStrike. Attackers are increasingly turning to voice phishing because it bypasses ...

Microsoft Observed 7.6 Billion Phishing Emails in Q2 2026

Researchers at Microsoft warn that phishing emails are still the top initial access vector, with more than 2 billion phishing threats detected each month during the second quarter of 2026.

Warning: Compromised Hotel Routers Send Users to Phishing Sites

Attackers are using compromised hotel Wi-Fi routers to redirect users to Microsoft 365 phishing sites, according to researchers at ReliaQuest. The attacks were observed in multiple U.S. ...