
Trezor email-provider breach fuels targeted crypto phishing
A breach at a Trezor email provider is being followed by phishing that uses trust in the brand and breach-related urgency to target crypto users.
Modern phishing exploits trust, urgency and familiar workflows. This hub tracks verified campaigns and techniques, with emphasis on identity verification, payment controls and resilient user-facing defenses.

A breach at a Trezor email provider is being followed by phishing that uses trust in the brand and breach-related urgency to target crypto users.

Passkey-themed social engineering is being used to compromise identities, maintain access, and reach Microsoft cloud data through familiar authentication and collaboration services.

A reported sale of Condé Nast account data may fuel targeted phishing, but the advertised size and exposed fields remain unconfirmed.

A fake CAPTCHA can become a network foothold when it persuades someone to paste a command into PowerShell.

A trusted workplace interface can make a scammer look legitimate even when the criminal controls the account and the evidence.

The promise of an interview is being used to persuade job seekers to hand spyware control of their phones.

A confirmed social-engineering event exposed a password and briefly opened an identity-system window; larger attacker claims remain unverified.

A threat actor posing as a cryptocurrency-media representative targeted cybersecurity professionals with invitations and documents tied to a fake conference. The campaign used trusted collaboration tools such as…

Suspected Russian espionage clusters are abusing legitimate Google and WhatsApp authentication flows to target government, defence, aerospace and research communities in Europe and the US.

Paying a bill online often begins with a search for the provider’s website. The US Federal Trade Commission warns that the first result may be a paid advertisement…

CERT Polska has observed active exploitation of a Zimbra Collaboration vulnerability, raising the priority for organizations still running exposed or unpatched mail servers.

Attackers are increasingly moving identity phishing into collaboration services that employees already trust. Palo Alto Networks Unit 42 documented campaigns using platforms such as Microsoft Teams, Slack and…

Scammers are imitating cryptocurrency anti-money-laundering services and using the appearance of a security check to obtain wallet permissions. Malwarebytes researchers documented sites that copied the branding and language…

The FBI’s Boston Division is warning about an impersonation scam that begins with a caller pretending to represent a financial institution. The target is told that their identity…

A breach at France’s tax authority exposed data tied to 678,000 people, creating not only a privacy issue but a powerful new source of material for follow-on fraud.

Volksbank is warning customers about fraudsters posing as bank security staff, a familiar scam pattern that remains effective because it combines urgency with trusted-brand impersonation.

Dozens of organizations in the United States and Canada were targeted by criminals posing as help-desk staff through Microsoft Teams, according to Sophos research reported by Cybersecurity Dive.…

An Austria-led investigation supported by Europol and Eurojust dismantled an Albania-based call-centre network targeting victims across Europe and beyond.

The UK NCSC and international partners exposed a campaign using zero-click techniques against organisations running Zimbra collaboration software.

Lidl disclosed that attackers accessed a separately stored customer-data file at an external service provider. The breach affected online-shop customers in Germany, Belgium and the Netherlands and exposed…

Operation First Light 2026 targeted social-engineering scams across 97 countries and intercepted about $293 million in illicit assets.

Kaspersky documented a campaign distributing malicious script files through WhatsApp that installed legitimate remote-monitoring software for unauthorized access. Kaspersky Securelist published the underlying report or notice on 2026-06-22, placing the event within the month’s

Proofpoint reported that suspected North Korean actors used fake recruitment and coding assignments to infect developers and steal cryptocurrency. Proofpoint published the underlying report or notice on 2026-06-09, placing the event within the month’s

Unit 42 observed attackers contacting employees through Microsoft Teams while impersonating IT support and guiding targets into remote access or credential theft. Palo Alto Networks Unit 42 published the underlying report or notice on
Today’s strongest security actions concern two exploited or highly actionable vulnerabilities. NetScaler administrators should assess affected configurations and patch the authentication-bypass issue, for which proof-of-concept code is reportedly available. N-able N-central on-premises customers should urgently upgrade because exploitation attempts have been observed. Magento and Adobe Commerce merchants should verify the vendor’s guidance and investigate possible persistence rather than relying on patching alone. The reported Condé Nast database sale remains only partly confirmed, and the loyalty-points item is educational guidance rather than evidence of a specific breach.
February compressed the time available for defense. Microsoft reported six zero-days under active exploitation, Ivanti mobile-management flaws affected a growing victim set, and phishing-as-a-service tooling relayed credentials and MFA codes in real time. At the same time, ransomware disrupted a payment provider and software-update infrastructure remained a credible route to compromise.\n\nThe connection is speed plus trust abuse. Attackers did not need to defeat every security layer directly; they could steal valid sessions, relay authentication, exploit newly disclosed flaws or enter through suppliers and management platforms. AI-related reporting added another acceleration signal, but the verified operational risk still came from familiar weaknesses exploited faster.\n\nThe bottom line: security programs built around slow patch cycles, static MFA assumptions and isolated third-party reviews are increasingly mismatched to the threat environment. Faster escalation, stronger session controls and better dependency visibility are the practical response.
Cyber crime affected 19% of businesses and 14% of charities, with phishing and repeat victimization shaping the practical risk.
Exploitation of public-facing applications rose 44% as AI accelerates reconnaissance, credential theft and ransomware operations.