Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Newsroom

Live intel feed

Current phishing and threat reporting tracked from external security sources, refreshed on a schedule. For PhishPond research and analysis, browse the sections.

Tracked Reporting

30 tracked
  • ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

    The Hacker NewsJul 27, 2026News

    Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing lo

    Read more:The Hacker News

  • Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

    The Hacker NewsJul 27, 2026News

    Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools. "The victim was directed through compromised web infrastructure to a coun

    Read more:The Hacker News

  • GitHub, PyPI add time-based defenses against supply chain attacks

    BleepingComputerJul 26, 2026News

    GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]

    Read more:BleepingComputer

  • Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    BleepingComputerJul 25, 2026News

    Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]

    Read more:BleepingComputer

  • BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

    The Hacker NewsJul 24, 2026News

    The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns design

    Read more:The Hacker News

  • Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

    The Hacker NewsJul 24, 2026News

    Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Control

    Read more:The Hacker News

  • Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

    The Hacker NewsJul 24, 2026News

    The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. Th

    Read more:The Hacker News

  • Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

    The Hacker NewsJul 23, 2026News

    A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the brow

    Read more:The Hacker News

  • Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

    CISA AdvisoriesJul 23, 2026Government Advisory

    Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary   A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial

    Read more:CISA Advisories

  • Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

    The Hacker NewsJul 23, 2026News

    Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email add

    Read more:The Hacker News

  • Flaws in Passkey Implementation Show Old Attacks Still Work

    Dark ReadingJul 22, 2026News

    Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users.

    Read more:Dark Reading

  • Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

    The Hacker NewsJul 22, 2026News

    German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a jo

    Read more:The Hacker News

  • Siemens SIDIS Secured SmartPlug

    CISA AdvisoriesJul 21, 2026Government Advisory

    View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends

    Read more:CISA Advisories

  • Tycon Systems TPDIN-Monitor-WEB2

    CISA AdvisoriesJul 21, 2026Government Advisory

    View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following v

    Read more:CISA Advisories

  • Attackers Combo Up Evasion Tactics for BEC Phishing

    Dark ReadingJul 20, 2026News

    "The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.

    Read more:Dark Reading

  • Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks

    Microsoft Security BlogJul 17, 2026Vendor Research

    Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception. The post Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks appeared first

    Read more:Microsoft Security Blog

  • ACR Stealer: Two observed intrusion chains amid increased threat activity

    Microsoft Security BlogJul 16, 2026Vendor Research

    From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive doc

    Read more:Microsoft Security Blog

  • Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix

    CISA AdvisoriesJul 16, 2026Government Advisory

    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix are affected: Compact

    Read more:CISA Advisories

  • Rockwell Automation FactoryTalk DataMosaix

    CISA AdvisoriesJul 16, 2026Government Advisory

    View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server. The following versions of Rockwell Automation FactoryTalk DataMosaix are affected: DataMosaix Private Cloud CVSS Ve

    Read more:CISA Advisories

  • Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

    Microsoft Security BlogJul 16, 2026Vendor Research

    Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses. The post Unpacking the AsyncAPI npm supply chain compr

    Read more:Microsoft Security Blog

  • The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)

    Unit 42 (Palo Alto Networks)Jul 15, 2026Vendor Research

    Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42 .

    Read more:Unit 42 (Palo Alto Networks)

  • Identity Attacks Overtake Exploits as Top Ransomware Cause

    Dark ReadingJul 15, 2026News

    Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.

    Read more:Dark Reading

  • ClickFix's Mushrooming Ecosystem Demands New Defense Tactics

    Dark ReadingJul 14, 2026News

    The attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option.

    Read more:Dark Reading

  • OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

    Proofpoint Threat InsightJul 14, 2026Vendor Research

    Read more:Proofpoint Threat Insight

  • Defending SaaS-based applications against ShinyHunters OAuth abuse

    Microsoft Security BlogJul 13, 2026Vendor Research

    Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications. The

    Read more:Microsoft Security Blog

  • FBI Seizes NetNut Proxy Platform, Popa Botnet

    KrebsOnSecurityJul 2, 2026Analysis

    The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR].

    Read more:KrebsOnSecurity

  • ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365

    Cisco Talos IntelligenceJul 1, 2026Vendor Research

    Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration.

    Read more:Cisco Talos Intelligence

  • Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

    Unit 42 (Palo Alto Networks)Jul 1, 2026Vendor Research

    Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more. The post Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector appeared first on Unit 42 .

    Read more:Unit 42 (Palo Alto Networks)

  • Defending the Authentication Flow: Device Code Phishing with Selena Larson

    Proofpoint Threat InsightJun 30, 2026Vendor Research

    Read more:Proofpoint Threat Insight

  • 29th June – Threat Intelligence Report

    Check Point ResearchJun 29, 2026Vendor Research

    For the latest discoveries in cyber research for the week of 29th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Polymarket, a large cryptocurrency-based prediction market, has confirmed a supply chain attack after a third-par

    Read more:Check Point Research