Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Newsroom

Live intel feed

Current phishing and threat reporting tracked from external security sources, refreshed on a schedule. For PhishPond research and analysis, browse the sections.

Tracked Reporting

30 tracked
  • Protecting organizations from AI-assisted executive impersonation and invoice fraud

    Microsoft Security BlogSep 10, 2026Vendor Research

    Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud. The post Protecting organizations from AI-assisted executive impersonation and invoice frau

    Read more:Microsoft Security Blog

  • AVEVA Pipeline Integrity Monitor

    CISA AdvisoriesSep 10, 2026Government Advisory

    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA Pipeline Integrity Monitor are affected: AVEVA P

    Read more:CISA Advisories

  • ST Engineering iDirect iQ-Series Terminals (Update A)

    CISA AdvisoriesSep 10, 2026Government Advisory

    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals (Update A)

    Read more:CISA Advisories

  • Copyright scammers get Instagram accounts suspended and demand payment

    Malwarebytes LabsSep 10, 2026Vendor Research

    Scammers are filing fraudulent copyright complaints to suspend Instagram accounts, then demanding payment to withdraw them.

    Read more:Malwarebytes Labs

  • Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

    The Hacker NewsSep 10, 2026News

    Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its ap

    Read more:The Hacker News

  • Passkey-themed social engineering leads to identity and cloud compromise

    Microsoft Security BlogSep 9, 2026Vendor Research

    Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with

    Read more:Microsoft Security Blog

  • Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

    The Hacker NewsSep 9, 2026News

    Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Steal

    Read more:The Hacker News

  • ClickFix Campaigns Abuse Legitimate Services for Persistent Access

    Dark ReadingSep 8, 2026News

    Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.

    Read more:Dark Reading

  • Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

    The Hacker NewsSep 8, 2026News

    A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Sp

    Read more:The Hacker News

  • Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

    The Hacker NewsSep 8, 2026News

    Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign w

    Read more:The Hacker News

  • China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

    CISA AdvisoriesSep 8, 2026Government Advisory

    Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—

    Read more:CISA Advisories

  • CareCam Pro IP Cameras

    CISA AdvisoriesSep 8, 2026Government Advisory

    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of CareCam Pro IP Cameras are affected: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader

    Read more:CISA Advisories

  • Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites

    Dark ReadingSep 8, 2026News

    A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.

    Read more:Dark Reading

  • ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

    Cisco Talos IntelligenceSep 8, 2026Vendor Research

    Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser sessi

    Read more:Cisco Talos Intelligence

  • Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

    The Hacker NewsSep 7, 2026News

    Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM)

    Read more:The Hacker News

  • ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

    The Hacker NewsSep 7, 2026News

    Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting

    Read more:The Hacker News

  • N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

    The Hacker NewsSep 7, 2026News

    Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released it

    Read more:The Hacker News

  • JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

    The Hacker NewsSep 7, 2026News

    Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniq

    Read more:The Hacker News

  • Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

    The Hacker NewsSep 5, 2026News

    Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CV

    Read more:The Hacker News

  • Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

    CISA AdvisoriesSep 3, 2026Government Advisory

    View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Ea

    Read more:CISA Advisories

  • Tycon Systems TPDIN-Monitor-WEB3

    CISA AdvisoriesSep 3, 2026Government Advisory

    View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPD

    Read more:CISA Advisories

  • Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

    Microsoft Security BlogSep 2, 2026Vendor Research

    Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to

    Read more:Microsoft Security Blog

  • Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users

    Dark ReadingSep 2, 2026News

    The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.

    Read more:Dark Reading

  • Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

    Dark ReadingSep 2, 2026News

    Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.

    Read more:Dark Reading

  • AI Model Evaluator METR Hit by Credential Theft, Probing

    Dark ReadingSep 1, 2026News

    In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.

    Read more:Dark Reading

  • ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

    Dark ReadingSep 1, 2026News

    The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.

    Read more:Dark Reading

  • Anthropic Users Hit by Infostealer Attacks, Session Thefts

    Dark ReadingAug 31, 2026News

    A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.

    Read more:Dark Reading

  • 'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks

    Dark ReadingAug 31, 2026News

    The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.

    Read more:Dark Reading

  • TerminalFix campaign deploys a reverse tunnel through multistage intrusion

    Microsoft Security BlogAug 29, 2026Vendor Research

    Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrus

    Read more:Microsoft Security Blog

  • Russian Hackers Phish EU Officials Over Messaging Apps

    Dark ReadingAug 27, 2026News

    EU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp.

    Read more:Dark Reading