A reported exploitation wave against Ghost CMS pushed malicious JavaScript onto more than 700 sites, sending visitors into fake verification flows that used ClickFix-style paste-and-run instructions.
Read more:The Hacker NewsMalwarebytes Labs
By PhishPond Desk
A phishing wave impersonating Signal Support pressures targets to hand over the 64-character recovery key that protects their encrypted backups, harvesting a secret directly inside the trusted app with no link to detonate.
Read more:TechCrunchMalwarebytes
By PhishPond Desk
Recent code-of-conduct phishing campaigns show how attackers blend HR pressure, PDF staging, CAPTCHA gates, and AiTM flows to steal session tokens.
Read more:Microsoft Security BlogMicrosoft Security Blog
By PhishPond Desk
Attackers are blending push prompts, urgent collaboration lures, and identity fatigue to move users from suspicion to accidental approval.
Read more:The Hacker NewsThe Hacker News
By PhishPond Desk