
Storm-3075 Uses ChatGPT and Claude Brands to Harvest Credentials
Microsoft identified Storm-3075 using ChatGPT, Claude, and DeepSeek brands in AiTM phishing that targeted over 2,000 organizations across the US,

Microsoft identified Storm-3075 using ChatGPT, Claude, and DeepSeek brands in AiTM phishing that targeted over 2,000 organizations across the US,

An active campaign uses 32 Google Sites pages to distribute credential malware targeting AI API keys, browser logins, and password

Attackers send fake Chrome Web Store DMCA notices using real extension data to steal developer accounts and push malicious updates

Pakistan-attributed SideCopy APT used Pashto-language LNK lures against Afghanistan’s Finance Ministry, deploying Xeno RAT for full system access and exfil.

Over 5,000 election-themed domains registered between April and May 2026 form phishing infrastructure targeting voters, campaign staff, and election workers.

Scammers have spoofed the PSNI’s official switchboard number to impersonate officers and pressure victims into buying gift cards in a

Scammers have spoofed the PSNI’s official switchboard number to impersonate officers and pressure victims into buying gift cards in a

Over 5,000 election-themed domains registered between April and May 2026 form phishing infrastructure targeting voters, campaign staff, and election workers.

Pakistan-attributed SideCopy APT used Pashto-language LNK lures against Afghanistan’s Finance Ministry, deploying Xeno RAT for full system access and exfil.

LLMShare, discovered by Push Security, abuses ChatGPT’s share links on chatgpt.com to host fake outage pages that deliver infostealer malware
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.