Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
22 clusters · 101 sources · 55 days · First seen · Last updated
Phishing and cyber scam escalation
Overview
The cyber-threat landscape continues to evolve through the integration of artificial intelligence and the exploitation of seasonal digital activity. AI-powered phishing has reportedly increased by 341% over a six-month period, with attackers utilizing AI-generated content to enhance credibility. This technological shift has reduced the average time between initial system access and lateral movement to 29 minutes. Notably, 82% of 2025 detections did not involve traditional malware, as attackers increasingly use valid credentials and legitimate administrative tools.
Recent developments show a shift toward more autonomous threats. The Google Threat Intelligence Group (GTIG) documented the use of agentic AI, including an autonomous multi-agent framework that compromised cloud infrastructure to manage 23,800 sensitive data records in under six hours. Threat actors are further automating attack lifecycles using multi-agent AI frameworks for tasks such as vulnerability scanning and credential harvesting. Anthropic reported that the Russian threat actor Midnight Blizzard utilized Claude AI to automate operations targeting military and diplomatic organizations across Ukraine, Europe, and the United States.
Technical exploitation is advancing through specialized kits and social engineering. The ‘BlueMoon’ exploit kit leverages a patch-gap window to chain three V8 vulnerabilities (CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880) to achieve SYSTEM-level access on Windows systems. This kit, adopted by espionage-motivated clusters like TA412 (APT31), utilizes a malicious extension named GemStone—masquerading as Google Gemini—to perform keystroke logging and credential theft.
New distribution methods have also emerged. BlueVoyant reported attackers using social engineering via Microsoft Teams to trick users into granting remote access through tools like Quick Assist, utilizing DLL sideloading via manipulated zlib.dll files to trigger the FireClient backdoor. Additionally, Barracuda Networks identified a novel phishing technique that bypasses web filters by generating fake login pages using Blob URLs directly in the victim's browser memory, making them invisible to standard URL blocklists.
Entities
Kaspersky · Microsoft · Google · CrowdStrike · Meta
Claims
What the coverage asserts, and how many sources carry each claim.
Coverage disagrees
Sources make claims that cannot both be true. CLSTR reports the disagreement; it does not decide who is right.
-
"73% of Latin American companies were targeted by phishing campaigns in 2025."
vs
"81.4% of manufacturing firms in Latin America reported phishing attacks."
The claims provide different percentages (73% vs 81.4%) for the same metric of phishing attacks targeting companies in Latin America according to the same source.
- [DISPUTED] 73% of Latin American companies were targeted by phishing campaigns in 2025.
- [DISPUTED] 81.4% of manufacturing firms in Latin America reported phishing attacks.
- [● 4 SOURCES] AI-based cyberattacks grew 89% in 2025 compared to the previous year. www.eldogomes.com.br · leianoticias.com.br · dicaappdodia.com · zeev.it
- [● 4 SOURCES] The average time between initial access and lateral movement fell to 29 minutes. www.eldogomes.com.br · leianoticias.com.br · dicaappdodia.com · zeev.it
- [● 3 SOURCES] 82% of detections in 2025 did not involve traditional malware. www.eldogomes.com.br · leianoticias.com.br · dicaappdodia.com
- [● 3 SOURCES] AI analyzes images in detail, including facial features, lighting, and composition, to create valuable databases. ts.mk · tv21.tv · javanews.al
- [● 3 SOURCES] The 1980s-style photo transformation trend can be used as a tool to collect users' visual and personal data. ts.mk · tv21.tv · javanews.al
- [● 3 SOURCES] Fake links and unknown applications exploit user curiosity by offering free image transformations. ts.mk · tv21.tv · javanews.al
- [● 3 SOURCES] Repeatedly uploading photos from different angles provides platforms with a wide collection of visual data for identity theft or fraud. ts.mk · tv21.tv · javanews.al
- [● 2 SOURCES] The “Screen Overlay” technique displays fake screens over legitimate Android apps to capture credentials and payment data.
- [● 2 SOURCES] Reported losses from deepfake scams in 2026 have already exceeded last year’s total by 263%. bitcoinethereumnews.com · cryptoslate.com
- [● 2 SOURCES] Reports involving scammer-side use of AI have risen roughly 13-fold since 2022. bitcoinethereumnews.com · cryptoslate.com
Timeline
-
4 days ago
[TECHNOLOGY] 3 sourcesCybersecurity researchers warn of passkey phishing and AI-driven social engineeringAttackers are using sophisticated social engineering and AI to impersonate IT help desks, using fake passkey requests to hijack enterprise cloud accounts and access sensitive data.
-
7 days ago
[TECHNOLOGY] 2 sourcesCybersecurity researchers warn of new Microsoft Teams and phishing attacksCybersecurity researchers warn of evolving threats, including FireClient backdoor attacks via Microsoft Teams and novel phishing campaigns that use in-memory Blob URLs to bypass traditional web filters.
-
9 days ago
[TECHNOLOGY] 4 sourcesCybersecurity threats evolve through AI automation and browser exploitsThreat actors are increasingly using AI-driven frameworks and chained browser vulnerabilities, such as the BlueMoon kit, to automate espionage and achieve high-level system access.
-
11 days ago
[TECHNOLOGY] 5 sourcesCybersecurity experts warn of risks in viral 1980s AI photo trendCybersecurity experts and Indian police warn that viral 1980s-style AI photo trends are being exploited by fraudsters to steal sensitive personal data, banking credentials, and identity information.
-
13 days ago
[TECHNOLOGY] 4 sourcesCybersecurity risks rise for SMEs and telecom sectors via phishing and Shadow AICybersecurity risks are rising for SMEs due to increasing phishing attacks and for the telecom sector due to ‘Shadow AI’, where employees use unmonitored generative AI tools, risking data leaks.
-
13 days ago
[TECHNOLOGY] 7 sourcesCybersecurity threats evolve through AI and social media extortionCybercriminals are using AI and social media copyright tools to conduct sophisticated scams, including deepfakes and extortion schemes targeting Instagram creators.
-
13 days ago
[TECHNOLOGY] 3 sourcesAI-driven phishing and Android malware pose new security threatsCybersecurity threats are evolving with AI-driven phishing that generates malicious sites in browsers and Android malware targeting job seekers via fake interview apps.
-
14 days ago
[TECHNOLOGY] 6 sourcesPolice warn of 25 sophisticated cybercrime scenarios for 2026Police warn of 25 sophisticated cybercrime scenarios for 2026, highlighting the use of AI, Deepfake, and DeepVoice technology to impersonate officials and relatives for financial theft.
-
21 days ago
[TECHNOLOGY] 3 sourcesCybersecurity threats rise as attackers exploit enterprise collaboration toolsCybersecurity researchers report a fourfold rise in attackers abusing enterprise collaboration tools, prompting a shift toward Zero Trust Architecture to combat identity phishing and lateral movement.
-
21 days ago
[TECHNOLOGY] 3 sourcesCybersecurity strategies evolve amid rising AI threats and legacy technology useCybersecurity strategies are evolving as organizations use legacy technology to reduce attack surfaces while Managed Service Providers adopt AI and automation to counter rapid, AI-driven phishing and malware.
-
21 days ago
[TECHNOLOGY] 3 sourcesCybersecurity trends show evolving phishing tactics and training effectivenessCybercriminals are using calendar invites and phone calls to bypass security, but annual training can reduce employee phishing susceptibility by 83 percent, according to a new industry report.
-
25 days ago
[TECHNOLOGY] 3 sourcesCybersecurity threats rise as attackers impersonate Zoom and OutlookCybersecurity experts warn of a surge in phishing attacks impersonating tools like Zoom and Outlook, while businesses focus on increasing resilience and insurance coverage during the post-summer return to work.
-
28 days ago
[TECHNOLOGY] 3 sourcesCybersecurity risks rise during summer vacation periodsCybercriminals exploit summer vacations to launch increased cyberattacks, targeting remote workers using public Wi-Fi, phishing, and AI-driven social engineering to bypass weakened corporate defenses.
-
28 days ago
[TECHNOLOGY] 3 sourcesCybersecurity landscape shifts toward AI threats and automated protectionEnterprises are navigating evolving cybersecurity threats, including AI-assisted exploits, while new tools like Akamai’s AI assistant aim to bridge the gap between threat detection and rapid protection.
-
28 days ago
[TECHNOLOGY] 31 sourcesAI-driven cyberattacks and deepfake fraud surge globallyAI-driven cyberattacks rose 89% in 2025, with lateral movement speeds accelerating. Deepfake fraud is also surging, with crypto-related losses and home-made impersonation attempts seeing massive increases.
-
30 days ago
[CRIME] 2 sourcesCybercriminals target professionals via LinkedIn and WhatsApp scamsAuthorities warn of rising digital fraud, including LinkedIn recruitment scams stealing millions in crypto and WhatsApp investment schemes using fake AI promises and stolen brand identities.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesCybersecurity threats evolve with AI-driven phishing 3.0Cybersecurity is shifting toward ‘phishing 3.0’, using AI and deepfakes to automate multi-channel attacks via voice and video, making identity theft harder to detect.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesCybersecurity threats rise during peak travel and work transitionsCybercriminals are leveraging seasonal shifts to launch scams, targeting travelers with travel-themed phishing and employees with impersonations of workplace tools like Zoom and Outlook.
-
about 1 month ago
[TECHNOLOGY] 6 sourcesCybersecurity threats escalate via AI phishing and targeted spywareCybersecurity threats are rising as attackers use AI-generated phishing, impersonate trusted work tools like Zoom, and target journalists with sophisticated spyware and social engineering tactics.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesCybersecurity threats surge through social engineering and HTML smugglingCybercriminals are increasingly using HTML smuggling, DCRat malware, and social engineering to bypass security, with a massive surge in government and family impersonation scams reported.
-
about 2 months ago
[CRIME] 12 sourcesPhishing attacks and related cyber scams rise globally, targeting businesses and travelersPhishing hits 73% of Latin American firms, while WhatsApp hotel scams, Android screen‑overlay attacks, hotel Wi‑Fi hijacking, travel phishing and industrial phishing all surge worldwide.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesOpen redirect attacks and phishing emails remain major cyber threatsOpen redirect flaws and phishing emails stay major cyber threats, letting attackers hijack trusted links and trick users, driving most data breaches.
Sources
abranet.org.br · activenews.ro · ad-hoc-news.de · agendadigitale.eu · alias.estadao.com.br · all-about-security.de · ambitur.pt · andro4all.com · androidnews.de · b2b-cyber-security.de · biometricupdate.com · bitcoinethereumnews.com · blog.knowbe4.com · blog.segurostv.es · blog.smlbrasil.com.br · borncity.com · brasil.estadao.com.br · cafef.vn · campustechnology.com · cbnews.fr · commonculture.org.uk · contabeis.com.br · corrierecomunicazioni.it · crypto-insiders.nl · cryptoslate.com · cxoinsightme.com · cybernoz.com · diariomarca.com.mx · diariosocialrd.com · dicaappdodia.com · digitaljournal.com · dinero.com.sv · docmanagement.com.br · e-trust.com.br · ebizlatam.com · eco.sapo.pt · economia.estadao.com.br · editorialge.com · eldogomes.com.br · elgrupoinformatico.com · eloutput.com · etailment.de · extra.globo.com · flagthis.com · forkast.news · futurezone.de · gamerevolution.com · gargalianoionline.gr
This summary has been updated 22 times: see revision history