< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

22 clusters · 101 sources · 55 days · First seen · Last updated

Phishing and cyber scam escalation

Overview

The cyber-threat landscape continues to evolve through the integration of artificial intelligence and the exploitation of seasonal digital activity. AI-powered phishing has reportedly increased by 341% over a six-month period, with attackers utilizing AI-generated content to enhance credibility. This technological shift has reduced the average time between initial system access and lateral movement to 29 minutes. Notably, 82% of 2025 detections did not involve traditional malware, as attackers increasingly use valid credentials and legitimate administrative tools.

Recent developments show a shift toward more autonomous threats. The Google Threat Intelligence Group (GTIG) documented the use of agentic AI, including an autonomous multi-agent framework that compromised cloud infrastructure to manage 23,800 sensitive data records in under six hours. Threat actors are further automating attack lifecycles using multi-agent AI frameworks for tasks such as vulnerability scanning and credential harvesting. Anthropic reported that the Russian threat actor Midnight Blizzard utilized Claude AI to automate operations targeting military and diplomatic organizations across Ukraine, Europe, and the United States.

Technical exploitation is advancing through specialized kits and social engineering. The ‘BlueMoon’ exploit kit leverages a patch-gap window to chain three V8 vulnerabilities (CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880) to achieve SYSTEM-level access on Windows systems. This kit, adopted by espionage-motivated clusters like TA412 (APT31), utilizes a malicious extension named GemStone—masquerading as Google Gemini—to perform keystroke logging and credential theft.

New distribution methods have also emerged. BlueVoyant reported attackers using social engineering via Microsoft Teams to trick users into granting remote access through tools like Quick Assist, utilizing DLL sideloading via manipulated zlib.dll files to trigger the FireClient backdoor. Additionally, Barracuda Networks identified a novel phishing technique that bypasses web filters by generating fake login pages using Blob URLs directly in the victim's browser memory, making them invisible to standard URL blocklists.

Entities

Kaspersky · Microsoft · Google · CrowdStrike · Meta

Claims

What the coverage asserts, and how many sources carry each claim.

Coverage disagrees

Sources make claims that cannot both be true. CLSTR reports the disagreement; it does not decide who is right.

  • "73% of Latin American companies were targeted by phishing campaigns in 2025."

    vs

    "81.4% of manufacturing firms in Latin America reported phishing attacks."

    The claims provide different percentages (73% vs 81.4%) for the same metric of phishing attacks targeting companies in Latin America according to the same source.

Timeline

  1. 4 days ago

    [TECHNOLOGY] 3 sources
    Cybersecurity researchers warn of passkey phishing and AI-driven social engineering

    Attackers are using sophisticated social engineering and AI to impersonate IT help desks, using fake passkey requests to hijack enterprise cloud accounts and access sensitive data.

  2. 7 days ago

    [TECHNOLOGY] 2 sources
    Cybersecurity researchers warn of new Microsoft Teams and phishing attacks

    Cybersecurity researchers warn of evolving threats, including FireClient backdoor attacks via Microsoft Teams and novel phishing campaigns that use in-memory Blob URLs to bypass traditional web filters.

  3. 9 days ago

    [TECHNOLOGY] 4 sources
    Cybersecurity threats evolve through AI automation and browser exploits

    Threat actors are increasingly using AI-driven frameworks and chained browser vulnerabilities, such as the BlueMoon kit, to automate espionage and achieve high-level system access.

  4. 11 days ago

    [TECHNOLOGY] 5 sources
    Cybersecurity experts warn of risks in viral 1980s AI photo trend

    Cybersecurity experts and Indian police warn that viral 1980s-style AI photo trends are being exploited by fraudsters to steal sensitive personal data, banking credentials, and identity information.

  5. 13 days ago

    [TECHNOLOGY] 4 sources
    Cybersecurity risks rise for SMEs and telecom sectors via phishing and Shadow AI

    Cybersecurity risks are rising for SMEs due to increasing phishing attacks and for the telecom sector due to ‘Shadow AI’, where employees use unmonitored generative AI tools, risking data leaks.

  6. 13 days ago

    [TECHNOLOGY] 7 sources
    Cybersecurity threats evolve through AI and social media extortion

    Cybercriminals are using AI and social media copyright tools to conduct sophisticated scams, including deepfakes and extortion schemes targeting Instagram creators.

  7. 13 days ago

    [TECHNOLOGY] 3 sources
    AI-driven phishing and Android malware pose new security threats

    Cybersecurity threats are evolving with AI-driven phishing that generates malicious sites in browsers and Android malware targeting job seekers via fake interview apps.

  8. 14 days ago

    [TECHNOLOGY] 6 sources
    Police warn of 25 sophisticated cybercrime scenarios for 2026

    Police warn of 25 sophisticated cybercrime scenarios for 2026, highlighting the use of AI, Deepfake, and DeepVoice technology to impersonate officials and relatives for financial theft.

  9. 21 days ago

    [TECHNOLOGY] 3 sources
    Cybersecurity threats rise as attackers exploit enterprise collaboration tools

    Cybersecurity researchers report a fourfold rise in attackers abusing enterprise collaboration tools, prompting a shift toward Zero Trust Architecture to combat identity phishing and lateral movement.

  10. 21 days ago

    [TECHNOLOGY] 3 sources
    Cybersecurity strategies evolve amid rising AI threats and legacy technology use

    Cybersecurity strategies are evolving as organizations use legacy technology to reduce attack surfaces while Managed Service Providers adopt AI and automation to counter rapid, AI-driven phishing and malware.

  11. 21 days ago

    [TECHNOLOGY] 3 sources
    Cybersecurity trends show evolving phishing tactics and training effectiveness

    Cybercriminals are using calendar invites and phone calls to bypass security, but annual training can reduce employee phishing susceptibility by 83 percent, according to a new industry report.

  12. 25 days ago

    [TECHNOLOGY] 3 sources
    Cybersecurity threats rise as attackers impersonate Zoom and Outlook

    Cybersecurity experts warn of a surge in phishing attacks impersonating tools like Zoom and Outlook, while businesses focus on increasing resilience and insurance coverage during the post-summer return to work.

  13. 28 days ago

    [TECHNOLOGY] 3 sources
    Cybersecurity risks rise during summer vacation periods

    Cybercriminals exploit summer vacations to launch increased cyberattacks, targeting remote workers using public Wi-Fi, phishing, and AI-driven social engineering to bypass weakened corporate defenses.

  14. 28 days ago

    [TECHNOLOGY] 3 sources
    Cybersecurity landscape shifts toward AI threats and automated protection

    Enterprises are navigating evolving cybersecurity threats, including AI-assisted exploits, while new tools like Akamai’s AI assistant aim to bridge the gap between threat detection and rapid protection.

  15. 28 days ago

    [TECHNOLOGY] 31 sources
    AI-driven cyberattacks and deepfake fraud surge globally

    AI-driven cyberattacks rose 89% in 2025, with lateral movement speeds accelerating. Deepfake fraud is also surging, with crypto-related losses and home-made impersonation attempts seeing massive increases.

  16. 30 days ago

    [CRIME] 2 sources
    Cybercriminals target professionals via LinkedIn and WhatsApp scams

    Authorities warn of rising digital fraud, including LinkedIn recruitment scams stealing millions in crypto and WhatsApp investment schemes using fake AI promises and stolen brand identities.

  17. about 1 month ago

    [TECHNOLOGY] 2 sources
    Cybersecurity threats evolve with AI-driven phishing 3.0

    Cybersecurity is shifting toward ‘phishing 3.0’, using AI and deepfakes to automate multi-channel attacks via voice and video, making identity theft harder to detect.

  18. about 1 month ago

    [TECHNOLOGY] 2 sources
    Cybersecurity threats rise during peak travel and work transitions

    Cybercriminals are leveraging seasonal shifts to launch scams, targeting travelers with travel-themed phishing and employees with impersonations of workplace tools like Zoom and Outlook.

  19. about 1 month ago

    [TECHNOLOGY] 6 sources
    Cybersecurity threats escalate via AI phishing and targeted spyware

    Cybersecurity threats are rising as attackers use AI-generated phishing, impersonate trusted work tools like Zoom, and target journalists with sophisticated spyware and social engineering tactics.

  20. about 1 month ago

    [TECHNOLOGY] 2 sources
    Cybersecurity threats surge through social engineering and HTML smuggling

    Cybercriminals are increasingly using HTML smuggling, DCRat malware, and social engineering to bypass security, with a massive surge in government and family impersonation scams reported.

  21. about 2 months ago

    [CRIME] 12 sources
    Phishing attacks and related cyber scams rise globally, targeting businesses and travelers

    Phishing hits 73% of Latin American firms, while WhatsApp hotel scams, Android screen‑overlay attacks, hotel Wi‑Fi hijacking, travel phishing and industrial phishing all surge worldwide.

  22. about 2 months ago

    [TECHNOLOGY] 2 sources
    Open redirect attacks and phishing emails remain major cyber threats

    Open redirect flaws and phishing emails stay major cyber threats, letting attackers hijack trusted links and trick users, driving most data breaches.

Sources

abranet.org.br · activenews.ro · ad-hoc-news.de · agendadigitale.eu · alias.estadao.com.br · all-about-security.de · ambitur.pt · andro4all.com · androidnews.de · b2b-cyber-security.de · biometricupdate.com · bitcoinethereumnews.com · blog.knowbe4.com · blog.segurostv.es · blog.smlbrasil.com.br · borncity.com · brasil.estadao.com.br · cafef.vn · campustechnology.com · cbnews.fr · commonculture.org.uk · contabeis.com.br · corrierecomunicazioni.it · crypto-insiders.nl · cryptoslate.com · cxoinsightme.com · cybernoz.com · diariomarca.com.mx · diariosocialrd.com · dicaappdodia.com · digitaljournal.com · dinero.com.sv · docmanagement.com.br · e-trust.com.br · ebizlatam.com · eco.sapo.pt · economia.estadao.com.br · editorialge.com · eldogomes.com.br · elgrupoinformatico.com · eloutput.com · etailment.de · extra.globo.com · flagthis.com · forkast.news · futurezone.de · gamerevolution.com · gargalianoionline.gr

This summary has been updated 22 times: see revision history