WhisperX tag archive

#phishing

This page collects WhisperX intelligence signals tagged #phishing. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (20)

The Vault · 2026-03-03 05:48:25 · SearXNG:crypto scam exposed

1. ‘ClickFix’ Hackers Impersonate VCs, Hijack QuickLens Extension in Coordinated Crypto Attack

Cybersecurity threat intelligence indicates a significant evolution in cryptocurrency-focused attack methodologies, with threat actors now employing sophisticated social engineering techniques that bypass traditional security controls. Recent analysis reveals two distinct but complementary attack vectors that have emer...

The Network · 2026-03-06 13:13:07 · ai

2. Starkiller Phishing Service Proxies Real Login Pages, Bypasses MFA

A new phishing-as-a-service platform named 'Starkiller' is enabling cybercriminals to bypass traditional detection methods by dynamically loading the *real* login pages of target brands and acting as a stealthy relay between victims and legitimate sites. Unlike static phishing kits, Starkiller uses cleverly disguised l...

The Lab · 2026-03-25 16:27:11 · GitHub Issues

3. Open Redirect Vulnerabilities Exposed in Codebase: Phishing Risk in Two Critical Files

Two open redirect vulnerabilities have been identified within a codebase, creating a direct pathway for potential phishing attacks. The flaws, classified with medium severity, reside in two separate route files where user-controlled input is used to construct redirect URLs without proper validation. This allows attacke...

The Lab · 2026-03-30 15:27:03 · Protos

4. Steakhouse Financial Front-End Breach Redirects Users to Phishing Scam

A front-end breach at DeFi risk curator Steakhouse Financial has turned its official website and mobile app into a trap, redirecting new users to a malicious phishing operation. The company disclosed the attack on Monday, March 30, 2026, warning that any interaction with its digital platforms likely leads to a hacker-c...

The Lab · 2026-03-31 02:27:01 · GitHub Issues

5. Open Redirect Vulnerabilities Exposed in Codebase: Phishing Risk in Two Critical Files

A security audit has identified two open redirect vulnerabilities within a codebase, classified as a medium-severity risk. The flaws, present in two separate route files, allow user-controlled input to dictate redirect destinations without validation. This creates a direct vector for phishing attacks, where attackers c...

The Lab · 2026-04-02 12:57:19 · GitHub Issues

6. Gno.land Ecosystem Patches Critical Markdown Injection Vulnerability (GHSA-q5xx-v955-c7vg)

A critical security vulnerability in the Gno.land blockchain ecosystem has been patched, preventing malicious actors from injecting phishing links into rendered markdown outputs. The flaw, tracked as GHSA-q5xx-v955-c7vg, resided in the `Render()` function, where user-supplied strings were not properly sanitized. This c...

The Lab · 2026-04-02 22:27:10 · GitHub Issues

7. DIA Backend API Vulnerability Exposes Users to Open Redirect Phishing Attacks

A critical security flaw in the DIA platform allows attackers to redirect users to arbitrary malicious websites. The vulnerability resides in the `redirectToExternalUrl()` method, which accepts an external URL from the backend API and passes it directly to the browser without any validation, domain allowlisting, or pro...

The Network · 2026-04-04 20:26:56 · GitHub Issues

8. Ransomware & Supply Chain Surge: DragonForce, BQTLock, and GitHub Actions Campaigns Dominate Critical Threat Landscape

The threat landscape has intensified, with ransomware-as-a-service (RaaS) operations and sophisticated supply chain attacks driving a surge in critical incidents. Over the past 24 hours, six reports were rated critical, dominated by DragonForce claiming five new victims across pharmaceuticals, manufacturing, and retail...

The Lab · 2026-04-06 14:27:20 · GitHub Issues

9. Open Redirect Vulnerability Patched in Patient Portal Messaging System

A critical open redirect vulnerability has been patched in a patient portal's messaging system. The flaw, located in the `portal/messaging/handle_note.php` script, allowed an attacker to redirect authenticated patients to malicious phishing pages after they performed a messaging action. The vulnerability stemmed from t...

The Network · 2026-04-08 19:27:28 · TechCrunch

10. Hack-for-Hire Group Exposed: Android Spyware & iCloud Phishing Campaign Uncovered

A sophisticated hack-for-hire operation has been caught running a multi-pronged spying campaign, targeting victims through Android spyware and iCloud credential phishing. Security researchers exposed the group's activities, revealing a commercialized threat that bypasses traditional security perimeters by directly comp...

The Lab · 2026-04-11 06:23:46 · CafeF Home

11. Cảnh báo khẩn: Chiến dịch lừa đảo Apple Pay quy mô lớn đang nhắm vào người dùng iPhone

Một chiến dịch lừa đảo công nghệ cao, mạo danh hệ thống thanh toán Apple Pay, đang lan rộng với tốc độ đáng báo động. Chiến dịch này trực tiếp đe dọa an toàn tài chính của hàng triệu người dùng iPhone, lợi dụng uy tín của thương hiệu Apple để đánh cắp thông tin cá nhân và tài chính. Đây không phải là một trò lừa đảo th...

The Lab · 2026-04-11 10:22:25 · Numerama

12. Discord face à un père : piratage d'un compte mineur révèle des failles structurelles critiques

Un récit personnel publié par Ars Technica met en lumière les défaillances systémiques de Discord en matière de sécurité et de support utilisateur, particulièrement pour les mineurs. Un père de famille américain détaille l'impuissance totale qu'il a rencontrée après le piratage du compte Discord de sa fille. Malgré ses...

The Lab · 2026-04-13 03:03:34 · CafeF Home

13. Cảnh báo khẩn: Chiến dịch lừa đảo tinh vi nhắm vào người dùng iPhone để chiếm đoạt tài khoản ngân hàng

Một chiến dịch lừa đảo mạng mới, được các chuyên gia an ninh đánh giá là vô cùng tinh vi, đang nhắm mục tiêu trực tiếp vào người dùng trong hệ sinh thái Apple. Mục đích cuối cùng của kẻ tấn công là chiếm đoạt thông tin cá nhân và tài sản trong tài khoản ngân hàng của nạn nhân. Đây không phải là một trò lừa đảo thông th...

The Network · 2026-04-13 18:52:56 · TechCrunch

14. FBI Takedown: W3LL Phishing Kit Targeted 17,000+ Global Victims, Stole Passwords & MFA Codes

The FBI has dismantled a sophisticated phishing operation that successfully compromised thousands of victims worldwide by stealing not just passwords, but also the multi-factor authentication (MFA) codes meant to protect them. This takedown highlights a critical escalation in credential theft, moving beyond simple pass...

The Lab · 2026-04-14 15:52:55 · Decrypt

15. Fake Ledger Live App on Mac App Store Steals $9M+ in Crypto, Targeting Over 50 Users

A sophisticated scam has siphoned over $9 million in cryptocurrency from unsuspecting holders through a fraudulent Ledger Live application listed on Apple's official Mac App Store. The fake app, which successfully bypassed Apple's security vetting, has already impacted more than 50 users, including musician G. Love, hi...

The Lab · 2026-04-21 08:52:55 · The Register

17. Adaptavist Group Breach: Ransomware Crew Claims 'Mega-Haul' as Imposter Emails Circulate

A ransomware crew is publicly boasting of a 'mega-haul' of stolen data from UK enterprise software consultancy The Adaptavist Group, directly contradicting the company's official statements and triggering a wave of imposter phishing emails. The breach, confirmed by Adaptavist, originated from an intruder using stolen c...

The Vault · 2026-04-21 12:22:28 · Golem.de

18. Banken-Phishing-Panne: Betrüger schicken E-Mails an falsche Kunden – Verwirrung statt Beute

Ein aktueller Phishing-Angriff auf Bankkunden ist offenbar gründlich schiefgelaufen. Die Betrüger haben E-Mails verschickt, die sich an Kunden einer bestimmten Bank richten sollten – doch die Empfänger gehörten größtenteils gar nicht zu dieser Bank. Die Aktion stiftete daher vor allem Verwirrung, anstatt erfolgreich se...

The Network · 2026-04-21 20:22:29 · Krebs on Security

19. ‘Scattered Spider’ Senior Member ‘Tylerb’ Pleads Guilty to Major Crypto Theft Scheme

A senior member of the notorious cybercrime group ‘Scattered Spider’ has pleaded guilty to federal charges, admitting to a sophisticated phishing campaign that siphoned tens of millions in cryptocurrency from investors. Tyler Robert Buchanan, a 24-year-old British national known by the handle ‘Tylerb,’ confessed to wir...

The Network · 2026-04-24 16:24:10 · Handelsblatt

20. Spionageverdacht: Phishing-Angriff auf Signal trifft deutsche Politik und Behörden

Ermittler untersuchen einen mutmaßlichen Spionageangriff auf den verschlüsselten Messengerdienst Signal, bei dem Unbekannte gezielt hochrangige Politikerschaft und Bundesbehörden ins Visier genommen haben. Betroffen sind nach Informationen von Handelsblatt führende Köpfe aus dem Bundestag, Ministerien sowie Sicherheits...