Trezor disclosed that hackers who compromised 138 accounts at email marketing provider Brevo used the access to send roughly 347,000 phishing emails to its customers. The messages, disguised as security alerts, directed recipients to a fake app designed to steal their wallet backup passwords. Trezor says its own products and account systems were not breached, but the stolen credentials could let attackers drain victims' crypto holdings.
techcrunch.com
· 2026-09-11
Microsoft has detailed a social engineering campaign, active since May 2026, in which attackers tied to groups like ShinyHunters and Helix pose as corporate IT help desks and warn employees their passkey, MFA, or SSO settings need urgent updating. Victims are steered to convincing fake Microsoft login pages—often via SMS to personal phones—where attackers harvest credentials and session tokens using adversary-in-the-middle and device-code phishing techniques, rather than actually registering new passkeys.
bleepingcomputer.com
· 2026-09-11
Trezor disclosed that a breach at its third-party email provider Brevo let attackers send fake security alerts to its opt-in newsletter subscribers, reaching roughly 347,000 email addresses. The fraudulent messages warned of a fake microcontroller vulnerability and pushed recipients to a malicious app requesting wallet backup phrases; Trezor says 2,500 people clicked the link before it disabled the domain within 20 minutes.
bleepingcomputer.com
· 2026-09-11
Prophet Security analyzed every alert across customer environments from May to July 2026, rather than only alerts analysts chose to escalate. Of the incidents fully investigated, 93% were benign and 7% were confirmed malicious, with identity-related attacks accounting for roughly half of that malicious activity. The firm identified session hijacking, token replay, MFA bypass, credential stuffing, and phishing as the dominant attack patterns.
bleepingcomputer.com
· 2026-09-10
Trezor alerted customers that attackers compromised its third-party email provider and used the legitimate [email protected] address to send phishing emails warning of a fake 'STM32 Entropy Vulnerability' in its hardware wallets. The company took down the malicious domain and is investigating how attackers gained access to its email infrastructure. This follows an earlier breach disclosed in August involving shipping partner ShipMonk, which exposed personal data of roughly 81,000 customers across multiple countries.
bleepingcomputer.com
· 2026-09-10
Attackers are exploiting a chain of legitimate Google services, including redirect links, to disguise malicious URLs and slip past email security filters. Victims who follow the multi-hop links are directed either to credential-harvesting phishing pages or prompted to install ScreenConnect remote access software.
darkreading.com
· 2026-09-08
Security researchers found that a Chinese-speaking threat actor has compromised Brazilian government and education websites, using them as a reverse-proxy network to funnel traffic to gambling-themed phishing sites. The attackers exploit the trust and infrastructure of official domains to disguise malicious traffic and evade detection.
darkreading.com
· 2026-09-08
CloudSEK researchers infiltrated the admin panel of a phishing-as-a-service tool called BigBear 2.0 and found it had harvested over 5,000 Microsoft 365 credentials from 258 organizations. The kit uses an Evilginx2-based adversary-in-the-middle proxy to intercept usernames, passwords, and session cookies even after victims complete multi-factor authentication, letting attackers replay stolen sessions to hijack accounts.
bleepingcomputer.com
· 2026-09-07
Microsoft researchers identified a large phishing operation that inserts invisible Unicode 'Tags' characters inside finance-related keywords—splitting words like 'funding' into fragments—to slip past email filters that scan for suspicious terms. The campaign peaked at 2.37 million daily messages in late February and, despite a drop in volume by May, remains active, with Defender for Office 365 tracing it to 148 finance-themed sender domains.
bleepingcomputer.com
· 2026-09-06
Security researchers, including work from SpecterOps, have documented at least 39 distinct methods that can undermine passkey authentication despite the underlying FIDO2 cryptography remaining secure. These techniques target the surrounding infrastructure rather than the cryptographic keys themselves, including browsers, operating systems, password managers, sync services, Bluetooth transport, and account recovery workflows. Many have working proof-of-concept tools, and some techniques are already surfacing in real-world attack activity.
bleepingcomputer.com
· 2026-09-04
Microsoft Entra now fully supports passkeys as a passwordless authentication method, with both device-bound and synced passkey options reaching general availability. The guide explains how passkeys work using the WebAuthn standard, where a private key stays on the user's device or synced service while a public key is stored in Entra ID.
emsroute.com
· 2026-09-02
Huntress researchers found phishing campaigns that trick victims into running a disguised but legitimate Faronics Deploy installer, often labeled as an Adobe file, which secretly enrolls their machine into an attacker-controlled management console. From there, attackers run PowerShell scripts to fetch additional tools and install ConnectWise ScreenConnect, giving them persistent remote access. Over 457 endpoints were targeted between July 21 and August 20 using fake invoice and tax-document lures.
bleepingcomputer.com
· 2026-09-01