The UK's National Cyber Security Centre (NCSC) issued an alert regarding a new 'zero-click' threat campaign orchestrated by Russian state-backed hackers targeting organizations across critical sectors, according to a recent report by IT Pro.
The Kratos kit enabled cybercriminals with limited technical skills to harvest credentials, including passwords and session cookies, by providing convincing Microsoft-themed phishing pages.
Security researchers at Group-IB have identified multiple scam campaigns targeting fans eager to purchase tickets for Celine Dion's return to the stage.
The campaign, active since at least January 2026, employs rotating lures tied to the calendar, such as tax themes in winter and Valentine's or Easter invitations later on, according to Forescout.
The platform, active since 2020, allowed criminals to make over 1.8 million scam calls globally, targeting approximately 170,000 victims and causing tens of millions in financial losses.