Ad tech firm Optimizely, which counts PayPal, Salesforce, Vodafone, and Zoom among its clients, has been impacted by a data breach stemming from a voice phishing attack against certain systems, according to BleepingComputer.
Cybernews reports that Microsoft, Google, Apple, Facebook, and other platforms have had their legitimate login pages exploited by the new Starkiller phishing kit for credential theft.
Manufacturing, technology, and financial entities are having their Microsoft Entra accounts subjected to combined device code phishing and voice-based phishing intrusions exploiting the OAuth 2.0 Device Authorization flow, according to BleepingComputer.
Infosecurity Magazine reports that AI has been allowing low-skilled cybercriminals to craft convincing extortion messages with deadlines and pressure tactics with the new "vibe extortion" technique.
Numerous websites impersonating the official Milano Cortina Olympics merchandise stores have been targeting U.S. and European shoppers as part of a discount scam campaign, Reuters reports.
Wells Fargo, USAA, and other financial and technology firms on the Fortune 500 have been spoofed as part of the Operation Doppelbrand phishing campaign that ran from December 2025 to January 2026, reports Infosecurity Magazine.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.