SiliconANGLE reports that analysis showed phishing-as-a-service kits were used in 90% of high-volume phishing campaigns in 2025 as attacks became more sophisticated and harder to detect.
More threat actors have been abusing spoof protection misconfigurations and complicated routing scenarios to imitate targeted organizations' domains and deploy seemingly internal phishing messages since May, Security Affairs reports.
Threat actors have been able to deploy stealthier QR code phishing campaigns by using HTML tables, instead of image attachments, for illicit QR code generation, reports Cybernews.
Microsoft leads phishing impersonation rankings in Q4 Microsoft has become the most spoofed brand in phishing intrusions during the last quarter of 2025, surpassing Facebook, which previously led the rankings, reports Cybernews.
Cyber Security News reports that WordPress administrators have been targeted with fraudulent domain renewal emails to facilitate the compromise of credit card data and two-factor authentication codes as part of a new phishing campaign.