More than 90% of phishing intrusions between July and September have been aimed at Microsoft Outlook and Gmail inboxes, with threat actors increasingly weaponizing trusted platforms to facilitate compromise, according to GBHackers News.
Almost 40,000 phishing emails have been delivered to over 5,000 businesses using Facebook ads in the U.S., Canada, Europe, and Australia as part of a new attack campaign aimed at pilfering credentials and other sensitive data, The Register reports.
BleepingComputer reports that nearly 1,000 domains have been used by the novel advanced Quantum Route Redirect phishing-as-a-service platform to pilfer Microsoft 365 account credentials across 90 countries.
The attack, uncovered in July 2025, featured a phishing campaign using password-protected archives to distribute a new backdoor called BackDoor.ShellNET.1.
Overall subscriber losses from smishing, account hijacking, and other SMS fraud are expected to decrease from $80 billion this year to $71 billion in 2026, reports Infosecurity Magazine.
More than 1,200 domains impersonating luxury brands, including Gucci, Louis Vuitton, Dior, Versace, and Dolce & Gabbana, have been registered between August and September, as threat actors look to exploit the holiday shopping season, Cybernews reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.