THREAT FEED
Clear filtersReal-time security alerts filtered for your threat landscape.
Gmail Credential Harvesting via Fake Security Alerts Phishing 2026-03-06
Widespread phishing campaign using fake Gmail security alerts. Emails claim suspicious login detected and direct users to a near-perfect Google sign-in replica. Campaign has compromised over 100,000 accounts in the past week.
Zoom Zero-Day Meeting Infiltration Vulnerability 2026-03-06
Zero-day vulnerability in Zoom client versions prior to 6.1.2 allows unauthenticated attackers to join private meetings without a passcode. Exploit bypasses the waiting room feature and has been observed in targeted attacks against corporate meetings.
Comcast Xfinity Customer Data Breach Data Breach 2026-03-05
Comcast Xfinity confirmed unauthorized access to customer accounts affecting approximately 35 million users. Exposed data includes usernames, hashed passwords, security questions, and partial Social Security numbers. The breach was traced to a vulnerability in the Citrix Bleed exploit (CVE-2025-4921).
Microsoft 365 OAuth Phishing Campaign Phishing 2026-03-05
Sophisticated phishing campaign exploiting Microsoft 365 OAuth flows. Victims receive emails with Review Document links that redirect through legitimate Microsoft login to a malicious OAuth consent page, granting attackers persistent access to email, files, and Teams.
New Ransomware Variant Targeting Remote Workers Malware 2026-03-04
Unit 42 researchers identified PhantomLock, a new ransomware variant specifically designed to target remote workers. It spreads through malicious Slack messages and Zoom meeting links, encrypting local files and cloud-synced folders. Demands cryptocurrency payment within 48 hours.
PayPal Account Takeover via SIM Swap Data Breach 2026-02-20
Coordinated SIM swap attacks targeting PayPal users with Verizon phone numbers. Attackers port victim phone numbers to new SIMs, intercept 2FA codes, and drain PayPal balances. Over $2.3 million stolen in February alone.
AWS Access Key Exposure in Public Repositories Data Breach 2026-02-15
Automated scanning reveals thousands of valid AWS access keys committed to public GitHub repositories. Exposed keys are being used within minutes for cryptocurrency mining and data exfiltration. Developers using Amazon services are urged to rotate all access keys immediately.