Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Workforce Has a Blind Spot, and It's Ringing

With inboxes increasingly well guarded, cybercriminals are turning to a more vulnerable front in their attacks against your digital workforce. Voice is the fastest-growing attack vector, and it’s because it’s dangerously effective. According to Verizon’s 2026 Data Breach Investigation Report, phone-centric attacks are 40% more successful than traditional email-based phishing.

Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy

In addition to everyday users, Google's infrastructure is trusted by email security gateways, enterprise firewalls and automated URL detonation platforms. Threat actors know this.

New Phishing Kit Uses AI to Fully Automate Vishing Attacks

A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB. The phishing platform, called “Balonx,” includes a module dubbed “CallFlow” that the researchers say “represents a fundamental evolution” in the phishing-as-a-service market.

Recruitment-Themed Phishing Campaign Targets Enterprise Users

Researchers at Zimperium are tracking widespread phishing campaigns that use Browser-in-the-Browser (BitB) attacks to trick users into handing over their enterprise credentials. The attackers impersonate real HR employees at major companies and target job seekers with extremely realistic interview processes.

Warning: Chameleon SEO Poisoning Spreads Phishing Pages

Cloaked SEO poisoning attacks surged by 40% in the second quarter of 2026, according to researchers at Fortra. This tactic, also known as “Chameleon SEO poisoning,” uses cloaked search engine results to spread phishing sites. “Chameleon SEO poisoning,” uses cloaked search engine results to spread phishing sites.

Warning: Replying to a "Wrong Number" Text Marks You as a Target for Scams

Attackers are using “wrong-number” texts to identify potential targets for scams, according to researchers at Malwarebytes. These texts appear to be harmless messages meant for another person, such as “Are we still on for dinner tomorrow?” or “Where’s the PowerPoint?” Recipients often try to be helpful by replying to let the person know they’ve got the wrong number.