Recent exploitation of CVE-2026-35616 turned FortiClient EMS into a malware delivery channel, pushing an EKZ credential stealer through trusted endpoint management paths.
Read more:Arctic WolfArctic Wolf
By PhishPond Desk
Recent code-of-conduct phishing campaigns show how attackers blend HR pressure, PDF staging, CAPTCHA gates, and AiTM flows to steal session tokens.
Read more:Microsoft Security BlogMicrosoft Security Blog
By PhishPond Desk
Persistent OAuth grants let third-party apps keep operating after the original login, password reset, or employee lifecycle event has faded from view.
Read more:The Hacker NewsMicrosoft Learn
By PhishPond Desk
A newly reported kit packages templates, domain setup, anti-analysis controls, session monitoring, and AI-assisted drafting into one operator console.
Read more:BleepingComputerVaronis
By PhishPond Desk
Microsoft's Q1 2026 email threat review shows link-based phishing dominance, QR code growth, CAPTCHA-gated flows, and persistent business email compromise pressure.
Read more:Microsoft Security Blog
By PhishPond Desk
Recent package compromises show how developer trust can be abused to harvest credentials and seed downstream phishing risk.
Read more:BleepingComputerCISA
By PhishPond Desk