GreyVibe Hackers Weaponize ChatGPT and Gemini in Attacks

GreyVibe Hackers Weaponize ChatGPT and Gemini in Attacks A threat group tracked as GreyVibe is actively using commercial AI platforms, including ChatGPT and Google Gemini, to build convincing attack lures and develop a custom suite of malware tools targeting military, government, civilian, and business organizations. Cybersecurity firm WithSecure identified and reported the campaign in January … Read more

GHOST STADIUM Phishing Targets FIFA World Cup Fans in Canada

GHOST STADIUM: Chinese-Linked Phishing Operation Deploys 300+ Fake FIFA Domains to Defraud World Cup Fans A large-scale, financially motivated phishing campaign has been uncovered targeting fans of the 2026 FIFA World Cup, with researchers identifying over 300 fraudulent domains engineered to steal credentials, payment information, and ticket access. The operation, attributed to a threat actor … Read more

Kali365 PhaaS (phishing-as-a-service) Bypasses MFA to Hijack Microsoft 365 Accounts

Kali365 PhaaS Platform Hijacks Microsoft 365 Accounts Without Stealing a Single Password A criminal subscription service called Kali365 is actively compromising Microsoft 365 accounts across North America and Europe, and it does so without ever needing a victim’s password or triggering a standard multi-factor authentication (MFA) prompt. The FBI issued a formal public service announcement … Read more