<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:video="http://www.google.com/schemas/sitemap-video/1.1">
<url>
<loc>https://www.miragesecurity.ai</loc>
<lastmod>2026-07-31T04:32:41.433Z</lastmod>
<changefreq>weekly</changefreq>
<priority>1</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog</loc>
<lastmod>2026-07-31T04:32:41.433Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/resources</loc>
<lastmod>2026-07-31T04:32:41.433Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks</loc>
<lastmod>2026-07-31T00:49:27.459Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/methodology</loc>
<lastmod>2026-07-31T04:32:41.433Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.3</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/simulation</loc>
<lastmod>2026-07-31T04:32:41.433Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/talk-to-founders</loc>
<lastmod>2026-07-31T04:32:41.433Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/privacy-policy</loc>
<lastmod>2026-07-31T04:32:41.433Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.3</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/tos</loc>
<lastmod>2026-07-31T04:32:41.433Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.3</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/25-million-hk-deepfake-theft-what-you-need-to-know</loc>
<lastmod>2024-02-04T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/ai-at-war-unveiling-nation-state-attacks-with-gpt</loc>
<lastmod>2024-02-19T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/openai-s-voice-engine-what-it-means-for-cybersecurity</loc>
<lastmod>2024-04-05T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/deepfake-detection-a-lost-cause</loc>
<lastmod>2024-05-09T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/hackers-x-humans-ep-0-executive-security</loc>
<lastmod>2025-01-06T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/phishing-simulations-legit-training-or-bs</loc>
<lastmod>2024-05-29T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/social-engineering-in-2024-a-year-in-review</loc>
<lastmod>2025-02-13T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/the-dark-side-of-phishing-simulations-new-study-reveals-unexpected-risks</loc>
<lastmod>2024-11-20T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/hackers-x-humans-ep-1-the-darknet</loc>
<lastmod>2025-02-20T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/mirage-knowbe4-the-first-ai-social-engineer-integrated-with-ksat</loc>
<lastmod>2025-03-27T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/hackers-x-humans-ep-2-synthetic-threats-with-dr-matthew-canham</loc>
<lastmod>2025-05-05T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/ai-social-engineering-strategy-guide</loc>
<lastmod>2025-06-01T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/scattered-spider-a-retrospective</loc>
<lastmod>2025-06-24T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/how-scattered-spider-hacks-global-it-service-providers</loc>
<lastmod>2025-07-24T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/introducing-adaptive-training-for-vishing</loc>
<lastmod>2025-08-03T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/mirage-mimecast-integration</loc>
<lastmod>2026-01-06T09:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/hackers-x-humans-ep-3-human-risk-management-with-oz-alashe</loc>
<lastmod>2026-01-13T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/human-risk-blind-spot-dprk-hiring-fraud</loc>
<lastmod>2026-02-10T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/mirage-ethical-simulation-standards</loc>
<lastmod>2026-02-27T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/inside-p1bot-vishing-platform-weaponizing-elevenlabs</loc>
<lastmod>2026-03-11T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/introducing-mirage-rover</loc>
<lastmod>2026-04-01T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/axios-maintainer-social-engineering</loc>
<lastmod>2026-04-06T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/blog/vscode-extension-supply-chain-risk</loc>
<lastmod>2026-05-22T13:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/resources/phish-scale-calculator</loc>
<lastmod>2025-12-06T13:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/resources/vishing-simulator</loc>
<lastmod>2025-12-07T13:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/resources/knowbe4-vishing</loc>
<lastmod>2026-07-28T09:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-china-police-app-tied-to-android-rat-ring-546117ea</loc>
<video:video>
<video:title>Fake China Police App Tied to Android RAT Ring</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/546117ea.jpg</video:thumbnail_loc>
<video:description>Researchers investigated a fake Android app posing as a Chinese public security bureau service and traced it to a broader criminal ecosystem using a leaked Android remote-access tool (RAT) framework called “Flying Eagle.” The tooling lets criminals build convincing look‑alike apps and then steal credentials through in-app “overlay” login prompts targeting payment, banking, and government service apps.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/acc79965fdd321029b501455ea003a3e9652001b657f7a2f4a42e7d7efec8045/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-31T00:03:52.587Z</video:publication_date>
</video:video>
<lastmod>2026-07-31T00:03:52.587Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-cloudflare-pages-hijack-trusted-websites-d0412a9c</loc>
<video:video>
<video:title>Fake Cloudflare Pages Hijack Trusted Websites</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/d0412a9c.jpg</video:thumbnail_loc>
<video:description>Attackers compromised hundreds of legitimate websites and injected code that sent visitors to a fake Cloudflare page. The fake page used a “ClickFix” trick to convince users to run steps that installed malware. The incident shows how criminals can use trusted brands and trusted sites as the delivery mechanism, not just as a reputational issue.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/bedd6d2cc060beacd4f52b19c727e304663076e719824a6d8e416081e76e71e9/mp4/media.mp4</video:content_loc>
<video:duration>45</video:duration>
<video:publication_date>2026-07-30T21:03:16.336Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.576Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-install-guides-and-helpdesk-calls-drive-attacks-c6d3aa74</loc>
<video:video>
<video:title>Fake Install Guides and Helpdesk Calls Drive Attacks</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/c6d3aa74.jpg</video:thumbnail_loc>
<video:description>This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA, leading to account takeover or malware installation.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/49176825e472752a81b88fcf0c53576f130e204eeb64bff0bb21acfc9b48e32d/mp4/media.mp4</video:content_loc>
<video:duration>54</video:duration>
<video:publication_date>2026-07-30T17:06:33.342Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.002Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-it-support-hits-teams-to-drop-ransomware-48eaca56</loc>
<video:video>
<video:title>Fake IT Support Hits Teams to Drop Ransomware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/48eaca56.jpg</video:thumbnail_loc>
<video:description>Researchers reported a months-long campaign where attackers used Microsoft Teams chats/calls while pretending to be IT/help desk support. Victims were talked into starting remote-control sessions (Quick Assist or RemSupp), after which the attackers used PowerShell to maintain access and, in some cases, deploy Chaos ransomware quickly (as little as 17 hours after first access).</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/6c1d05b27194f8b0aadf9c4eed80731b362b887d96ff34da3ee9383c0ada2753/mp4/media.mp4</video:content_loc>
<video:duration>54</video:duration>
<video:publication_date>2026-07-30T16:05:58.332Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.498Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/lazarus-linked-lures-hit-korea-via-surveys-sites-2e1534cd</loc>
<video:video>
<video:title>Lazarus-Linked Lures Hit Korea via Surveys &amp; Sites</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/2e1534cd.jpg</video:thumbnail_loc>
<video:description>South Korean agencies and AhnLab warn that tools tied to North Korea’s Lazarus Group appear to be shared with the Gunra ransomware operation targeting South Korean organizations. The campaign used compromised legitimate websites (watering-hole attacks) and spearphishing emails, including messages disguised as a semiconductor survey, to trigger flaws in widely used Korean financial security software and deliver malicious code.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/fca6625ca1b07662747f994d2f7ee4b8bad51ce692df810e72ddaecae6f3e141/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-30T15:06:03.004Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.548Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/romance-scammer-stole-10m-by-weaponizing-trust-0e6418f5</loc>
<video:video>
<video:title>Romance Scammer Stole $10M by Weaponizing Trust</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/0e6418f5.jpg</video:thumbnail_loc>
<video:description>U.S. prosecutors said Derrick Van Yeboah ran long-running romance scams by posing as fake romantic partners online and persuading mostly older, vulnerable victims to send money. In one example, he claimed he needed funds for his mother’s funeral and to recover “imaginary gold and diamonds” from storage in Italy, leading a victim to send $123,000.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/4386d48d172a2f26089284737b72c9163feec7208b234fc8b8cd98cc4f3a2af5/mp4/media.mp4</video:content_loc>
<video:duration>50</video:duration>
<video:publication_date>2026-07-30T15:06:03.004Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:27:48.508Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/ta488-half-click-email-triggers-owa-exploit-e91a9926</loc>
<video:video>
<video:title>TA488 “Half-Click” Email Triggers OWA Exploit</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/e91a9926.jpg</video:thumbnail_loc>
<video:description>Researchers reported a real TA488 campaign where a specially crafted email exploits an Outlook Web Access (OWA) flaw and runs malicious JavaScript as soon as the user opens the message. The attack relies on normal-looking business topics to get people to quickly view the email, and then uses browser-based persistence so attackers can keep mailbox access even after password resets.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/79f1bd428d0e73c43a2992964c3dc7efeb8799ac5c67d1cc0550b56a83a0f525/mp4/media.mp4</video:content_loc>
<video:duration>47</video:duration>
<video:publication_date>2026-07-30T15:06:03.004Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.618Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/hidden-prompt-turns-copilot-docs-into-a-worm-4d412ff6</loc>
<video:video>
<video:title>Hidden Prompt Turns Copilot Docs Into a Worm</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/4d412ff6.jpg</video:thumbnail_loc>
<video:description>A security researcher demonstrated that Microsoft Copilot for Word can be tricked by hidden text inside a Word document, causing Copilot to follow attacker instructions. The result is a self-propagating “AI worm” that silently modifies documents and embeds the same hidden prompt into new files, spreading through normal document sharing without traditional malware.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/205f626da3c41b6cbb88a048ea81931b93c66ebe794e000b4a79a252b095c4b5/mp4/media.mp4</video:content_loc>
<video:duration>59</video:duration>
<video:publication_date>2026-07-30T14:05:34.941Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.456Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/teams-hr-phish-used-real-microsoft-login-flow-52baba49</loc>
<video:video>
<video:title>Teams HR Phish Used Real Microsoft Login Flow</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/52baba49.jpg</video:thumbnail_loc>
<video:description>Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When victims approved the requested permissions, the attackers obtained an authorization token and could access Microsoft 365 data like Outlook, SharePoint, and OneDrive. The compromised mailbox could also be used as a launchpad for business email compromise (BEC).</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/88a2b6614760696b267c8d0e255d1873d6ff30a062bd20cb4a3f187ee3b9f931/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-30T14:05:34.941Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.104Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/phishers-hide-behind-real-microsoft-login-0265fef1</loc>
<video:video>
<video:title>Phishers Hide Behind Real Microsoft Login</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/0265fef1.jpg</video:thumbnail_loc>
<video:description>Researchers observed a phishing campaign that tricks employees into clicking a fake Microsoft Planner task email, then sends them to a real Microsoft login page. After the user signs in, the scam relies on an OAuth permissions prompt; approving it can grant attackers ongoing access to Microsoft 365 data like email, files, Teams chats, and calendars.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/57af62778ef1bde47e13bdb4a1518b85a85a735207847753869916f273f21bb1/mp4/media.mp4</video:content_loc>
<video:duration>50</video:duration>
<video:publication_date>2026-07-30T12:05:57.531Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.508Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-resumes-watering-holes-hit-anysign4pc-users-4e0ec4d7</loc>
<video:video>
<video:title>Fake Resumes + Watering Holes Hit AnySign4PC Users</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/4e0ec4d7.jpg</video:thumbnail_loc>
<video:description>A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed. In some cases, simply visiting a compromised page triggered the exploit and installed SIGNBT or COPPERHEDGE backdoors without any download prompt. Authorities and multiple security firms say the activity affected dozens of organizations across several sectors.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/d6ca4b6c2bddda9325893349b9fce5f20116f3b05404152e22df281da675ca0a/mp4/media.mp4</video:content_loc>
<video:duration>55</video:duration>
<video:publication_date>2026-07-30T11:07:14.035Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.405Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/half-click-owa-emails-trigger-stealth-mailbox-takeover-f40e6295</loc>
<video:video>
<video:title>Half-Click OWA Emails Trigger Stealth Mailbox Takeover</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/f40e6295.jpg</video:thumbnail_loc>
<video:description>A Russia-aligned group (TA488) sent specially crafted emails that triggered malicious JavaScript simply by being viewed in Outlook Web Access (no link click or attachment needed). The implant (“OWAReaper”) can quietly change server-side mailbox permissions and abuse OAuth tokens, so attackers can keep access even after a password reset or device rebuild.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/04cd2d805ac755ddc687e21d32cd9bec7b67bc262b40e5fc6d9734d788d77350/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-30T11:07:14.035Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.208Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/half-click-owa-email-trap-spreads-e0202465</loc>
<video:video>
<video:title>“Half-Click” OWA Email Trap Spreads</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/e0202465.jpg</video:thumbnail_loc>
<video:description>Proofpoint reports a Russian-linked espionage group is using booby-trapped emails that infect users simply when they open the message in Outlook Web Access (OWA) on on‑premises Exchange. The attack runs malicious JavaScript inside the victim’s logged-in mail session and installs a stealthy browser-based implant that can persist even after password changes or device rebuilds.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/2f74ee9d99ff62fef23831d102069699bfcc5e2fde2ef6bdda8e7fc6e368562b/mp4/media.mp4</video:content_loc>
<video:duration>54</video:duration>
<video:publication_date>2026-07-30T11:07:14.035Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.134Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/invoice-phish-drops-valleyrat-via-byovd-drivers-81a89a30</loc>
<video:video>
<video:title>Invoice Phish Drops ValleyRAT via BYOVD Drivers</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/81a89a30.jpg</video:thumbnail_loc>
<video:description>Researchers reported a real campaign by the China-based Silver Fox group against a Japanese industrial manufacturer. The attack starts with an invoice-themed phishing message that leads victims to open a ZIP file, triggering a DLL sideloading chain and installing ValleyRAT for persistent remote access. The malware also abuses vulnerable drivers to weaken security controls and includes recovery mechanisms that relaunch components if defenders try to kill them.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/2dbe937736051971f5926ea54f86fd06e1cb46cfa346be5a4fef8fbdbc359fe8/mp4/media.mp4</video:content_loc>
<video:duration>55</video:duration>
<video:publication_date>2026-07-30T11:07:14.035Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.140Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/ai-chatbots-outperform-humans-in-romance-scams-998ef264</loc>
<video:video>
<video:title>AI Chatbots Outperform Humans in Romance Scams</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/998ef264.jpg</video:thumbnail_loc>
<video:description>Researchers simulated “pig butchering” romance-style scams and found an AI chatbot built trust more effectively than a human scammer over a week of texting. In the test, victims were significantly more likely to comply with the AI’s request to install an app, showing how AI could automate the long “relationship-building” stage before a human steps in to push a fake investment.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/64ca42b16ae9b86cc6545ef58d762d3971f06d11cb3696a2147ec972670ac01c/mp4/media.mp4</video:content_loc>
<video:duration>56</video:duration>
<video:publication_date>2026-07-30T10:05:11.487Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.146Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/no-action-emails-trigger-owa-mailbox-takeover-08772ea5</loc>
<video:video>
<video:title>“No-Action” Emails Trigger OWA Mailbox Takeover</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/08772ea5.jpg</video:thumbnail_loc>
<video:description>Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access (OWA) could trigger a hidden exploit. The campaign targeted government and multiple industries, then installed a stealthy browser-based implant designed to keep mailbox access even after password resets or device rebuilds.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/cf538b80cad47836b3b40ffc5feb4d64e5a0a4ba9d731ec408ef6bec3babb1ce/mp4/media.mp4</video:content_loc>
<video:duration>57</video:duration>
<video:publication_date>2026-07-30T08:04:14.725Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.125Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/phished-npm-maintainer-led-to-debug-chalk-hijack-c446184a</loc>
<video:video>
<video:title>Phished npm Maintainer Led to Debug/Chalk Hijack</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/c446184a.jpg</video:thumbnail_loc>
<video:description>Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet transactions in users’ browsers to steal funds. The same actor is linked by multiple vendors to a separate axios npm compromise, but Amazon is the main source tying North Korea to the earlier debug/chalk incident.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/46a1d7bb431d88219fe44bcca27445e8f54c2e120d59e7860c6fde6164ce72d0/mp4/media.mp4</video:content_loc>
<video:duration>55</video:duration>
<video:publication_date>2026-07-30T07:03:00.283Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.191Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-iphone-wallet-app-stole-1-8m-in-bitcoin-5952679c</loc>
<video:video>
<video:title>Fake iPhone Wallet App Stole $1.8M in Bitcoin</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/5952679c.jpg</video:thumbnail_loc>
<video:description>Three crypto investors sued Apple after allegedly losing about $1.8 million in Bitcoin to an iPhone app that impersonated the legitimate (desktop-only) Sparrow Wallet. The victims trusted the app because it was available in the App Store, then entered their wallet “seed phrase” into the counterfeit app, allowing the thieves to steal funds. The case highlights that app-store listing/approval can be abused by scammers and that seed phrases should never be entered into unverified apps.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/f7030d39447362530d5871df5fb3551b4e3b78b45cf78ddfa45d6efe08a1e859/mp4/media.mp4</video:content_loc>
<video:duration>42</video:duration>
<video:publication_date>2026-07-30T00:04:11.077Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.991Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-job-interview-lure-targets-crypto-staff-6d5369fd</loc>
<video:video>
<video:title>Fake Job Interview Lure Targets Crypto Staff</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/6d5369fd.jpg</video:thumbnail_loc>
<video:description>A North Korea-linked group is running fake recruitment campaigns to trick people into taking “online assessments” for jobs that don’t exist. The goal is to harvest personal details and potentially compromise corporate access, especially targeting non-technical staff in crypto firms who can influence or authorize financial activity.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/6c39ec6a339e47c3283df18eae5485d4785d753af30c846a609cce3d8865714f/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-30T00:04:11.077Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.345Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-iphone-crypto-wallet-stole-1-8m-f4b6b069</loc>
<video:video>
<video:title>Fake iPhone Crypto Wallet Stole $1.8M</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/f4b6b069.jpg</video:thumbnail_loc>
<video:description>Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users into entering their wallet recovery phrase, then criminals used it to drain about $1.8 million in Bitcoin. The case highlights how app-store listings and lookalike apps can be used as a convincing social-engineering lure.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/3f6672e8fe46ecf6f75c4c3d5232c61b2659d24a5b507dcb173cc475e5092890/mp4/media.mp4</video:content_loc>
<video:duration>54</video:duration>
<video:publication_date>2026-07-29T23:05:33.114Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.076Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/35-000-world-cup-fake-sites-trap-fans-0d0c3af0</loc>
<video:video>
<video:title>35,000+ World Cup Fake Sites Trap Fans</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/0d0c3af0.jpg</video:thumbnail_loc>
<video:description>Researchers tracked a large scam wave abusing interest in the 2026 FIFA World Cup, including fake merchandise stores, cloned ticket sites, and bogus “free streaming” pages. The most harmful scams used near-perfect ticket-site clones to steal login details, credit card data, and one-time passwords in real time to push through fraudulent payments. Users were commonly pulled in via search results manipulated by SEO poisoning, then redirected through multiple pages to scam destinations.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/0b6943fc1bf34dd28c03203611d5606c26515709e68a73c61608a968f67aab9d/mp4/media.mp4</video:content_loc>
<video:duration>54</video:duration>
<video:publication_date>2026-07-29T22:04:17.860Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.047Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-download-sites-hijack-clicks-to-drop-malware-13f6b7f2</loc>
<video:video>
<video:title>Fake Download Sites Hijack Clicks to Drop Malware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/13f6b7f2.jpg</video:thumbnail_loc>
<video:description>Researchers and a Windows app developer uncovered a campaign using lookalike “official” software download websites that rank highly in Google results. The sites initially serve legitimate downloads to build trust, then quietly swap the download links to malware that can steal credentials and cryptocurrency or install unwanted software.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/5e402d31970a835b2196d3249c93515c9dc610994bb7a5af1c151c7f9aecd6b8/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-29T20:04:43.952Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.271Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/laundry-bear-uses-half-click-owa-email-exploit-4c503da8</loc>
<video:video>
<video:title>Laundry Bear Uses “Half-Click” OWA Email Exploit</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/4c503da8.jpg</video:thumbnail_loc>
<video:description>UK and US cyber authorities and Proofpoint reported a real campaign where the Russian-linked group “Laundry Bear” (TA488) sent emails that could infect victims simply by being opened in Outlook Web Access. The email’s HTML triggers the server to run attacker code, installing a mailbox-stealing backdoor (“OWAReaper”) that can persist and reinfect even after device re-imaging. Targeting was unusually broad across multiple sectors, likely to blend in with normal spam traffic.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/ab7b86d9a3b1e20e3e434cc33d685d3485983a2791730f664fad515e1738dd28/mp4/media.mp4</video:content_loc>
<video:duration>61</video:duration>
<video:publication_date>2026-07-29T19:05:10.434Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.890Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/telegram-dating-bot-used-to-recruit-young-saboteurs-1b451afe</loc>
<video:video>
<video:title>Telegram Dating Bot Used to Recruit Young Saboteurs</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/1b451afe.jpg</video:thumbnail_loc>
<video:description>Russian authorities allege Telegram was used to recruit and pressure young people into real-world attacks, with “Ukrainian agents” posing as young women via a popular Telegram dating chatbot. The article describes a concrete manipulation workflow (romance/entrapment → coercion) that led to arrests and alleged attacks on critical infrastructure.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/2595ff3013e54e9d19b46c34421ff34027e95c64923fbd8d3a2ad07e3a54d6ae/mp4/media.mp4</video:content_loc>
<video:duration>51</video:duration>
<video:publication_date>2026-07-29T18:04:57.302Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.941Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/ta488-uses-half-click-owa-emails-to-persist-11ab0900</loc>
<video:video>
<video:title>TA488 Uses “Half-Click” OWA Emails to Persist</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/11ab0900.jpg</video:thumbnail_loc>
<video:description>Proofpoint reports a Russia-aligned espionage group (TA488) returned with a campaign that compromises on‑premises Outlook Web Access simply when a user opens an email in the reading pane. The attack uses a cross-site scripting flaw to run hidden JavaScript, install a browser-resident implant, and create server-side mailbox access that can survive password resets and even device re-imaging.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/863955a158bc5b62d5873f046c0b3e93f9f7e805c406f2a05b0004db493edd40/mp4/media.mp4</video:content_loc>
<video:duration>66</video:duration>
<video:publication_date>2026-07-29T16:06:36.310Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.176Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/logokit-builds-real-time-fake-login-pages-8cad4462</loc>
<video:video>
<video:title>LogoKit Builds Real-Time Fake Login Pages</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/8cad4462.jpg</video:thumbnail_loc>
<video:description>Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the victim organization’s real website and uses legitimate online services to make the phishing page look familiar, then steals credentials and redirects victims to the real site.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/0b8a1ab6912279bef2e77201dc5014aaf8bea207d661003b274ef5cdcbb5c570/mp4/media.mp4</video:content_loc>
<video:duration>46</video:duration>
<video:publication_date>2026-07-29T16:06:36.310Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.502Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/clone-websites-trick-firms-into-paying-fake-invoices-afe089cb</loc>
<video:video>
<video:title>Clone Websites Trick Firms Into Paying Fake Invoices</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/afe089cb.jpg</video:thumbnail_loc>
<video:description>Researchers described a long-running fraud campaign where criminals clone real Russian company websites and replace contact and bank details to intercept international business deals. Victims are lured through cold calls, phishing emails, and fake supplier websites, then sent realistic contracts and invoices that route “advance payments” to attacker-controlled accounts.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/597fffba1643091a5633b63272269f55e99d074a5af8cadd3ee0a3871ca16dd4/mp4/media.mp4</video:content_loc>
<video:duration>50</video:duration>
<video:publication_date>2026-07-29T15:04:37.194Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.524Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/phishing-installs-legit-remote-tools-in-2-stages-1412cb49</loc>
<video:video>
<video:title>Phishing Installs “Legit” Remote Tools in 2 Stages</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/1412cb49.jpg</video:thumbnail_loc>
<video:description>Cofense reports real phishing campaigns where attackers trick employees into installing legitimate remote access tools (like GoTo, Datto RMM, SimpleHelp, and ConnectWise). After the first tool is installed, it contacts a command-and-control server that directs it to download additional remote tools and utilities to help attackers keep access without being noticed. The approach is often used to create and sell “initial access” into corporate networks to other criminals.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/2581514d18674ecc50ee1c7591fbf63b6f27ee76e9aedf52a89f0428d11e1135/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-29T14:05:46.378Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.259Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/docusign-lure-targets-tech-exec-credentials-1333d357</loc>
<video:video>
<video:title>DocuSign Lure Targets Tech Exec Credentials</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/1333d357.jpg</video:thumbnail_loc>
<video:description>Researchers reported a real spearphishing campaign that impersonates DocuSign emails to trick tech executives into clicking “Review Document” links and entering login details. The emails use compromised legitimate business mailboxes and realistic context (including copied email threads) to appear trustworthy, then route victims to fake Google Workspace/Gmail-style login pages to steal credentials.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/2ca7fc5cdc58ccca91adb51f26ead67c9ccd95f41938da270b245f832819fd8e/mp4/media.mp4</video:content_loc>
<video:duration>65</video:duration>
<video:publication_date>2026-07-29T13:05:00.831Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.213Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/dating-bot-used-to-recruit-teens-for-sabotage-712ad6b1</loc>
<video:video>
<video:title>Dating Bot Used to Recruit Teens for Sabotage</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/712ad6b1.jpg</video:thumbnail_loc>
<video:description>Russian authorities claim Ukrainian intelligence used Telegram, including a Tinder-like dating bot, to recruit Russians (including teenagers) for sabotage and arson inside Russia. The alleged approach involved operatives posing as young women online, building relationships, and then persuading or coercing targets to carry out attacks.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/223d4b1aa7a11b09ebb7a4c0a7a23f301f9ccfcea58b52982ff713bf1f8107b0/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-29T13:05:00.831Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.248Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/telegram-dating-bot-used-for-romance-to-arson-scam-6ddf8b23</loc>
<video:video>
<video:title>Telegram Dating Bot Used for Romance-to-Arson Scam</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/6ddf8b23.jpg</video:thumbnail_loc>
<video:description>Russia’s FSB claims Ukrainian intelligence used a Telegram dating chatbot to deceive and psychologically pressure young Russians into sharing locations, clicking phishing links, and later carrying out arson or armed attacks. The alleged scheme started with romance-style outreach and payments via phishing links, then escalated to intimidation calls/messages impersonating Russian authorities. The article provides a step-by-step workflow that can be adapted into realistic awareness simulations.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/2d134b54aebecc5959948d78f0957c1a8c6ca67c7c1db38e3b4e89da56bc69e6/mp4/media.mp4</video:content_loc>
<video:duration>50</video:duration>
<video:publication_date>2026-07-29T11:05:36.018Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.637Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/120-fake-walmart-sites-steal-card-details-3f31ddeb</loc>
<video:video>
<video:title>120 Fake Walmart Sites Steal Card Details</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/3f31ddeb.jpg</video:thumbnail_loc>
<video:description>A network of more than 120 convincing Walmart lookalike websites is luring mobile shoppers with “40% to 70% off” discounts on name-brand liquor. Victims are funneled to checkout pages that collect full credit card details (number, expiry date, CVV), even though the sites have no connection to Walmart.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/e61d580dbfa9d0ea321bb439f42ef75ce37d35ae243b12b08ea710e8e04f46e0/mp4/media.mp4</video:content_loc>
<video:duration>47</video:duration>
<video:publication_date>2026-07-29T11:05:36.018Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.191Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-it-support-calls-in-teams-lead-to-ransomware-fbd23564</loc>
<video:video>
<video:title>Fake IT Support Calls in Teams Lead to Ransomware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/fbd23564.jpg</video:thumbnail_loc>
<video:description>Sophos reports a real Microsoft Teams voice-phishing campaign where attackers pretended to be IT support to convince employees to start remote-access sessions. After gaining access, the attackers ran commands to download malware and in several cases deployed Chaos ransomware within hours. The activity (tracked as STAC4749) hit dozens of organizations, mainly in the US and Canada, across multiple sectors including services, manufacturing, energy, construction/engineering, and law firms.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/4387e1a9209038614fac4dba1f5ff5fcae838b31679bf741023a4dcbd9fe6a6b/mp4/media.mp4</video:content_loc>
<video:duration>50</video:duration>
<video:publication_date>2026-07-29T11:05:36.018Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:32:18.973Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/how-attackers-bypass-mfa-in-the-real-world-a42081fc</loc>
<video:video>
<video:title>How Attackers Bypass MFA in the Real World</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/a42081fc.jpg</video:thumbnail_loc>
<video:description>The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay codes in real time, SIM swapping, and stealing session cookies so MFA isn’t needed again. It also cites known incidents (e.g., Uber 2022 MFA fatigue; Colonial Pipeline legacy VPN without MFA) and provides practical defensive steps like phishing-resistant MFA, tightening account recovery, and regularly reviewing authentication workflows.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/916e564a75929c813d947c97d58c50ced9014950a4a27860c40317379cbc056a/mp4/media.mp4</video:content_loc>
<video:duration>45</video:duration>
<video:publication_date>2026-07-29T09:04:53.692Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.340Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/phishers-hijack-meta-google-ad-accounts-for-profit-881b8fbf</loc>
<video:video>
<video:title>Phishers Hijack Meta/Google Ad Accounts for Profit</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/881b8fbf.jpg</video:thumbnail_loc>
<video:description>Criminal groups are stealing Meta Business Manager and Google Ads accounts using phishing that arrives through trusted platforms like Salesforce, Google Workspace mail-merge, and SharePoint links. The stolen accounts are valuable not just for the budget inside them, but because older accounts with real ad history can run scam ads more easily and sell for a premium. Once attackers get in, they often lock out the real owner by changing admin roles, making recovery slow and costly.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/f813851660d507d0bd79fd3aa424f4df213d16344a3901839b3687c3e5cc8163/mp4/media.mp4</video:content_loc>
<video:duration>63</video:duration>
<video:publication_date>2026-07-29T09:04:53.692Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.542Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-public-security-app-spreads-android-rat-94065782</loc>
<video:video>
<video:title>Fake Public Security App Spreads Android RAT</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/94065782.jpg</video:thumbnail_loc>
<video:description>Researchers tied the Flying Eagle Android remote-access trojan to a fake “Public Security” service app aimed at Android users in China. The malicious app was reportedly distributed from a lookalike website and could steal payment credentials and remotely control infected phones. The tooling is being shared in criminal Telegram channels, making it easier for more criminals to reuse the same scam-and-malware workflow.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/4bcc601ea49de87dd36a763f3a002739285e7f64a61591d417ead8d512dbc49c/mp4/media.mp4</video:content_loc>
<video:duration>51</video:duration>
<video:publication_date>2026-07-29T08:06:00.704Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.003Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/prompt-injection-pr-trick-leaks-repo-secrets-dc820423</loc>
<video:video>
<video:title>Prompt-Injection PR Trick Leaks Repo Secrets</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/dc820423.jpg</video:thumbnail_loc>
<video:description>A researcher showed that AI coding agents used in GitHub workflows can be tricked by a malicious pull request description into running “safe-looking” commands and then posting the results publicly, leaking secrets. The issue isn’t just the prompt; it’s how the agent’s automation pipeline (the “harness”) approves steps and then publishes outputs across stages without re-checking trust.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/02c38e8c6a2ffe178c2dd3904078bf52e4047be8be537cbb2d3a24197d4da01f/mp4/media.mp4</video:content_loc>
<video:duration>66</video:duration>
<video:publication_date>2026-07-29T07:03:19.154Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.873Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/work-panel-streamlines-vishing-into-one-console-a4565e8b</loc>
<video:video>
<video:title>“Work Panel” Streamlines Vishing Into One Console</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/a4565e8b.jpg</video:thumbnail_loc>
<video:description>Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites and guide victims through password and MFA capture. The tool clones brand look-and-feel for services like Okta and Microsoft 365, then lets a manager monitor victims in real time and push them through MFA prompts while a caller keeps them on the phone.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/accbdd07ebca5c181748ebe4500d073af6a6f516079668e29402f3429858b467/mp4/media.mp4</video:content_loc>
<video:duration>51</video:duration>
<video:publication_date>2026-07-29T02:03:52.725Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.078Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/steam-forum-fix-posts-push-malicious-powershell-de0865e5</loc>
<video:video>
<video:title>Steam Forum “Fix” Posts Push Malicious PowerShell</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/de0865e5.jpg</video:thumbnail_loc>
<video:description>Attackers used fake Steam forum replies that looked like helpful troubleshooting steps for real gaming/PC problems. The posts tricked users into running PowerShell as an administrator, which then downloaded and installed the XMRig crypto miner and set it to run automatically at startup. The campaign used a newly registered domain (msfconfig[.]icu) to host the payload.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/72ad6c1d81548a779e4b14031b9e73d5c126c6734eb2d23f5e86fc2c5b12a71e/mp4/media.mp4</video:content_loc>
<video:duration>58</video:duration>
<video:publication_date>2026-07-29T00:05:47.615Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.202Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-chatgpt-billing-emails-steal-card-details-d1bd286f</loc>
<video:video>
<video:title>Fake ChatGPT Billing Emails Steal Card Details</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/d1bd286f.jpg</video:thumbnail_loc>
<video:description>Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit card numbers.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/af97f78d0a6fec026825fc1f7e26605ced01c5538057c82a22b3b0a36401b8b6/mp4/media.mp4</video:content_loc>
<video:duration>56</video:duration>
<video:publication_date>2026-07-28T21:05:49.605Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.034Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/phantomenigma-phishes-via-hijacked-gov-br-sites-31da1f50</loc>
<video:video>
<video:title>PhantomEnigma Phishes via Hijacked .gov.br Sites</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/31da1f50.jpg</video:thumbnail_loc>
<video:description>Researchers describe a real phishing-driven malware operation (&quot;PhantomEnigma&quot;) that abuses compromised Brazilian government websites and mailboxes to appear trustworthy. Victims are lured with fake law-enforcement style documents (e.g., “Ofício” summons or “Procuração Digital”) and pushed to download and run a malicious installer that deploys a backdoor and can deliver additional payloads.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/6e744642caca9cce081dcccb73c56270eafbd2f24240890f803dcc26b41d10cf/mp4/media.mp4</video:content_loc>
<video:duration>61</video:duration>
<video:publication_date>2026-07-28T18:03:32.028Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.304Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/hotel-wi-fi-dns-scam-steals-microsoft-365-logins-28080eea</loc>
<video:video>
<video:title>Hotel Wi‑Fi DNS Scam Steals Microsoft 365 Logins</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/28080eea.jpg</video:thumbnail_loc>
<video:description>Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in pages. Victims are then tricked into completing a device-code login that grants attackers a legitimate session token, often bypassing MFA. This is a realistic scenario to simulate for traveling staff because it relies on a believable “Microsoft 365 login” workflow on public Wi‑Fi.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/bfff587ea28c5c04aaad7d83a8648d5fd5d16bb109895081d86edef67db5d250/mp4/media.mp4</video:content_loc>
<video:duration>64</video:duration>
<video:publication_date>2026-07-28T15:03:51.324Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.366Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/qr-code-pdfs-steal-microsoft-365-logins-44c6ea8f</loc>
<video:video>
<video:title>QR-Code PDFs Steal Microsoft 365 Logins</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/44c6ea8f.jpg</video:thumbnail_loc>
<video:description>Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing campaign. The campaign uses victim-tailored PDF attachments with QR codes that lead to Microsoft 365 credential-harvesting pages hosted on trusted cloud infrastructure, then uses the compromised mailbox to spread more phishing.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/f0b20cb1883f74efb1530adbea5e61fdb62f05b39541ed56663845613f94a87e/mp4/media.mp4</video:content_loc>
<video:duration>55</video:duration>
<video:publication_date>2026-07-28T14:05:52.943Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.570Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/phishers-abuse-docusign-rewards-and-verification-aeac00c2</loc>
<video:video>
<video:title>Phishers Abuse DocuSign, Rewards, and “Verification”</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/aeac00c2.jpg</video:thumbnail_loc>
<video:description>This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click through, or run commands.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/65b56ac6b29086a8f743600dedcbfcc68753216c5b4afa637b229abfedb83dbe/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-28T13:07:02.159Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.102Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/qr-pdf-phishing-hits-m365-mfa-bypass-surges-f51be5d7</loc>
<video:video>
<video:title>QR-PDF Phishing Hits M365, MFA Bypass Surges</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/f51be5d7.jpg</video:thumbnail_loc>
<video:description>Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted cloud hosting to evade email defenses. Attackers frequently bypassed multi-factor authentication using adversary-in-the-middle proxies, session-token theft, and device-code (OAuth) phishing, enabling mailbox takeover, internal re-phishing, and in some cases ransomware follow-on activity.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/935683473fd6de6eac553240d57d4c0e80dcee381173464881293fbe27b9ba8f/mp4/media.mp4</video:content_loc>
<video:duration>60</video:duration>
<video:publication_date>2026-07-28T12:06:44.821Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.500Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-teams-it-support-calls-hijack-pcs-via-quick-assist-d16b1cb5</loc>
<video:video>
<video:title>Fake Teams “IT Support” Calls Hijack PCs via Quick Assist</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/d16b1cb5.jpg</video:thumbnail_loc>
<video:description>Attackers are calling employees on Microsoft Teams while pretending to be internal IT support, then persuading them to approve a Microsoft Quick Assist remote-control session. Once the employee approves, the attacker can take control of the computer and use PowerShell to install a Go-based backdoor (GoGRPC) and other tools for long-term access and data theft.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/2522718633870f26e002d9ff784941cbe44de7aba2f4bde4fdb461ccf3e8b265/mp4/media.mp4</video:content_loc>
<video:duration>46</video:duration>
<video:publication_date>2026-07-28T11:04:28.273Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.421Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/tax-and-ssa-lures-push-stealth-malware-via-cruciferra-7d01edb3</loc>
<video:video>
<video:title>Tax and SSA Lures Push Stealth Malware via Cruciferra</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/7d01edb3.jpg</video:thumbnail_loc>
<video:description>Proofpoint linked multiple real-world email campaigns to “Cruciferra,” a commercial crypter service that helps criminals hide malware from security tools. The campaigns used familiar social-engineering themes, tax documents, U.S. Social Security Administration messages, and even bed-bug complaints, to trick recipients into clicking to fake pages or opening disguised files that delivered malware.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/4e3a7b824298fb9246531da070ad8806a35bc6f5aeefc969fd23b190920e0af0/mp4/media.mp4</video:content_loc>
<video:duration>60</video:duration>
<video:publication_date>2026-07-28T11:04:28.273Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.083Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/mirage-kitten-uses-fake-hiring-lures-to-drop-malware-ceefdcfc</loc>
<video:video>
<video:title>Mirage Kitten Uses Fake Hiring Lures to Drop Malware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/ceefdcfc.jpg</video:thumbnail_loc>
<video:description>Researchers report Mirage Kitten (an espionage-focused threat group) targeted organizations in the Middle East and Africa using highly tailored spear‑phishing. The lures included recruitment-themed messages impersonating trusted brands/hiring sites and fake videoconferencing pages that redirected people to malicious archives on file‑sharing services, leading to new malware deployments.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/8b0c830d53be5fbd29844997b776a755c7eae394e7e43d867da223872773460c/mp4/media.mp4</video:content_loc>
<video:duration>47</video:duration>
<video:publication_date>2026-07-28T08:05:04.498Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.882Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-free-cp-giveaway-steals-cod-mobile-accounts-c1ad5173</loc>
<video:video>
<video:title>Fake Free CP Giveaway Steals CoD Mobile Accounts</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/c1ad5173.jpg</video:thumbnail_loc>
<video:description>Researchers reported a real phishing campaign targeting Call of Duty Mobile players with a fake “free Call of Duty Points” giveaway site. Victims are tricked into entering their email/password and then a one-time 2FA code, allowing attackers to take over accounts and potentially access linked gaming profiles and stored payment methods.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/d17bcebda0de874af91d448c47dc6db3725d3029439297fdc1a722783bedc5e4/mp4/media.mp4</video:content_loc>
<video:duration>40</video:duration>
<video:publication_date>2026-07-28T05:02:25.276Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.602Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/hotel-wi-fi-dns-hijack-steals-m365-logins-0a3a8324</loc>
<video:video>
<video:title>Hotel Wi‑Fi DNS Hijack Steals M365 Logins</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/0a3a8324.jpg</video:thumbnail_loc>
<video:description>Researchers report attackers compromising hotel and venue Wi‑Fi “captive portal” gateways to redirect Microsoft 365 sign-ins to attacker-controlled lookalike domains. Victims can have their Microsoft 365 credentials stolen without clicking a phishing link or installing malware, because the manipulation happens at the network gateway level.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/af5ad2902c1c8e966991b259a255298e4089000844d332fc44c86764314b28f8/mp4/media.mp4</video:content_loc>
<video:duration>71</video:duration>
<video:publication_date>2026-07-28T03:03:04.916Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.251Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/hotel-wi-fi-redirect-scam-steals-microsoft-365-logins-8b9cfb9a</loc>
<video:video>
<video:title>Hotel Wi‑Fi Redirect Scam Steals Microsoft 365 Logins</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/8b9cfb9a.jpg</video:thumbnail_loc>
<video:description>Attackers are compromising hotel and conference center Wi‑Fi gateways and changing DNS settings so business travelers are silently redirected to fake Microsoft 365 login pages. When victims sign in, attackers steal passwords and potentially session tokens, allowing account takeover even when multi-factor authentication is enabled.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/be348d4ec49e92a0cf4df237b8e86d106ea16902f67f2fa5d8984b733ea1dda8/mp4/media.mp4</video:content_loc>
<video:duration>48</video:duration>
<video:publication_date>2026-07-27T23:04:52.231Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.297Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/android-aftercall-apps-push-ads-after-every-call-b98fe5f2</loc>
<video:video>
<video:title>Android “Aftercall” Apps Push Ads After Every Call</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/b98fe5f2.jpg</video:thumbnail_loc>
<video:description>Researchers found a campaign of deceptive Android apps on Google Play that pretend to be helpful tools (alarms, calendars, cleaners) but show full-screen ads right after a phone call ends. The apps persuade users to grant special “appear on top” (overlay) permissions so the ads can pop up over anything, then they hide to make removal harder.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/368d8a47dbcdf2ffaca1a263237b54dad9e5a480f127c907e6b5c660abbf03c3/mp4/media.mp4</video:content_loc>
<video:duration>47</video:duration>
<video:publication_date>2026-07-27T20:06:19.583Z</video:publication_date>
</video:video>
<lastmod>2026-07-27T20:06:19.583Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/telegram-security-alert-phish-hijacks-accounts-7f05891b</loc>
<video:video>
<video:title>Telegram “Security Alert” Phish Hijacks Accounts</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/7f05891b.jpg</video:thumbnail_loc>
<video:description>Researchers documented a real phishing operation that used Telegram “secret chats” to send fake security warnings to specific people, including an exiled Belarusian activist and users in Russia and Kazakhstan. Victims were pushed to click a personalized link and enter Telegram’s one-time login code (OTP), which would allow attackers to immediately take over the account. The campaign used anti-detection tricks (device checks, redirects, look‑alike characters) and follow-up pressure messages to increase success.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/ea721dc96e912e381447ed74a2e896aad113c919b5faabf44745771a0731539f/mp4/media.mp4</video:content_loc>
<video:duration>57</video:duration>
<video:publication_date>2026-07-27T17:03:48.544Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:27:48.480Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-shinyhunters-sextortion-demands-2-000-d0622ef7</loc>
<video:video>
<video:title>Fake ShinyHunters Sextortion Demands $2,000</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/d0622ef7.jpg</video:thumbnail_loc>
<video:description>A sextortion email campaign is using real leaked email addresses from ShinyHunters-related data dumps to make threats sound credible. The scammers impersonate the “ShinyHunters hacking group,” claim they recorded victims via webcam, and demand $2,000 in Bitcoin within 48 hours. Reporting indicates the emails are bluffs with no proof, but the leaked data helps them target and personalize messages at scale.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/ccacea0b94fbf4d944838be1013362426bbbf171ba81324df750ff759c5dbb35/mp4/media.mp4</video:content_loc>
<video:duration>51</video:duration>
<video:publication_date>2026-07-27T16:05:40.404Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.079Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/voicemail-lure-drives-microsoft-device-code-phish-cfc6397c</loc>
<video:video>
<video:title>Voicemail Lure Drives Microsoft Device-Code Phish</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/cfc6397c.jpg</video:thumbnail_loc>
<video:description>A voicemail-themed phishing campaign (“Kali365 Ringer”) targeted financial and insurance organizations using a missed-call notification and a Google Sites page to appear legitimate. Victims were redirected through multiple trusted services and instructed to approve a Microsoft device-code login session, giving attackers access without stealing a password via a fake login page.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/da18afeb108af75b47930fb25e66e1911cd0b17744d45921d50f6d9d26b43074/mp4/media.mp4</video:content_loc>
<video:duration>43</video:duration>
<video:publication_date>2026-07-27T15:06:11.448Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.645Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/hotel-wi-fi-hijacks-microsoft-365-logins-5672177f</loc>
<video:video>
<video:title>Hotel Wi‑Fi Hijacks Microsoft 365 Logins</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/5672177f.jpg</video:thumbnail_loc>
<video:description>Researchers report attackers compromising hotel and conference Wi‑Fi gateway equipment to silently redirect travelers to fake Microsoft 365 sign-in pages, without sending phishing emails. In some cases, attackers also abuse Microsoft device-code login prompts so victims unintentionally approve access tokens, potentially bypassing normal protections even when MFA is used.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/9797f66e95a1e106115ed0859862e087628c3843cbc7a1571669fe9736a0e764/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-27T15:06:11.448Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.394Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-teams-update-drops-remote-access-tools-3e98a5e9</loc>
<video:video>
<video:title>Fake Teams Update Drops Remote-Access Tools</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/3e98a5e9.jpg</video:thumbnail_loc>
<video:description>Researchers reported a real phishing campaign (“Operation BlueDash”) that tricks users with a “secure document” lure and routes them to a fake Microsoft Store page that claims Microsoft Teams must be updated. The download installs legitimate remote access tools (Level RMM and ScreenConnect) so attackers can keep persistent access to the victim’s computer.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/413ae4bcdb4e2124e395c30cb1c9253cbfa5401244495ee1e16a9712184a6395/mp4/media.mp4</video:content_loc>
<video:duration>46</video:duration>
<video:publication_date>2026-07-27T14:05:14.856Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.426Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/tax-and-ssa-phish-push-cruciferra-malware-loader-7c7cdda8</loc>
<video:video>
<video:title>Tax and SSA Phish Push Cruciferra Malware Loader</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/7c7cdda8.jpg</video:thumbnail_loc>
<video:description>Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The campaigns used a “crypter” service called Cruciferra to hide malicious files and help malware run while avoiding detection. Targets included taxpayers and finance teams, as well as organizations in hospitality/travel, and multiple regulated sectors.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/14ff2cb08fe801ba35003dd98e6b7e047684c3bf2ab35218feaf8984b7dac6be/mp4/media.mp4</video:content_loc>
<video:duration>57</video:duration>
<video:publication_date>2026-07-27T12:07:03.126Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.935Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/rogue-wi-fi-portals-steal-microsoft-365-logins-8129ea6c</loc>
<video:video>
<video:title>Rogue Wi‑Fi Portals Steal Microsoft 365 Logins</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/8129ea6c.jpg</video:thumbnail_loc>
<video:description>ReliaQuest reports attackers are compromising public Wi‑Fi “captive portal” gateways (such as in hotels and conference centers) and changing their DNS settings to redirect users to attacker-controlled pages. The goal is to harvest traveling employees’ Microsoft 365 credentials using Microsoft-impersonation lures and adversary-in-the-middle interception.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c14f9f8f41bb2523de3d729e961712b5d865a0bf546a014f9722331e604b7667/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-27T11:03:54.227Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.368Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/hotel-wi-fi-dns-trick-steals-microsoft-365-logins-04367fa6</loc>
<video:video>
<video:title>Hotel Wi‑Fi DNS Trick Steals Microsoft 365 Logins</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/04367fa6.jpg</video:thumbnail_loc>
<video:description>Researchers found attackers taking over hotel and conference-center Wi‑Fi gateways and silently redirecting guests to fake Microsoft 365 sign-in pages to steal credentials. In some cases, the attackers also tried to route broader device traffic through a malicious proxy (WPAD) or trick users into approving Microsoft “device-code” sign-ins, which can bypass passwords and MFA.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/a7a817b9444d14ccc119733c757a08e1361b8c013f1dfa8beddb661df36bf2f4/mp4/media.mp4</video:content_loc>
<video:duration>59</video:duration>
<video:publication_date>2026-07-26T14:03:25.652Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.121Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/insurance-phish-turns-otps-into-live-account-hijacks-bb8d98fd</loc>
<video:video>
<video:title>Insurance Phish Turns OTPs Into Live Account Hijacks</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/bb8d98fd.jpg</video:thumbnail_loc>
<video:description>Researchers observed insurance-themed phishing that doesn’t just steal passwords, it hijacks accounts in real time while the victim is actively logging in. The attack often starts with sponsored Google ads that lead to convincing fake insurance portals, which immediately prompt victims for one-time passcodes (OTPs) and relay them to the real site before they expire. CTM360 says a purpose-built kit (“InsureOTP Kit”) supports live session monitoring, OTP handling, and even Telegram-based data exfiltration.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/414a8fbe355e9ca03b2ee51b1ea703087238a2cac49a9a4e13504cf7da095ee7/mp4/media.mp4</video:content_loc>
<video:duration>48</video:duration>
<video:publication_date>2026-07-25T12:04:59.240Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.338Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-zoom-teams-calls-used-to-steal-crypto-wallets-33203de2</loc>
<video:video>
<video:title>Fake Zoom/Teams Calls Used to Steal Crypto Wallets</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/33203de2.jpg</video:thumbnail_loc>
<video:description>North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed cryptocurrency wallet extensions and selectively targets high-value victims before delivering malware.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/d7e1ca9ae50637caf881657445163d3105b12cf9901aaf4ec82f1e7d4d167758/mp4/media.mp4</video:content_loc>
<video:duration>51</video:duration>
<video:publication_date>2026-07-24T17:04:13.847Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.980Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/tiktok-resin-art-dm-to-order-scam-429f1c49</loc>
<video:video>
<video:title>TikTok Resin Art “DM to Order” Scam</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/429f1c49.jpg</video:thumbnail_loc>
<video:description>Scammers on TikTok are impersonating resin artists by reposting stolen videos and telling viewers to “DM to order.” After moving the conversation into direct messages (and sometimes off-platform), they request deposits or full payment and then disappear, or they try to extract personal/banking details from artists by pretending to want to buy or license work.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/3ff0cf1fa5ad532539cdc2f2a247985b37a9a6a7189cb8fe50111cf5f496fbb9/mp4/media.mp4</video:content_loc>
<video:duration>55</video:duration>
<video:publication_date>2026-07-24T16:04:41.881Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.289Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-cod-points-giveaway-steals-accounts-a14b55b6</loc>
<video:video>
<video:title>Fake CoD Points Giveaway Steals Accounts</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/a14b55b6.jpg</video:thumbnail_loc>
<video:description>A phishing campaign targets Call of Duty Mobile players by promising free Call of Duty Points (CP). Victims are tricked into entering their email, password, and then their 2FA code on a fake site that impersonates an official promotion. The attackers use the captured credentials to take over Activision accounts, potentially exposing linked gaming accounts and stored payment methods.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/829d59c21112c43c64865eccdc89c9186a6c227da7a388cfeaf0e029136ab5d6/mp4/media.mp4</video:content_loc>
<video:duration>50</video:duration>
<video:publication_date>2026-07-24T16:04:41.881Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:27:48.530Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-cloudflare-prompt-tricks-claude-agents-da9ef9e0</loc>
<video:video>
<video:title>Fake Cloudflare Prompt Tricks Claude Agents</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/da9ef9e0.jpg</video:thumbnail_loc>
<video:description>A researcher demonstrated that a Claude web-browsing agent could be manipulated by a fake “Cloudflare authentication” warning on a malicious website. Once the agent followed the prompt loop and clicked links, it could be coaxed into revealing personal/owner details such as employer and hometown. Anthropic later mitigated the issue by stopping the agent from following links on external pages.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/50278af5179b5ce5eeadfc19f5d54c58c53da782410b1c6813668969c4485b56/mp4/media.mp4</video:content_loc>
<video:duration>55</video:duration>
<video:publication_date>2026-07-24T14:06:12.810Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.267Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/kratos-phaas-fueled-mfa-bypass-phishing-1710912b</loc>
<video:video>
<video:title>Kratos PhaaS Fueled MFA-Bypass Phishing</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/1710912b.jpg</video:thumbnail_loc>
<video:description>Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session cookies. The article also describes a real campaign using tax-season lures and personalized QR codes to trick users into visiting fake Microsoft sign-in pages, enabling account takeover and follow-on business email compromise.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/1dedf92671fac2cb910d295f9605d6578c1b263f0c0d92204465ad3b85a07e95/mp4/media.mp4</video:content_loc>
<video:duration>65</video:duration>
<video:publication_date>2026-07-24T13:04:29.180Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.468Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/phishing-link-could-plant-a-rogue-chatgpt-agent-d43d2a88</loc>
<video:video>
<video:title>Phishing Link Could Plant a Rogue ChatGPT Agent</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/d43d2a88.jpg</video:thumbnail_loc>
<video:description>Researchers described a now-patched flaw (&quot;AgentForger&quot;) where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent could run on a schedule, take &quot;TASK&quot; instructions via email, and exfiltrate results back to the attacker.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/25c56b1e1b2753061ba792c376eb629dbe7e128292a5d77ac56f20e1e95c29b8/mp4/media.mp4</video:content_loc>
<video:duration>51</video:duration>
<video:publication_date>2026-07-24T13:04:29.180Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:32:18.942Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/lampion-phishing-hits-portugal-with-fake-brands-0be0e66b</loc>
<video:video>
<video:title>Lampion Phishing Hits Portugal With Fake Brands</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/0be0e66b.jpg</video:thumbnail_loc>
<video:description>Researchers report that the Lampion banking Trojan is spreading in Portugal through phishing emails that impersonate legitimate private-sector entities. Victims who follow the lure end up with a credential-stealing remote-access tool (RAT) that can overlay fake login screens on banking sites to capture credentials.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/4d5d8163fac7e951aef0cf349e40ededb9e4f2c1994184b74365a846a0b85614/mp4/media.mp4</video:content_loc>
<video:duration>46</video:duration>
<video:publication_date>2026-07-24T12:06:49.503Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.411Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-chatgpt-billing-emails-steal-card-details-500e018c</loc>
<video:video>
<video:title>Fake ChatGPT Billing Emails Steal Card Details</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/500e018c.jpg</video:thumbnail_loc>
<video:description>Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores and fake login pages to steal credentials or payments.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/fa0073184246126b91ae14b0f6761327924a5533215849d26d15cef0d7641ef4/mp4/media.mp4</video:content_loc>
<video:duration>46</video:duration>
<video:publication_date>2026-07-24T12:06:49.503Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.560Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/hotel-wi-fi-dns-poisoning-steals-work-logins-837253f0</loc>
<video:video>
<video:title>Hotel Wi‑Fi DNS Poisoning Steals Work Logins</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/837253f0.jpg</video:thumbnail_loc>
<video:description>Researchers reported an ongoing campaign where attackers compromise hotel and conference venue Wi‑Fi routers and quietly redirect visitors’ web traffic through attacker-controlled systems. This can lead to corporate usernames and passwords being captured even when the victim does not click a phishing link, because the network itself is manipulated.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/f7363e5858c420082a862ee5f9dd0ab66c946cf7205ce168aefc588eb16310c5/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-24T12:06:49.503Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.885Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/zimbra-zero-day-email-preview-triggers-espionage-7665d37d</loc>
<video:video>
<video:title>Zimbra Zero-Day Email: Preview Triggers Espionage</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/7665d37d.jpg</video:thumbnail_loc>
<video:description>A Russia-aligned espionage group sent specially crafted HTML emails that could compromise vulnerable Zimbra webmail servers just by being opened or previewed, no link clicks or attachments needed. The exploit ran JavaScript inside the email body to steal mailbox data and credentials, then set up persistent access by creating an application password.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/484b1dc1ea9b838decd072e409f0435a513b936c8292c95ac643b6b293739689/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-24T12:06:49.503Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.860Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/clickfix-lures-push-golden-chickens-malware-2320d2a0</loc>
<video:video>
<video:title>ClickFix Lures Push Golden Chickens Malware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/2320d2a0.jpg</video:thumbnail_loc>
<video:description>Recorded Future reports the Golden Chickens (TAG-195) malware-as-a-service operation has resurfaced with four new malware families, including TinyEgg and ChonkyChicken. The group (and a linked operator TAG-127) has used ClickFix-style social engineering that tricks people into manually running malicious commands, leading to malware installation and credential theft from web browsers.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/f173285fb807a9305dcba52859fa2e46732f2aae20dae05f5dbe10a91170ff2e/mp4/media.mp4</video:content_loc>
<video:duration>44</video:duration>
<video:publication_date>2026-07-24T11:03:54.906Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.478Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/teams-phishing-rises-after-tycoon2fa-takedown-3601310e</loc>
<video:video>
<video:title>Teams Phishing Rises After Tycoon2FA Takedown</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/3601310e.jpg</video:thumbnail_loc>
<video:description>Microsoft reported that phishing tied to the Tycoon2FA phishing-as-a-service platform dropped sharply after a disruption, pushing attackers to change tactics rather than stop. The report highlights real campaigns that shifted toward Microsoft Teams-based social engineering, highly automated BEC email blasts, and multi-stage phishing using calendar invites and Microsoft login redirects to deliver malware.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/3481c65df5fd96c9de1d31d492bce29030ca2ba657b45b52bfa89453fc07818f/mp4/media.mp4</video:content_loc>
<video:duration>65</video:duration>
<video:publication_date>2026-07-24T11:03:54.906Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:32:18.941Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-notepad-plugin-used-in-ukraine-phish-8ff13ada</loc>
<video:video>
<video:title>Fake Notepad++ Plugin Used in Ukraine Phish</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/8ff13ada.jpg</video:thumbnail_loc>
<video:description>CERT-UA reports a real phishing campaign linked to Russia-aligned actor UAC-0099 targeting Ukrainian organizations. Victims receive an email with an image attachment that leads (via a link shortener) to a file-sharing download, where a disguised script installs a trojanized Notepad++ plugin and sets up persistence. The malware chain includes a loader designed to misbehave if analysts run it incorrectly, making investigation harder.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/f15b43156443777ac30436262d7355bbdcb7a7eb599649510ffad7961dc0466c/mp4/media.mp4</video:content_loc>
<video:duration>67</video:duration>
<video:publication_date>2026-07-24T10:03:53.165Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.423Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/laundry-bear-uses-zero-click-zimbra-email-trap-1972fb99</loc>
<video:video>
<video:title>Laundry Bear Uses Zero-Click Zimbra Email Trap</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/1972fb99.jpg</video:thumbnail_loc>
<video:description>A newly identified Russia-linked threat actor (“Laundry Bear”) is targeting Western organisations with a zero-click technique that can compromise Zimbra webmail simply by viewing a malicious email. The campaign has reportedly stolen sensitive data across multiple sectors and may evolve to target other email platforms as organisations patch.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/1bef42b52199bfcf2b33005091df473ca1fbbed3ad5dbcb22b2a51a3c2362102/mp4/media.mp4</video:content_loc>
<video:duration>62</video:duration>
<video:publication_date>2026-07-24T09:03:30.539Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:32:18.931Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/phishing-email-pushes-fake-notepad-plugin-852d7225</loc>
<video:video>
<video:title>Phishing Email Pushes Fake Notepad++ Plugin</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/852d7225.jpg</video:thumbnail_loc>
<video:description>CERT-UA reported a real phishing campaign where victims receive an email with an image attachment that leads (via a shortened link) to a ZIP download. The ZIP contains a script disguised as a PDF, which installs a malicious Notepad++ plugin and sets up an automated task that repeatedly runs malware to load additional payloads.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/3157ee94aaeda70a174a4e478864eb51353e1b37d9377f5d493a8598d257dd58/mp4/media.mp4</video:content_loc>
<video:duration>54</video:duration>
<video:publication_date>2026-07-24T07:03:51.897Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.253Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/agentforger-turns-ai-agents-into-insider-threats-281c4007</loc>
<video:video>
<video:title>AgentForger Turns AI Agents Into Insider Threats</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/281c4007.jpg</video:thumbnail_loc>
<video:description>Zenity Labs described a real phishing-based technique (“AgentForger”) that could silently create an autonomous AI agent inside an OpenAI workspace after a single click. The planted agent can keep running on a schedule, read and act across connected tools like Outlook/Slack/Drive, and execute new instructions sent by attackers via email. OpenAI patched the underlying flaw within days, but the workflow shows how “rogue” enterprise AI agents could be abused as persistent insiders.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/d0c699f9fa74ae2f009ac47cd710085922f21bfe0c0cf004c4e4e6c66b941d66/mp4/media.mp4</video:content_loc>
<video:duration>56</video:duration>
<video:publication_date>2026-07-24T01:03:21.094Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:32:18.905Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/13m-emails-push-japan-users-into-tech-support-scam-57e3336e</loc>
<video:video>
<video:title>13M Emails Push Japan Users Into Tech Support Scam</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/57e3336e.jpg</video:thumbnail_loc>
<video:description>Researchers observed a long-running tech support scam that sent over 13 million emails, mostly to Japanese “.jp” addresses, pushing victims to fake security alert websites. The lures increasingly looked like workplace HR and internal IT notices, aiming to trick employees into clicking links, calling a bogus support line, and ultimately paying fees or moving money while attackers remotely controlled the device.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/2c424d099faaf68957991765654caaccc1ffe15830ce16b937a05d7748cf304b/mp4/media.mp4</video:content_loc>
<video:duration>54</video:duration>
<video:publication_date>2026-07-23T23:03:44.319Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.349Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/ta488-half-click-emails-hack-zimbra-webmail-db69b67c</loc>
<video:video>
<video:title>TA488 “Half-Click” Emails Hack Zimbra Webmail</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/db69b67c.jpg</video:thumbnail_loc>
<video:description>A Russian-aligned group (TA488) used malicious emails to exploit a Zimbra webmail flaw so that simply opening or previewing a message triggered compromise, no link click or attachment required. The attackers then stole email data and set up persistent access to compromised mail servers, including by creating an app password named “ZimbraWeb.” The campaign focused on Ukrainian and U.S. government-related organizations, plus defense and scientific groups.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/d996fee93880eb791ee32d873f6863e2231c2f58b0cfe43afea5d7109f007bc1/mp4/media.mp4</video:content_loc>
<video:duration>46</video:duration>
<video:publication_date>2026-07-23T22:04:29.353Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.929Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/zero-click-emails-hit-zimbra-users-in-espionage-push-4cacdce3</loc>
<video:video>
<video:title>Zero-Click Emails Hit Zimbra Users in Espionage Push</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/4cacdce3.jpg</video:thumbnail_loc>
<video:description>Government agencies and security firms warn that Russia-aligned hackers are using “zero-click” phishing emails to compromise organizations using Zimbra webmail. The attack hides a malicious JavaScript payload inside an email so it runs when the message is opened, aiming to steal recent email, passwords, contacts, and authentication tokens. Authorities urge Zimbra customers to patch immediately or switch users to a different mail client if patching isn’t possible.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/e57e6974c9ef12e1e65240f0126aa8b80834a0453f8aec04308f498c2c240484/mp4/media.mp4</video:content_loc>
<video:duration>47</video:duration>
<video:publication_date>2026-07-23T18:05:11.260Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-captcha-copy-paste-sites-push-castleloader-12e71ae7</loc>
<video:video>
<video:title>Fake CAPTCHA “Copy/Paste” Sites Push CastleLoader</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/12e71ae7.jpg</video:thumbnail_loc>
<video:description>Threat actors are using fake CAPTCHA pages on compromised or lookalike websites to trick people into copying and pasting malicious commands (“paste and run”). The article describes real campaigns tied to CastleLoader and similar activity, including fake background-removal sites and job-site impersonation domains promoted via Google Ads.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/a85d04a046e0a5d3176b89adeaed709136b713f619cca2d06dd3aeaf4de7b688/mp4/media.mp4</video:content_loc>
<video:duration>53</video:duration>
<video:publication_date>2026-07-23T18:05:11.260Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.867Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-claude-app-and-alert-apps-drive-new-scams-0fad97e2</loc>
<video:video>
<video:title>Fake Claude App and Alert Apps Drive New Scams</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/0fad97e2.jpg</video:thumbnail_loc>
<video:description>This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to click, download, or install, and then the malware steals data or enables surveillance.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/a826ebad42950c2b6e7b43e22410d5aa7f503b4ce2895aecc0580f3668d5167a/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-23T17:05:31.488Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:34:18.885Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/zimbra-email-view-triggers-russian-data-theft-9563d840</loc>
<video:video>
<video:title>Zimbra Email View Triggers Russian Data Theft</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/9563d840.jpg</video:thumbnail_loc>
<video:description>Government agencies say a Russian-linked group sent specially crafted HTML emails that exploit a Zimbra webmail flaw, so simply viewing the message can trigger data theft, no click required. The campaign has targeted multiple Western sectors since July 2025 and focuses on stealing email content and login information to maintain access.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/42625b79120905c390521a93732a8cee63b7b2355fc87c8a5ac478d9c8ce5fb9/mp4/media.mp4</video:content_loc>
<video:duration>68</video:duration>
<video:publication_date>2026-07-23T17:05:31.488Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.255Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/one-click-phish-could-spawn-a-hidden-ai-insider-d0071bdd</loc>
<video:video>
<video:title>One-Click Phish Could Spawn a Hidden AI Insider</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/d0071bdd.jpg</video:thumbnail_loc>
<video:description>Researchers disclosed a flaw in OpenAI ChatGPT Workspace Agents that could let an attacker trick an employee into creating an invisible, attacker-controlled “autonomous agent” inside the company. The attack depends on a phishing message that gets a logged-in user to click a weaponized URL, after which the agent can take instructions from attacker emails and use already-connected apps (like Gmail/Outlook) to act and send results back out.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/eed7a86abeefd23426180c3b8e8079248b0e72e53ca6e2790f3d5d359cb40c79/mp4/media.mp4</video:content_loc>
<video:duration>55</video:duration>
<video:publication_date>2026-07-23T16:08:19.495Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:32:18.994Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/bec-are-you-at-your-desk-lures-surge-in-q2-90ed2eac</loc>
<video:video>
<video:title>BEC ‘Are you at your desk?’ Lures Surge in Q2</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/90ed2eac.jpg</video:thumbnail_loc>
<video:description>Microsoft reports billions of phishing attempts in Q2 2026, with attackers increasingly using attachments (PDF/DOC/HTML) and new formats like calendar invites to trick employees into entering credentials. The report also highlights continued growth in Teams-based social engineering and notes that most BEC scams start with simple “conversation starter” emails before moving to fraud.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/78282fdc07f5a26cfd3d5acb305b6b0c669011854663f96761559cc9a81e39e3/mp4/media.mp4</video:content_loc>
<video:duration>47</video:duration>
<video:publication_date>2026-07-23T16:08:19.495Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.027Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/zero-click-zimbra-webmail-phish-hits-nato-sectors-5f2aac4b</loc>
<video:video>
<video:title>Zero-Click Zimbra Webmail Phish Hits NATO Sectors</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/5f2aac4b.jpg</video:thumbnail_loc>
<video:description>Researchers at Unit 42 reported a real espionage campaign targeting organizations using Zimbra webmail, including government, defense, transportation and financial sectors. The attackers sent “zero-click” phishing emails disguised as news headlines, where opening/viewing the message could trigger a Zimbra vulnerability and silently steal mailbox data and credentials. The stolen data was sent to attacker-controlled command-and-control servers, with multiple domains and IPs observed.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/98f87abf25761c99b2c3973e379a07431242e6ee1a51d1a22ef72ef8ecb9abdc/mp4/media.mp4</video:content_loc>
<video:duration>61</video:duration>
<video:publication_date>2026-07-23T15:05:07.859Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.092Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-claude-download-used-in-jadeprox-attacks-fc34dbd2</loc>
<video:video>
<video:title>Fake Claude Download Used in JadeProx Attacks</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/fc34dbd2.jpg</video:thumbnail_loc>
<video:description>Investigators found evidence of a China-linked operation (tracked as JadeProx) targeting government, healthcare, and education organizations, including spear-phishing and a fake software download site. One campaign impersonated Anthropic’s Claude using a lookalike domain to deliver a malicious Windows installer, while another used a decoy “account statement” document to lure victims.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/d30fe11faed753fe06d4d2430a2a381f042adcf92c483846727e0a0f8cbe59fb/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-23T15:05:07.859Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.192Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-claude-download-page-led-to-sectoprat-17000ce2</loc>
<video:video>
<video:title>Fake Claude Download Page Led to SectopRAT</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/17000ce2.jpg</video:thumbnail_loc>
<video:description>Attackers abused Anthropic’s Claude “Artifacts” publishing feature to host a convincing fake Claude download page on the real claude.ai domain. Victims found it via a sponsored Bing ad, clicked “Download,” and were redirected to attacker-controlled sites that delivered the SectopRAT remote access trojan. Huntress says employees at 29+ organizations were compromised in just two days.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/e6da4d788e7cf600cf99925f06809595b7c74f30699762c51ce5fc9a59ac8c2a/mp4/media.mp4</video:content_loc>
<video:duration>57</video:duration>
<video:publication_date>2026-07-23T14:07:36.624Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.043Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/phishing-link-plants-a-rogue-chatgpt-insider-bb77eac7</loc>
<video:video>
<video:title>Phishing Link Plants a Rogue ChatGPT “Insider”</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/bb77eac7.jpg</video:thumbnail_loc>
<video:description>Researchers say a one-click phishing link could trick ChatGPT into creating a malicious AI “agent” inside a company’s ChatGPT workspace. The agent could act using the employee’s existing access (Outlook, Teams, Slack, Google Drive, etc.), run on a schedule, and take instructions from attacker emails, effectively behaving like an insider account.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/4e1d2a136ec6ee6bcc0d18164002189f0b3108dafc1aefd7978f4ed49ea965ab/mp4/media.mp4</video:content_loc>
<video:duration>50</video:duration>
<video:publication_date>2026-07-23T14:07:36.624Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.316Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-badges-and-uniforms-to-walk-in-15ba6d01</loc>
<video:video>
<video:title>Fake Badges and Uniforms to Walk In</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/15ba6d01.jpg</video:thumbnail_loc>
<video:description>The article describes how social engineers can use cheap, online-ordered lookalike lanyards, ID badges, uniforms, and PPE to appear legitimate and gain physical access to facilities. It’s based on real physical security engagements where testers used convincing “visual tokens of trust” (badges, branded clothing, key fobs, letterhead) to reduce suspicion. The main lesson is that appearance is not identity, staff must consistently verify unfamiliar people even when they look the part.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/6243ce60db314be779d12fc92193776db38043a19594cff6eaa5ebec0558e5b1/mp4/media.mp4</video:content_loc>
<video:duration>46</video:duration>
<video:publication_date>2026-07-23T13:05:50.832Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.249Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/deepfake-video-call-drove-25m-wire-transfer-scam-e2d6141f</loc>
<video:video>
<video:title>Deepfake Video Call Drove $25M Wire Transfer Scam</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/e2d6141f.jpg</video:thumbnail_loc>
<video:description>The article discusses Google’s new selfie-video account recovery, but it also highlights a real deepfake-enabled fraud case. In that incident, a finance employee joined a video call showing deepfake versions of coworkers and was persuaded to send multiple wire transfers, illustrating how realistic impersonation can override normal suspicion.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/bc6b1dfc755e9bda53fec141aaa37357647e6b43287f58dc46eaf629cb0bb55e/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-23T11:05:34.701Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.237Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/chaos-rat-masquerades-as-windows-update-b40ce326</loc>
<video:video>
<video:title>Chaos RAT Masquerades as Windows Update</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/b40ce326.jpg</video:thumbnail_loc>
<video:description>Cisco Talos reports a remote access trojan (msaRAT) linked to the Chaos ransomware group that hides its command-and-control traffic inside legitimate Chrome/Edge browser activity. The malware is delivered as a fake “Windows update” MSI and, once run, launches a browser in a special debug mode to tunnel attacker commands over encrypted WebRTC traffic via trusted cloud services.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/3861e0b2a37d19c13bbe2e466f522fcfef3aecd7eb15d2cecf5699e9b6b00834/mp4/media.mp4</video:content_loc>
<video:duration>54</video:duration>
<video:publication_date>2026-07-23T11:05:34.701Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.190Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-badge-real-access-to-hospital-records-b8c2718e</loc>
<video:video>
<video:title>Fake Badge, Real Access to Hospital Records</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/b8c2718e.jpg</video:thumbnail_loc>
<video:description>A hired security tester socially engineered a hospital nurse to unlock a restricted medical records room, despite having a non-working fake badge. He used a believable story, referenced a real doctor’s name, and built rapport by complaining about that doctor to convince the gatekeeper to let him in. The story highlights how friendly, “I belong here” behavior can bypass physical controls and lead to exposure of sensitive medical files.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/3175a243b4761fa63f3499d49bcd4fa41f2fe60f2bd035508aba8433d0a69ad9/mp4/media.mp4</video:content_loc>
<video:duration>41</video:duration>
<video:publication_date>2026-07-23T07:03:45.910Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.904Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/kimsuky-poses-as-diplomats-in-lnk-phishing-ec01228b</loc>
<video:video>
<video:title>Kimsuky Poses as Diplomats in LNK Phishing</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/ec01228b.jpg</video:thumbnail_loc>
<video:description>AhnLab reports real-world spear-phishing attacks by the Kimsuky group that impersonate diplomatic personnel and trick targets into opening disguised LNK “document” attachments. Opening the fake document launches scripts that install tools like the PebbleDash backdoor and PrxClient proxy, enabling remote control and data theft. The campaign is described as targeting people in the education sector and using diplomatic-themed decoy files to look legitimate.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/5309d4b1285dd9fdbff093e07fdc85ee64c5691e962078ba40dd9c9147061cbb/mp4/media.mp4</video:content_loc>
<video:duration>63</video:duration>
<video:publication_date>2026-07-23T04:03:36.583Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.147Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-defense-summit-invites-hit-dutch-police-06622705</loc>
<video:video>
<video:title>Fake Defense Summit Invites Hit Dutch Police</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/06622705.jpg</video:thumbnail_loc>
<video:description>A Russian-linked group allegedly stole sensitive contact data from the Netherlands National Police after getting access to an employee’s email account. The podcast describes a realistic spearphishing lure: an email invitation to a “European Defence Summit” that includes a link or a QR code in a PDF leading to a fake Microsoft Teams login page designed to capture credentials.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/30e68183bc7584aedfe9e9fd6990093cce269244344385797a1669f0b5eeec90/mp4/media.mp4</video:content_loc>
<video:duration>47</video:duration>
<video:publication_date>2026-07-23T00:03:33.200Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:27:48.531Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/device-code-phish-bypasses-mfa-via-real-microsoft-login-faa3c0f9</loc>
<video:video>
<video:title>Device-Code Phish Bypasses MFA via Real Microsoft Login</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/faa3c0f9.jpg</video:thumbnail_loc>
<video:description>Attackers abused Microsoft’s OAuth “device code” sign-in so victims completed a real Microsoft login and MFA, but the resulting session tokens were issued to the attacker. In a documented Microsoft 365 takeover, the attacker used a believable partner-law-firm email thread and a Google Sites lure page to get the victim to enter a verification code on Microsoft’s legitimate sign-in page. After approval, the attacker signed in from abroad, registered rogue devices, and created hidden mailbox rules to maintain access and spread more phishing.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/f05554cebc2e3d869f2bfff8e047ab9895a4b1b5044ff3459d387ac34df22873/mp4/media.mp4</video:content_loc>
<video:duration>46</video:duration>
<video:publication_date>2026-07-22T20:05:42.821Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.962Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/hidden-pr-prompts-trick-azure-devops-ai-agents-0319cf1b</loc>
<video:video>
<video:title>Hidden PR Prompts Trick Azure DevOps AI Agents</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/0319cf1b.jpg</video:thumbnail_loc>
<video:description>Researchers showed that hidden instructions in an Azure DevOps pull request description can trick an AI coding assistant into taking unintended actions using the reviewer’s own access. In a proof of concept, the AI agent was manipulated to pull confidential data from another project and post it back into the attacker’s pull request, without stealing credentials.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/229fbbc6d1ac2b81b52363787bec7be8b291b0bc8988cb8feb5703da01b884c3/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-22T15:04:16.121Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.861Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/survey-call-led-to-sim-swap-near-takeover-7c1e879c</loc>
<video:video>
<video:title>Survey Call Led to SIM Swap Near-Takeover</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/7c1e879c.jpg</video:thumbnail_loc>
<video:description>An attacker called the victim pretending to be their mobile carrier, built trust with a “customer satisfaction survey,” then asked the victim to read back an SMS one-time passcode and a long-standing account passcode. The attacker had already initiated (and days earlier executed) a SIM swap, then used the collected details to log in, hijack the session, and make unauthorized account changes before the victim recovered access.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/df264eb36fba32d070644e2584288076fc6b20566d66b5475aac07e05fe56658/mp4/media.mp4</video:content_loc>
<video:duration>53</video:duration>
<video:publication_date>2026-07-22T14:06:57.639Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.113Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/kratos-kit-used-w-2-qr-phish-to-hijack-m365-3cfa7993</loc>
<video:video>
<video:title>Kratos Kit Used W-2 QR Phish to Hijack M365</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/3cfa7993.jpg</video:thumbnail_loc>
<video:description>Law enforcement dismantled the infrastructure behind Kratos, a widely used phishing kit that helped criminals steal Microsoft 365 credentials and, in some cases, capture session cookies to bypass MFA. The article describes a real, observed campaign using tax-themed W-2 QR-code emails that led victims to a fake Microsoft 365 login page. It also includes concrete technical “tells” (file names and collection endpoints) defenders can use to identify Kratos-style phishing pages.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/ac9a52d48b32726a1ec7bc4ee304bd439ca7fa9c4a5cb6f9bc0c7e3989a258c4/mp4/media.mp4</video:content_loc>
<video:duration>68</video:duration>
<video:publication_date>2026-07-22T08:06:32.523Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.361Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/hidden-pr-text-can-hijack-azure-devops-ai-reviews-8c8679da</loc>
<video:video>
<video:title>Hidden PR Text Can Hijack Azure DevOps AI Reviews</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/8c8679da.jpg</video:thumbnail_loc>
<video:description>Researchers showed that an attacker can hide instructions inside an Azure DevOps pull request description so an AI coding agent follows the attacker’s directions instead of the reviewer’s. Because the agent acts with the reviewer’s permissions, it can access other projects and leak sensitive content (like confidential wiki pages) back into the pull request where the attacker can read it.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/9dd60142ef3b72e1de24de9d0371271a94011537e1b592602f0c670b65b2ed33/mp4/media.mp4</video:content_loc>
<video:duration>46</video:duration>
<video:publication_date>2026-07-22T07:03:35.868Z</video:publication_date>
</video:video>
<lastmod>2026-07-31T00:48:23.295Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/finance-phishing-lures-feed-telegram-data-leaks-3e45ff0e</loc>
<video:video>
<video:title>Finance Phishing Lures Feed Telegram Data Leaks</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/3e45ff0e.jpg</video:thumbnail_loc>
<video:description>A June 2026 financial-sector threat report describes real phishing emails that used business-looking themes (e.g., money transfers, receipts, voicemail) to push victims to malicious links or HTML attachments that mimic login pages. The report also highlights cases where stolen account information was exfiltrated to attackers via the Telegram API, alongside dark-web sales of financial datasets and access credentials.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/6a60d3994a7c7c818bffbbca6fa7b816e379981dc5db9af0be1c11be8e41cec3/mp4/media.mp4</video:content_loc>
<video:duration>41</video:duration>
<video:publication_date>2026-07-22T03:03:42.474Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.229Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/govt-themed-phishing-spreads-cruciferra-malware-0bb30b03</loc>
<video:video>
<video:title>Govt-Themed Phishing Spreads Cruciferra Malware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/0bb30b03.jpg</video:thumbnail_loc>
<video:description>Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a “crypter” service called Cruciferra to help common remote-access and data-stealing malware evade detection. Financial services, healthcare, and government organizations were frequently targeted.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/4d9ebabfe5cdf09c9b1e35d8b76db38f2e4103c34be61c9015851f53a24b75f4/mp4/media.mp4</video:content_loc>
<video:duration>48</video:duration>
<video:publication_date>2026-07-21T22:02:49.835Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:32:18.979Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-teams-update-led-to-630k-crypto-theft-36e09bdb</loc>
<video:video>
<video:title>Fake Teams “Update” Led to $630K Crypto Theft</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/36e09bdb.jpg</video:thumbnail_loc>
<video:description>AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft Teams call link. After the call “had no working audio,” the victim approved what looked like a Teams update, which installed a malicious extension that later enabled theft of about $630,000 in crypto.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/fd76537e62b090c28e984838866a0e36e07d9ec27fb1cd1a5df0a17e7952d1c9/mp4/media.mp4</video:content_loc>
<video:duration>47</video:duration>
<video:publication_date>2026-07-21T18:06:33.991Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.501Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/kratos-phaas-takedown-fake-microsoft-logins-c51ef846</loc>
<video:video>
<video:title>Kratos PhaaS Takedown: Fake Microsoft Logins</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/c51ef846.jpg</video:thumbnail_loc>
<video:description>German and international law enforcement disrupted the infrastructure behind “Kratos,” a phishing-as-a-service kit used at scale to steal Microsoft account logins. The kit provided convincing Microsoft-themed fake login pages designed to steal passwords and session cookies, which could help criminals bypass multi-factor authentication (MFA). Reporting also links the kit to tax-season lures (fake W-2 forms) and other common cloud-service themes like SharePoint and OneDrive.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/a3b823ea22d7470f3ac40b44a1c42c62a68e3f18862ad34726f57a8c6bb2ed9d/mp4/media.mp4</video:content_loc>
<video:duration>55</video:duration>
<video:publication_date>2026-07-21T17:05:05.103Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.020Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/ai-agents-steered-to-malware-on-fake-github-repos-113e935e</loc>
<video:video>
<video:title>AI Agents Steered to Malware on Fake GitHub Repos</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/113e935e.jpg</video:thumbnail_loc>
<video:description>Researchers found thousands of malicious GitHub repositories designed to look like real developer tools, including hundreds posing as AI “Skills” and Model Context Protocol (MCP) servers. In a technique dubbed “AgentBaiting,” attackers rely on AI assistants to discover these repos and pass the installation steps to users, leading them to download and run malware that steals credentials and active sessions.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/d5e3f9d7b5a3d3a2e09ef318cf05307ddb79a75f79be2a77b1a924024150cc9e/mp4/media.mp4</video:content_loc>
<video:duration>47</video:duration>
<video:publication_date>2026-07-21T15:04:16.720Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.538Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-google-ads-sync-alert-steals-credentials-ca7e94e8</loc>
<video:video>
<video:title>Fake Google Ads “Sync” Alert Steals Credentials</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/ca7e94e8.jpg</video:thumbnail_loc>
<video:description>Cofense observed a real phishing campaign impersonating Google Ads Sync Accounts (MMC) with a fake “maintenance/system upgrade” notice. The email pressures recipients to click “Complete Sync Account,” sending them through lookalike sites and a fake Google sign-in pop-up that captures credentials. The attack relies on brand trust (Google logos) and urgency (threats of service interruption) to drive clicks.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/4a6cf0e0984c454946ef58800cf1354210f4e554ec94ec65162bfebe5decff32/mp4/media.mp4</video:content_loc>
<video:duration>46</video:duration>
<video:publication_date>2026-07-21T15:04:16.720Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.001Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/m365-device-code-phishing-bypasses-user-suspicion-ca47aaeb</loc>
<video:video>
<video:title>M365 Device Code Phishing Bypasses User Suspicion</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/ca47aaeb.jpg</video:thumbnail_loc>
<video:description>Attackers trick employees into entering a short “device code” on a real Microsoft sign-in page (microsoft.com/devicelogin), causing Microsoft 365 to issue login tokens directly to the attacker. Because the victim completes a legitimate MFA-approved sign-in on a legitimate Microsoft URL, the activity can look normal and may bypass some Conditional Access patterns. The result is persistent access via refresh tokens, often leading to mailbox access, inbox rule tampering, and business email compromise (BEC).</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/069b80f116781e292108de18e69ef8caef8094da0ccc71b4772ae0a538977d3e/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-21T14:06:03.441Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.610Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/clicklock-stealer-freezes-macs-for-passwords-15d96754</loc>
<video:video>
<video:title>ClickLock Stealer Freezes Macs for Passwords</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/15d96754.jpg</video:thumbnail_loc>
<video:description>Researchers found a new macOS infostealer, “ClickLock Stealer,” that uses ClickFix-style fake verification pages to trick people into running Terminal commands. After infection, it shows a realistic macOS password prompt and can effectively lock the Mac until the victim enters the correct password, then sends stolen data to attackers via Telegram while leaving a persistent backdoor behind.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/8e65aa140b4ea708998af9db66b37499d8e534e84f40875a29eb2dcb5fcc1af1/mp4/media.mp4</video:content_loc>
<video:duration>43</video:duration>
<video:publication_date>2026-07-21T13:07:42.936Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.458Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/printers-spit-ransom-notes-after-bitlocker-lock-c224c597</loc>
<video:video>
<video:title>Printers Spit Ransom Notes After BitLocker Lock</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/c224c597.jpg</video:thumbnail_loc>
<video:description>Two real incidents in Colombia and Mexico show attackers using built-in Windows BitLocker to lock company drives, then printing ransom notes from office printers to pressure victims to pay. One case started from an exposed Remote Desktop (RDP) service; the other began from a misconfigured Microsoft SQL Server where credentials were found in code posted on GitHub. The attackers demanded relatively small ransoms (example: $3,000) and used “reputation” language in their messages to convince victims they would provide recovery help after payment.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/601ab8841391608ba25eef4863912440fc1a2abf75a0332d30258011dd863d8e/mp4/media.mp4</video:content_loc>
<video:duration>48</video:duration>
<video:publication_date>2026-07-21T13:07:42.936Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.507Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-fbi-agents-target-scam-victims-in-dms-64d0ebf6</loc>
<video:video>
<video:title>Fake “FBI Agents” Target Scam Victims in DMs</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/64d0ebf6.jpg</video:thumbnail_loc>
<video:description>The FBI’s IC3 warns that scammers are impersonating FBI/IC3 staff on social media and messaging apps, especially targeting people who have already been scammed. The criminals use convincing branding (logos, fake reviews) and may even use AI-generated deepfake videos to pressure victims into clicking a link or paying money to “recover” funds.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/217c07ad481d8e3e5e603cd26acaf8b7cf99da40be14714c1105a44d294b1b8e/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-21T12:10:24.124Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.336Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-fbi-ic3-help-scams-hit-victims-twice-a2d7b32f</loc>
<video:video>
<video:title>Fake FBI ‘IC3 Help’ Scams Hit Victims Twice</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/a2d7b32f.jpg</video:thumbnail_loc>
<video:description>The FBI warns scammers are impersonating FBI/IC3 staff and re-targeting people who already lost money to fraud. The scammers use emails, phone calls, social media messages, and even AI-generated videos to push victims to spoofed IC3 websites or to hand over more personal and financial information, or send more money.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/e8fb37f2911ffae1fc0aa0f7125d77f57bc36800137b9882c6a3f49732fdc4ea/mp4/media.mp4</video:content_loc>
<video:duration>50</video:duration>
<video:publication_date>2026-07-21T12:10:24.124Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.116Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-support-techs-breach-windtre-retail-stores-aefdb439</loc>
<video:video>
<video:title>Fake Support Techs Breach WINDTRE Retail Stores</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/aefdb439.jpg</video:thumbnail_loc>
<video:description>Italy’s privacy regulator fined telecom operator WINDTRE after two breaches where attackers used simple social engineering, not hacking tools. The attackers posed as support technicians and talked retail store staff into giving them system access, leading to theft of customer data. The case shows how frontline staff and store procedures can be the weakest link, even in large telecoms.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/8557643ffdd9e4b2d93839be70dc79a91285312f25731858ea747921af941930/mp4/media.mp4</video:content_loc>
<video:duration>42</video:duration>
<video:publication_date>2026-07-21T12:10:24.124Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.338Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/deepfake-fbi-videos-push-victims-to-fake-ic3-sites-52c72531</loc>
<video:video>
<video:title>Deepfake FBI Videos Push Victims to Fake IC3 Sites</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/52c72531.jpg</video:thumbnail_loc>
<video:description>The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI agent and sent a link to “update” their IC3 complaint, which either delivers malicious code or harvests additional details.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/9c4cc56b224f122b4384b55b679c68a1cfc89047e38534dbbc17dd14464f250b/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-21T12:10:24.124Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.305Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-fbi-ic3-agents-re-scam-past-victims-0700927d</loc>
<video:video>
<video:title>Fake FBI “IC3” Agents Re-Scam Past Victims</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/0700927d.jpg</video:thumbnail_loc>
<video:description>Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The schemes use messages on social platforms (then move victims to Telegram) and AI-generated “deepfake” videos that push victims to a lookalike IC3 website to harvest personal and financial details.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/a93b464b8a879b2f8e2a7426de302c8b0caaa2a9aa0113db93da7bc3a9b25884/mp4/media.mp4</video:content_loc>
<video:duration>57</video:duration>
<video:publication_date>2026-07-21T11:05:15.930Z</video:publication_date>
</video:video>
<lastmod>2026-07-31T00:48:56.277Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-captcha-tricks-users-into-running-malware-4d5e3dfd</loc>
<video:video>
<video:title>Fake CAPTCHA Tricks Users Into Running Malware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/4d5e3dfd.jpg</video:thumbnail_loc>
<video:description>Ukraine’s CERT-UA says Russian-linked attackers are using fake CAPTCHA prompts on hacked websites to trick people into running malicious PowerShell commands themselves. The page pretends it’s verifying the visitor is human, but instead guides them to open the Windows Run box and execute attacker-provided code, leading to reconnaissance and potential further compromise.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/35c16d2db7d00d95f1231a028fae5514f95f81afb47bfcb28be889b2558e9e9e/mp4/media.mp4</video:content_loc>
<video:duration>51</video:duration>
<video:publication_date>2026-07-21T10:03:42.277Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.236Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-web3-job-interviews-push-clickfix-malware-189f217f</loc>
<video:video>
<video:title>Fake Web3 Job Interviews Push “ClickFix” Malware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/189f217f.jpg</video:thumbnail_loc>
<video:description>Researchers say a North Korea-aligned group is targeting Web3 and crypto professionals with fake recruiter outreach and “mandatory” online skill tests. During the test, victims are tricked into copying a terminal command to “fix” a camera/mic error, which installs remote-access malware and can lead to credential and crypto-wallet theft.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/81a0c839169152a18cfdf0206bb75b0f043b5c5b37b93c00f37aa2d02f3f971a/mp4/media.mp4</video:content_loc>
<video:duration>51</video:duration>
<video:publication_date>2026-07-21T10:03:42.277Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.386Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-docusign-flow-tricks-users-into-rmm-installs-088483f7</loc>
<video:video>
<video:title>Fake DocuSign Flow Tricks Users Into RMM Installs</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/088483f7.jpg</video:thumbnail_loc>
<video:description>Researchers found a DocuSign lookalike phishing workflow that guides people through a realistic “document viewing” experience and then convinces them to download legitimate remote access tools. Instead of classic malware, the attackers install trusted IT administration software (RMM) to keep long-term access on both Windows and macOS while blending into normal IT activity.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/9879b457f05128677e1f8986418dbb93ea6a8c897b496855c385fd12d5dfedbd/mp4/media.mp4</video:content_loc>
<video:duration>46</video:duration>
<video:publication_date>2026-07-20T23:03:01.524Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.241Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/odyssey-piracy-traps-fake-alerts-and-exe-movies-a564208a</loc>
<video:video>
<video:title>Odyssey Piracy Traps: Fake Alerts and EXE “Movies”</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/a564208a.jpg</video:thumbnail_loc>
<video:description>Researchers reported that scammers set up cloned piracy sites within hours of Christopher Nolan’s The Odyssey release to trick people looking for pirated copies. The scams used a fake “Browser Issue Detected” pop-up to push users into malicious ad redirects and a Windows .exe file disguised as a movie download using a VLC-looking icon. The attacks rely on people clicking or running files, not on exploiting software flaws.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/eed17d4ccd9edc80ad08a87fae012e5f4fb35b950baef89f67fabebcb785b260/mp4/media.mp4</video:content_loc>
<video:duration>56</video:duration>
<video:publication_date>2026-07-20T20:05:51.516Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.398Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-mexico-id-site-pushed-webdav-malware-c7c7b6f1</loc>
<video:video>
<video:title>Fake Mexico ID Site Pushed WebDAV Malware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/c7c7b6f1.jpg</video:thumbnail_loc>
<video:description>Researchers found an exposed malware delivery server that contained phishing lures, testing notes, and live delivery logs for an active campaign. The live operation targeted Windows users in Mexico using a fake government ID (CURP) lookup site that triggered a WebDAV-based download flow and delivered an infostealer disguised as a PDF.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/d4ec987241856a4aab841fec4948c22eb684fe4753d9fb4aca5c6526e779cdfb/mp4/media.mp4</video:content_loc>
<video:duration>54</video:duration>
<video:publication_date>2026-07-20T19:04:32.090Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.229Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/odyssey-piracy-lures-push-fake-fixes-and-exe-movies-fb514f3c</loc>
<video:video>
<video:title>Odyssey Piracy Lures Push Fake Fixes and EXE “Movies”</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/fb514f3c.jpg</video:thumbnail_loc>
<video:description>Scammers quickly set up fake piracy pages for Christopher Nolan’s “The Odyssey” to trick people into either clicking a fake browser “Fix It Now” warning or downloading a “movie” that is actually a Windows program. The goal is to route victims through malicious advertising redirects or get them to run malware disguised as a video file. The scams rely on user action (clicking or running a file), not on software vulnerabilities.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/adfbc7de8d6b01b50665659724cb93981c9a509432baaef0d68e62addff02c05/mp4/media.mp4</video:content_loc>
<video:duration>45</video:duration>
<video:publication_date>2026-07-20T16:05:17.750Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.335Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/phishing-lab-used-webdav-to-push-fake-pdf-malware-b269a561</loc>
<video:video>
<video:title>Phishing Lab Used WebDAV to Push Fake “PDF” Malware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/b269a561.jpg</video:thumbnail_loc>
<video:description>Investigators found an exposed WebDAV server being used as a “malware delivery lab” with over 1,000 files for testing lures, filenames, and execution tricks. One active campaign impersonated Mexico’s CURP ID lookup site and delivered malware by opening a remote WebDAV folder via a Windows “search-ms” link, where a disguised .scr file appeared to be a PDF.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/744ead843469721719044c2c001cc2655bf4713a496546055be051d5d6028c84/mp4/media.mp4</video:content_loc>
<video:duration>70</video:duration>
<video:publication_date>2026-07-20T14:05:16.529Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:32:18.978Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/gst-themed-phishing-hits-india-with-remcos-rat-8081f65b</loc>
<video:video>
<video:title>GST-Themed Phishing Hits India With Remcos RAT</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/8081f65b.jpg</video:thumbnail_loc>
<video:description>A real phishing campaign targeted Indian businesses and individual taxpayers by impersonating government departments and sending emails that look like official GST tax notices. The goal was to trick recipients into opening convincing “refund/compliance” documents that install Remcos RAT to steal sensitive information.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/48dac28c8d717ba672ba99285d741d85c3efee0e383219497394dbaf10d0c38b/mp4/media.mp4</video:content_loc>
<video:duration>48</video:duration>
<video:publication_date>2026-07-20T14:05:16.529Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.282Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-tech-support-trick-led-to-windtre-breaches-c047598d</loc>
<video:video>
<video:title>Fake Tech Support Trick Led to WINDTRE Breaches</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/c047598d.jpg</video:thumbnail_loc>
<video:description>Italy’s privacy regulator fined telecom operator WINDTRE €1.7M after two breaches where attackers used social engineering, posing as support technicians, to persuade store staff to grant system access. The intruders then pulled personal data for over 365,000 customers, including payment-related details for more than 41,000 people.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/7c9d3c9cb2be0312453edc780199c6a824f3364b49e85e5112f98a0c19f006cf/mp4/media.mp4</video:content_loc>
<video:duration>45</video:duration>
<video:publication_date>2026-07-20T14:05:16.529Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.292Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-dev-alias-got-into-metamask-codebase-8e46d618</loc>
<video:video>
<video:title>Fake Dev Alias Got Into MetaMask Codebase</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/8e46d618.jpg</video:thumbnail_loc>
<video:description>A suspected North Korean IT worker allegedly got hired by Consensys (MetaMask’s parent) using an alias and contributed to MetaMask’s core wallet code for about a month. The person was later removed, and Consensys says an investigation found no stolen assets, no data theft, and no malicious code shipped. The case highlights a realistic “fake contractor / fake identity” hiring workflow that security teams can simulate and train against.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/cc5fad404bff6b92fb380c716a97f529802fed63c7bdebae304bad04bb778e51/mp4/media.mp4</video:content_loc>
<video:duration>57</video:duration>
<video:publication_date>2026-07-20T13:05:44.828Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.471Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/clickfix-lure-drives-new-acr-stealer-waves-72db2462</loc>
<video:video>
<video:title>ClickFix Lure Drives New ACR Stealer Waves</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/72db2462.jpg</video:thumbnail_loc>
<video:description>Microsoft reports a surge in real-world ACR Stealer activity where attackers use a “ClickFix” trick to get employees to run malicious commands that steal passwords, session tokens, and business documents. Two separate campaigns used different execution methods (WebDAV-hosted payloads vs. MSHTA/fileless execution) to make related incidents harder for defenders to connect.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/1be08cef398761ab8046a150f678a157a1fa642647dea9da20f2ecc895eae488/mp4/media.mp4</video:content_loc>
<video:duration>55</video:duration>
<video:publication_date>2026-07-20T12:06:53.660Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.629Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-game-downloads-push-amatera-password-stealer-bc4272fe</loc>
<video:video>
<video:title>Fake Game Downloads Push Amatera Password Stealer</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/bc4272fe.jpg</video:thumbnail_loc>
<video:description>Researchers found real-world campaigns that trick people into downloading fake games, mods, cracks, or software installers. The download looks legitimate and shows an installer screen, but it silently runs a multi-stage infection that ultimately installs the Amatera Stealer to steal passwords and other sensitive data. The lures are delivered through fake download sites, itch.io pages, and common file-sharing services.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/20c11ecf61796d74ee39283c0665368d11419b554839e83f02d1081d793532bc/mp4/media.mp4</video:content_loc>
<video:duration>56</video:duration>
<video:publication_date>2026-07-20T12:06:53.660Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.920Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/steam-game-lure-led-to-220k-crypto-theft-36df730c</loc>
<video:video>
<video:title>Steam Game Lure Led to $220K Crypto Theft</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/36df730c.jpg</video:thumbnail_loc>
<video:description>Federal investigators arrested a Florida man accused of helping push malware disguised as video games, which infected about 8,000 devices and enabled theft from cryptocurrency wallets. The games were promoted through social platforms and direct messages aimed at people believed to hold significant crypto, convincing them to install the infected titles.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/d3a7fa8564282f4552c84359974edf9e8c0cfecb8b44fc333075f76784850573/mp4/media.mp4</video:content_loc>
<video:duration>44</video:duration>
<video:publication_date>2026-07-20T12:06:53.660Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.564Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-job-tests-hide-malware-in-svg-flag-images-ccf53b32</loc>
<video:video>
<video:title>Fake Job Tests Hide Malware in SVG “Flag” Images</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/ccf53b32.jpg</video:thumbnail_loc>
<video:description>Researchers report a real North Korea–linked social engineering campaign where attackers posed as recruiters and sent fake job offers and coding assessments. The “test” materials hid a multi-stage malware payload inside SVG flag images, aiming to steal browser logins and crypto wallet data and install remote access tools. The campaign notably targeted a security firm’s community Slack with a bogus e-commerce developer role.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/44f4f9055fa132daed864fc4147d373247063f717439ed6285757c989f8069ed/mp4/media.mp4</video:content_loc>
<video:duration>58</video:duration>
<video:publication_date>2026-07-20T12:06:53.660Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:32:18.963Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-captcha-tricks-ukrainians-into-running-malware-3eace55f</loc>
<video:video>
<video:title>Fake CAPTCHA Tricks Ukrainians Into Running Malware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/3eace55f.jpg</video:thumbnail_loc>
<video:description>CERT-UA reports a Sandworm-linked group (UAC-0145) is using fake CAPTCHA checks on compromised websites to persuade Ukrainian visitors to run PowerShell commands that infect their own computers. The campaign also includes Android attacks where victims are sent trojan APK “security tools” via messaging apps, resulting in a backdoor that steals files, contacts, and location.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c6aceb2e3c06cb97d47907269402b93a5953683878dd11972c737384c5404922/mp4/media.mp4</video:content_loc>
<video:duration>59</video:duration>
<video:publication_date>2026-07-19T15:02:44.776Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.218Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/microsoft-device-code-phish-steals-tokens-not-passwords-6de1b7af</loc>
<video:video>
<video:title>Microsoft Device Code Phish Steals Tokens, Not Passwords</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/6de1b7af.jpg</video:thumbnail_loc>
<video:description>This article demonstrates a phishing method that tricks users into signing in on Microsoft’s real login page and approving access for an attacker-controlled app. Instead of stealing a password, the attacker captures a valid Microsoft access token that can be used to access Microsoft 365 data like email, OneDrive, SharePoint, and Teams.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c20a90ef9d9a0751a21d3a955bdbea3ad9350e689a3732d94846855242d684e0/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-18T10:03:42.170Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.245Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/text-salting-phish-bypasses-ai-email-filters-a9959219</loc>
<video:video>
<video:title>Text-Salting Phish Bypasses AI Email Filters</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/a9959219.jpg</video:thumbnail_loc>
<video:description>Barracuda reports seeing more than one million retail-themed phishing emails since April that use “text salting,” where attackers hide large amounts of harmless text inside the message to trick automated email security tools. The victim sees a normal-looking urgent lure (like expiring rewards points), while hidden HTML/CSS content changes how some detection engines score the email. The campaign also uses authenticated-looking sending infrastructure (e.g., DKIM) and multiple hiding techniques to improve delivery.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/42422cf7d5917e148f1811feeb8d806d4d155f288ca35b93fd5c9fd49c83ce85/mp4/media.mp4</video:content_loc>
<video:duration>51</video:duration>
<video:publication_date>2026-07-17T23:02:37.915Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.868Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-screenshot-zip-led-to-digicert-cert-theft-96d9ebe2</loc>
<video:video>
<video:title>Fake Screenshot ZIP Led to DigiCert Cert Theft</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/96d9ebe2.jpg</video:thumbnail_loc>
<video:description>Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a customer support chat. The attackers then abused DigiCert’s support portal features to intercept EV code-signing certificate “initialization codes,” enabling them to obtain and misuse customer certificates to sign malware and evade detection.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/288ba2c68a5851697fee9d578d89d75f833786693574758b677189a617610a0a/mp4/media.mp4</video:content_loc>
<video:duration>56</video:duration>
<video:publication_date>2026-07-17T18:04:21.615Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.592Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-github-repos-and-trojan-apps-steal-data-f931cfaf</loc>
<video:video>
<video:title>Fake GitHub Repos and Trojan Apps Steal Data</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/f931cfaf.jpg</video:thumbnail_loc>
<video:description>Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to trick people into installing credential and crypto-stealing malware, and another uses hundreds of imposter GitHub repositories to lure developers into downloading an infostealer. Both attacks rely on victims trusting familiar brands or “free” tools and then clicking a download and running what looks like legitimate software.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/a70be53a9879d50a1c3eb81c64d5212af76a6811a4def646f2ec552886a8a426/mp4/media.mp4</video:content_loc>
<video:duration>67</video:duration>
<video:publication_date>2026-07-17T17:05:04.836Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.254Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-slack-job-posts-push-trojan-coding-tests-7dc9878f</loc>
<video:video>
<video:title>Fake Slack Job Posts Push Trojan Coding Tests</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/7dc9878f.jpg</video:thumbnail_loc>
<video:description>North Korea–linked actors used fake developer job offers inside a Slack community to trick targets into running a “coding assessment” project. The repository looked legitimate but secretly assembled malware hidden in SVG flag images, leading to credential, file, crypto-wallet, and clipboard theft plus remote access.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/5e14e98824cd7220ea62e0205d6f03d51686f5449b070ebabfadd7d9db452849/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-17T16:07:55.532Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.532Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/clickfix-lure-pushes-trojan-zoom-webex-installers-4026f10f</loc>
<video:video>
<video:title>ClickFix Lure Pushes Trojan Zoom/WebEx Installers</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/4026f10f.jpg</video:thumbnail_loc>
<video:description>Cisco Talos reports a real, financially motivated campaign by a Russian-speaking group (UAT-11795) targeting organizations in the US and Europe. The attackers use a “ClickFix” social-engineering trick to get victims to run a command, which leads to downloading trojanized installers for trusted tools (like Zoom/WebEx) and then stealing credentials and cryptocurrency. The campaign also uses stealthy, memory-only tooling and unusual command-and-control methods to maintain access.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/3741f02567a90c37b26ac0dff79828819221ffa7411fc5bcedd96df133099df4/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-17T16:07:55.532Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.906Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/ttf-trap-uses-fake-font-files-to-drop-malware-589d4850</loc>
<video:video>
<video:title>“TTF Trap” Uses Fake Font Files to Drop Malware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/589d4850.jpg</video:thumbnail_loc>
<video:description>FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive that ultimately runs malware on Windows. The trick is a file ending in .ttf (TrueType font) that is actually a malicious script executed by a bundled interpreter, leading to credential-stealing and remote-access malware.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/5e39bf9477123695168690ec063dca94bb6d2b922c9d5d94fcc686bab6f287ae/mp4/media.mp4</video:content_loc>
<video:duration>50</video:duration>
<video:publication_date>2026-07-17T14:04:08.602Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.015Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/facetime-spoof-calls-steal-codes-and-money-02ecfed3</loc>
<video:video>
<video:title>FaceTime Spoof Calls Steal Codes and Money</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/02ecfed3.jpg</video:thumbnail_loc>
<video:description>Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords, security codes, and financial details. The callers use personal information to sound legitimate, then create urgency to keep victims from hanging up and verifying the request independently. Some scams also try to get victims to disable protections like 2FA or Stolen Device Protection to make account takeover easier.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/ceb0f659c6767b037f49e4e4174e03d6011ec68db845337f5f8246192ba06a50/mp4/media.mp4</video:content_loc>
<video:duration>45</video:duration>
<video:publication_date>2026-07-17T13:03:06.175Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.323Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/clickfix-trick-spreads-acr-stealer-via-paste-run-d7cd26a8</loc>
<video:video>
<video:title>ClickFix Trick Spreads ACR Stealer via Paste-Run</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/d7cd26a8.jpg</video:thumbnail_loc>
<video:description>Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR (Amatera) Stealer. The malware steals saved browser passwords, live session tokens, and Microsoft 365/OneDrive/SharePoint files, meaning password changes alone may not be enough and token revocation is required.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/67140e2d1a34ffa798c3af7bbebb49510a6ec6bb6d1f2aa18d928fa305cd4d4c/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-17T11:03:53.542Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:32:18.988Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/spear-phishing-rtf-hits-bangladesh-defense-targets-cf5dd33c</loc>
<video:video>
<video:title>Spear-Phishing RTF Hits Bangladesh Defense Targets</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/cf5dd33c.jpg</video:thumbnail_loc>
<video:description>Researchers reported a targeted espionage operation against Bangladesh’s military and defense organizations using spear‑phishing emails with a booby‑trapped RTF document. When opened, the file pulls malicious content remotely and installs an implant that persists on the device while quietly sending data back to the attackers over encrypted web traffic.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/578ad31bc32dc3d1ed23d9222c8ebc39874f661c4bf4d2f459b7b106bdd73cfd/mp4/media.mp4</video:content_loc>
<video:duration>42</video:duration>
<video:publication_date>2026-07-17T11:03:53.542Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.486Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-zoom-webex-installers-drop-starland-rat-9ffe4f37</loc>
<video:video>
<video:title>Fake Zoom/Webex Installers Drop Starland RAT</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/9ffe4f37.jpg</video:thumbnail_loc>
<video:description>Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools like Zoom, Webex, and MobaXterm. Victims are socially engineered via a “ClickFix” style trick into running a command that silently downloads and runs a malicious file, while the installer appears to work normally. The result is remote access and credential/crypto wallet theft, with resilient command-and-control that can fall back to blockchain-hosted instructions.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/074e5787cc1a3cf34e862e8ab3772ec35ad66cf078af731a7c676a67bf770da0/mp4/media.mp4</video:content_loc>
<video:duration>61</video:duration>
<video:publication_date>2026-07-17T10:04:34.175Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.964Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-ai-tool-ads-drop-mediaarena-persistence-5f1128c5</loc>
<video:video>
<video:title>Fake “AI Tool” Ads Drop MediaArena Persistence</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/5f1128c5.jpg</video:thumbnail_loc>
<video:description>A malvertising campaign is luring users with fake free “AI tool” downloads (recipe/meal-planning apps) delivered via paid search ads. Even when Microsoft Defender later quarantines the detected file, the installer can already have created persistence (Startup shortcut and HKCU Uninstall key), meaning the device may still be compromised. The article provides specific domains, hosting infrastructure, and the exact persistence checks defenders should perform.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/29805cff221a8915e5faa64927e5c0e9caa05e5f34123c32c221e06c0f0524e6/mp4/media.mp4</video:content_loc>
<video:duration>63</video:duration>
<video:publication_date>2026-07-17T10:04:34.175Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.531Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-font-attachment-used-in-global-phishing-8dc5d24b</loc>
<video:video>
<video:title>Fake Font Attachment Used in Global Phishing</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/8dc5d24b.jpg</video:thumbnail_loc>
<video:description>Researchers report a real, ongoing phishing campaign where attackers impersonate well-known companies and send business or payment-themed emails that trick recipients into opening a compressed attachment. Inside is heavily obfuscated script and a file disguised as a TrueType font (.ttf) that ultimately installs credential-stealing malware and remote-access tools on Windows systems.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/2a715e3f6a24c3a8063ff81fb3263f28a6a1dd4c7e13ebc9ff6dc648b9150823/mp4/media.mp4</video:content_loc>
<video:duration>51</video:duration>
<video:publication_date>2026-07-17T09:03:22.641Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.051Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/one-click-google-sso-takeover-via-device-code-bug-ccd576bd</loc>
<video:video>
<video:title>One-Click Google SSO Takeover via Device-Code Bug</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/ccd576bd.jpg</video:thumbnail_loc>
<video:description>A researcher found two bugs in Google’s “device code” sign-in flow that could let an attacker get a valid Google sign-in token for a victim by getting them to open a single crafted link. In the most dangerous version, the victim sees no consent screen and no extra 2FA prompt, yet the attacker can log into third-party sites that use “Sign in with Google.” Google fixed the issue after an initial “won’t fix” response and later paid a bug bounty.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/9fbcdc51aaec7be146eebc198c974eab8e4327d2db22143ad94b5375f69c7831/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-17T08:05:02.345Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.233Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/ai-vishing-works-because-scripts-persuade-b002162f</loc>
<video:video>
<video:title>AI Vishing Works Because Scripts Persuade</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/b002162f.jpg</video:thumbnail_loc>
<video:description>Researchers tested AI and human voice scam calls and found people comply mainly because the caller’s script is persuasive, not because the voice sounds perfectly human. Even when listeners correctly suspect the voice is synthetic, many still continue the conversation and may hand over sensitive information. The article argues security training should focus on verification procedures (callbacks, identity checks) rather than trying to “hear” deepfakes.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/24d0c20349abbcb986081f6e8b92086180d692326ecc11d2c661a03c7c055bec/mp4/media.mp4</video:content_loc>
<video:duration>39</video:duration>
<video:publication_date>2026-07-17T06:02:35.787Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.925Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/linkedin-chat-leads-to-screen-share-scam-calls-2ae31624</loc>
<video:video>
<video:title>LinkedIn Chat Leads to Screen-Share Scam Calls</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/2ae31624.jpg</video:thumbnail_loc>
<video:description>The article describes multiple real-world suspected social engineering attempts that begin with friendly LinkedIn messages and quickly move to an off-platform meeting invite (often via Calendly). On the video call, the attacker refuses to turn on camera, uses a personal email address, asks the target to share their screen, and ultimately appears to aim at sending fraudulent links that push the victim to install software or run code.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/4fc2e986c2fb743715c17b9d638a4ec7c7491e41ec53fc3da73d6a4b0012605c/mp4/media.mp4</video:content_loc>
<video:duration>41</video:duration>
<video:publication_date>2026-07-17T02:03:47.860Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.038Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/clickfix-lures-spread-acr-stealer-in-two-chains-88097730</loc>
<video:video>
<video:title>ClickFix Lures Spread ACR Stealer in Two Chains</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/88097730.jpg</video:thumbnail_loc>
<video:description>Microsoft observed real-world ACR Stealer campaigns where users are tricked by “ClickFix” prompts into running attacker-provided commands. Two main intrusion chains were seen: one loads a DLL from a remote WebDAV share and later uses Python-based loaders, and the other uses MSHTA and an image-based (steganography) payload to run mostly in memory. The end goal in both is stealing browser credentials, session tokens, and sensitive documents for later misuse.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/514a90318f168e3a70a3a851a31635b71da5226f12102934a538e6afef286a41/mp4/media.mp4</video:content_loc>
<video:duration>50</video:duration>
<video:publication_date>2026-07-17T00:03:57.033Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.144Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/trojanized-zoom-webex-installers-spread-starland-rat-90c5e8b9</loc>
<video:video>
<video:title>Trojanized Zoom/Webex Installers Spread Starland RAT</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/90c5e8b9.jpg</video:thumbnail_loc>
<video:description>Cisco Talos reports a real, ongoing campaign where a Russian-speaking criminal group tricks people into installing trojanized versions of popular software (like Webex, Zoom, and MobaXterm). Once a victim runs the fake installer, a custom remote-access tool (“Starland RAT”) is installed and used to deliver additional malware aimed at stealing valuable credentials and cryptocurrency assets.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/d6f44d7633f8594005ada01fd6a0a690527563f08bd88e81e11787441a04eea7/mp4/media.mp4</video:content_loc>
<video:duration>50</video:duration>
<video:publication_date>2026-07-16T19:04:49.611Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:27:48.475Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-advisors-clickfix-and-chrome-sync-spying-3c8f9fdd</loc>
<video:video>
<video:title>Fake Advisors, ClickFix, and Chrome Sync Spying</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/3c8f9fdd.jpg</video:thumbnail_loc>
<video:description>This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned into training simulations: getting a user to run an installer/script, persuading a victim to “invest” more money over time, and quietly enabling browser syncing to exfiltrate private browsing data.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/2606fa04893c490c7d123d775306e9cca38ad2a6c0a77396a1be0eb4497aca1b/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-16T16:05:15.594Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.966Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/clicklock-tricks-mac-users-into-pasting-malware-8bcb76a5</loc>
<video:video>
<video:title>ClickLock Tricks Mac Users Into Pasting Malware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/8bcb76a5.jpg</video:thumbnail_loc>
<video:description>Researchers documented a real macOS data-stealing campaign that relies on social engineering instead of software bugs. Victims are sent to a fake “verification” page that tells them to copy and paste a command into Terminal, which silently installs a stealer and then pressures them to enter their Mac password to complete the theft.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c4c1776d8f2da7ba93f20911e023a5e6d1d631ca2609036431a34dbfa474990a/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-16T16:05:15.594Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.263Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/phishers-hide-lua-malware-as-ttf-font-436c40f8</loc>
<video:video>
<video:title>Phishers Hide Lua Malware as “.TTF Font”</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/436c40f8.jpg</video:thumbnail_loc>
<video:description>A real, ongoing phishing campaign is tricking recipients into opening malicious archives that appear to contain harmless TrueType font files (.ttf) but actually hide a Lua-based loader. Once executed, the loader uses stealthy, mostly in-memory techniques to install remote access trojans and credential-stealing malware such as Remcos and Agent Tesla.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/aff102b4d8bfbdf3c8d5d06e166031bfa506d8179b5d48d135344efa1f517037/mp4/media.mp4</video:content_loc>
<video:duration>50</video:duration>
<video:publication_date>2026-07-16T15:07:24.331Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.116Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/sandworm-uses-fake-captchas-to-spread-malware-4c8de262</loc>
<video:video>
<video:title>Sandworm Uses Fake CAPTCHAs to Spread Malware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/4c8de262.jpg</video:thumbnail_loc>
<video:description>Ukraine’s CERT says the Russia-linked Sandworm group is tricking targets into infecting their own PCs using compromised websites that display fake CAPTCHA checks. Victims are instructed to copy and paste a PowerShell command, which downloads malware and can lead to deeper compromise. CERT also warns Sandworm continues using messaging apps (including Signal) to socially engineer targets into installing bogus “security” software.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c32e91e017ecd747be6249919cf99b9c95d27555a2a6a08760dec4c0dd18976d/mp4/media.mp4</video:content_loc>
<video:duration>44</video:duration>
<video:publication_date>2026-07-16T14:06:10.324Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.461Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/clicklock-macos-stealer-forces-password-via-kill-loops-37373ce0</loc>
<video:video>
<video:title>ClickLock macOS Stealer Forces Password via Kill Loops</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/37373ce0.jpg</video:thumbnail_loc>
<video:description>Researchers observed a real macOS information-stealing campaign that tricks victims into pasting a command into Terminal from a “ClickFix” web page. After running, the malware shows a fake macOS password prompt and can repeatedly crash key apps (Finder/Dock/browsers) for hours or days to pressure the victim into entering their password. Stolen data can include browser passwords/cookies, crypto wallet data, and a persistent backdoor, with exfiltration sent via Telegram bots.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/ab0a6b5e7b8e2a8402b590a51ca67253308e73cb39d8b0c3c688f78b847b214b/mp4/media.mp4</video:content_loc>
<video:duration>64</video:duration>
<video:publication_date>2026-07-16T14:06:10.324Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.389Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/telepuz-spreads-via-clickfix-fix-web-lures-9a667808</loc>
<video:video>
<video:title>TELEPUZ Spreads via ClickFix “Fix” Web Lures</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/9a667808.jpg</video:thumbnail_loc>
<video:description>Researchers report a real, active malware operation where compromised websites use “ClickFix” style prompts to trick people into manually pasting and running malicious commands. The result is a multi-stage infection that downloads additional payloads and ultimately runs TELEPUZ, which can steal browser data and execute commands remotely. The lure looks like a normal “browser error/software update/CAPTCHA fix,” but it’s actually instructions to run attacker-provided commands.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c3414ceed325e5bcd13ea655f0e1ecc9e3aa540db5cbe0cf3554053e372739fe/mp4/media.mp4</video:content_loc>
<video:duration>48</video:duration>
<video:publication_date>2026-07-16T14:06:10.324Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.529Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/planted-text-tricks-ai-agents-into-bad-clicks-37241843</loc>
<video:video>
<video:title>Planted Text Tricks AI Agents Into Bad Clicks</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/37241843.jpg</video:thumbnail_loc>
<video:description>Researchers demonstrated a new “agent data injection” technique where attackers plant content (like a review or GitHub comment) that an AI agent mistakenly treats as trusted system data. In tests, this caused web-browsing agents to click the wrong buttons (e.g., “Buy Now”) and coding agents to run attacker-supplied commands after the user approves what looks like a normal step.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/99740faf4245db1f41579e75f7e5ec6a5c792b574fdf0bb48e970254933ffec5/mp4/media.mp4</video:content_loc>
<video:duration>53</video:duration>
<video:publication_date>2026-07-16T13:07:14.885Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.533Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/hijacked-gov-br-sites-used-as-malware-lures-513abd6b</loc>
<video:video>
<video:title>Hijacked .gov.br Sites Used as Malware Lures</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/513abd6b.jpg</video:thumbnail_loc>
<video:description>Researchers reported an active PhantomEnigma campaign where attackers hijacked 20+ Brazilian government websites and used them as trusted stepping-stones to deliver malware. The lure used official-looking police-themed documents (sometimes with QR codes) and emails that could pass common email authentication checks, making the messages look legitimate. The goal was to get victims to click through trusted .gov.br infrastructure to a malicious installer that ultimately deployed a backdoor and additional payloads.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c748c4cd743c74b914e14b0d74e453a027d5d12e6b95d281266d86878dc51cf6/mp4/media.mp4</video:content_loc>
<video:duration>52</video:duration>
<video:publication_date>2026-07-16T13:07:14.885Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.592Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/clicklock-tricks-mac-users-into-running-malware-1d520645</loc>
<video:video>
<video:title>ClickLock Tricks Mac Users Into Running Malware</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/1d520645.jpg</video:thumbnail_loc>
<video:description>A macOS info-stealing malware called ClickLock Stealer uses a fake “Cloudflare verification” page to trick users into copying and running a Terminal command. It then steals browser, crypto wallet, and Keychain data and sends it to attackers via a Telegram bot, while killing processes to hide warnings and force password entry.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/e9150136ec709ff66737eaa96581d7647727895f5f9a1869f559171fae382886/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-16T13:07:14.885Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.854Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/scattered-spider-duped-tfl-helpdesk-to-reset-2fa-844d5611</loc>
<video:video>
<video:title>Scattered Spider Duped TfL Helpdesk to Reset 2FA</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/844d5611.jpg</video:thumbnail_loc>
<video:description>UK authorities said two Scattered Spider members accessed Transport for London (TfL) by buying partial employee credentials and then tricking TfL’s helpdesk into resetting an employee password and 2FA. The attackers kept access for several days, escalated privileges, and ultimately exposed customer data and disrupted online services, costing TfL about £29 million to remediate.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c27a54b9fa7f24bc695cc1b3b7a00d136edfcb55b47c40f8d977b83350b2d50d/mp4/media.mp4</video:content_loc>
<video:duration>50</video:duration>
<video:publication_date>2026-07-16T13:07:14.885Z</video:publication_date>
</video:video>
<lastmod>2026-07-16T13:07:14.885Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/pink-vishing-tricks-staff-into-entra-passkeys-e4ab5f92</loc>
<video:video>
<video:title>Pink Vishing Tricks Staff Into Entra Passkeys</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/e4ab5f92.jpg</video:thumbnail_loc>
<video:description>The “Pink” data extortion group is running a real-world voice phishing campaign targeting employees in Microsoft 365 / Entra ID environments. Callers impersonate the internal IT helpdesk and direct staff to realistic lookalike login sites timed to Microsoft’s passkey-enrollment prompts, enabling attackers to register their own passkey and gain persistent access. A notable tell is a fake “recovery” page showing crypto-style BIP-39 seed phrases, which do not belong in Microsoft Entra flows.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c6c2e0ca53df818384a4ba8f047b21653d2559c1c2019fa3ffc11efea2e1040a/mp4/media.mp4</video:content_loc>
<video:duration>48</video:duration>
<video:publication_date>2026-07-16T12:07:42.328Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.210Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/okobot-tricks-crypto-users-into-running-commands-0949e553</loc>
<video:video>
<video:title>OkoBot Tricks Crypto Users Into Running Commands</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/0949e553.jpg</video:thumbnail_loc>
<video:description>Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that trick them into running PowerShell commands, and via GitHub repos posing as legitimate software downloads. The malware then steals wallet files/credentials and can show a fake hardware-wallet recovery page to capture seed phrases.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/ede4f7d83a8600ef77fee952c37264386cdf64fc2cadc62e98c866e58443694d/mp4/media.mp4</video:content_loc>
<video:duration>45</video:duration>
<video:publication_date>2026-07-16T12:07:42.328Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.526Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-fifa-ticket-sites-steal-cards-and-otps-07bb9f96</loc>
<video:video>
<video:title>Fake FIFA Ticket Sites Steal Cards and OTPs</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/07bb9f96.jpg</video:thumbnail_loc>
<video:description>Researchers and the FBI warn that criminals are luring World Cup fans to convincing fake FIFA ticket websites, often via social media ads and shared links. The scam steals payment details in real time during checkout, including card data and one-time passcodes (OTPs), while victims believe they are buying legitimate tickets.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/f5bb0f99e0c73dd3f9bf797924c5606a940734843acc6b0eec5e5c2118f98a0a/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-16T12:07:42.328Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.499Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/tfl-help-desk-tricked-hackers-got-keys-88b590eb</loc>
<video:video>
<video:title>TfL Help Desk Tricked, Hackers Got “Keys”</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/88b590eb.jpg</video:thumbnail_loc>
<video:description>Two teen hackers linked to the Scattered Spider collective gained deep access to Transport for London (TfL) by tricking the TfL help desk into resetting remote-access authentication onto a device the attackers controlled. TfL said the intrusion could have caused catastrophic disruption, forced 27,000 staff to reset passwords, and led to theft of data from about 7 million people.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/2956e40245076a52874d731e3adc6fa0d0f413dadb438f705d575f404bed83a7/mp4/media.mp4</video:content_loc>
<video:duration>42</video:duration>
<video:publication_date>2026-07-16T11:04:51.625Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:35:38.116Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/clickfix-lures-push-trojanized-apps-starland-rat-28207cdc</loc>
<video:video>
<video:title>ClickFix Lures Push Trojanized Apps, Starland RAT</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/28207cdc.jpg</video:thumbnail_loc>
<video:description>Cisco Talos reports a real, financially motivated campaign where victims are tricked via a “ClickFix” style lure into running a command that downloads a weaponized HTA file. That HTA then installs trojanized versions of legitimate software (e.g., WebEx/Zoom/MobaXterm) that deploy Starland RAT and other payloads to steal credentials and crypto wallets and keep remote access.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c6bd7f5d924c4dae32d9754e386c913aa31bd93389c4f9fc79dba089810b18b0/mp4/media.mp4</video:content_loc>
<video:duration>55</video:duration>
<video:publication_date>2026-07-16T11:04:51.625Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.996Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/linkedin-exec-impersonation-beat-mgm-help-desk-d066a2e5</loc>
<video:video>
<video:title>LinkedIn Exec Impersonation Beat MGM Help Desk</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/d066a2e5.jpg</video:thumbnail_loc>
<video:description>The article highlights how attackers can quickly build convincing executive “profiles” from public information and use them to manipulate employees. It cites the 2023 MGM Resorts incident where attackers allegedly used an executive’s LinkedIn details to impersonate them in a help desk phone call and obtain credentials within minutes. The piece recommends ongoing monitoring and cleanup of executive and family digital footprints to reduce social-engineering risk.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/0ed81c374c2361f1543be4678078e9c714f70c4ce98eaacd59ce767803347956/mp4/media.mp4</video:content_loc>
<video:duration>47</video:duration>
<video:publication_date>2026-07-16T10:04:28.427Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.036Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/700-agent-call-center-scam-stole-100m-month-9c2d3279</loc>
<video:video>
<video:title>700-Agent Call Center Scam Stole €100M/Month</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/9c2d3279.jpg</video:thumbnail_loc>
<video:description>Police say an organized crime group ran around 20 fraudulent call centers with over 700 staff who posed as “financial advisers” to trick people into fake investments. Victims were contacted by phone and online for weeks or months, shown fake profits on fraudulent trading platforms, then pressured to deposit larger amounts, often in cryptocurrency. Authorities also warned that “recovery companies” offering to get money back may be part of the same scam network.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/e7e76cd975b2041ffb708b7be6441df2cfcc7e4cbc56ab48326acce334dcf231/mp4/media.mp4</video:content_loc>
<video:duration>46</video:duration>
<video:publication_date>2026-07-16T09:03:28.125Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.328Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-qantas-it-help-vishing-led-to-data-theft-a3e5795b</loc>
<video:video>
<video:title>Fake “Qantas IT Help” Vishing Led to Data Theft</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/a3e5795b.jpg</video:thumbnail_loc>
<video:description>Qantas avoided a formal Australian privacy regulator investigation after a June 2025 breach that impacted about 5.12 million people. The breach started with a phone-based social engineering call where an attacker posed as “Qantas IT help” and convinced a call-centre agent to connect a customized data extraction tool to Qantas’ CRM, enabling mass data export.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/4e8ca6e4b25bcc02ea604ffad9c0bf0b0d2bb8b7d360d21323f7a0da8865a493/mp4/media.mp4</video:content_loc>
<video:duration>48</video:duration>
<video:publication_date>2026-07-16T07:04:07.301Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.313Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-qantas-it-help-call-led-to-5-7m-leak-68827617</loc>
<video:video>
<video:title>Fake “Qantas IT Help” Call Led to 5.7M Leak</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/68827617.jpg</video:thumbnail_loc>
<video:description>Australia’s Privacy Commissioner said Qantas’ 2025 breach was triggered by a tech-support phone scam targeting a contact center agent. The caller posed as “Qantas IT help” and coached the agent to take steps in the CRM that actually connected it to a data-extraction tool, enabling theft of customer records affecting about 5.7 million people.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/cf043a8ed1f1a40b96d230d6c5b568953f8eea115979d2400a5cd18aad8de41b/mp4/media.mp4</video:content_loc>
<video:duration>51</video:duration>
<video:publication_date>2026-07-16T07:04:07.301Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.199Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/finance-phishing-that-looks-like-routine-work-83d01498</loc>
<video:video>
<video:title>Finance Phishing That Looks Like Routine Work</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/83d01498.jpg</video:thumbnail_loc>
<video:description>Cofense reports that attackers target finance teams with phishing emails designed to look like normal invoices, contracts, and payment notices, not urgent “act now” scams. These “boringly normal” messages blend into everyday finance workflows, which can lead staff to click links or open attachments before verifying the sender. The goal is often credential theft via embedded malicious URLs.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/2d949f8f4f753903e50f47f647c4680cbd404db2005d6ba679ed235a2ac45050/mp4/media.mp4</video:content_loc>
<video:duration>45</video:duration>
<video:publication_date>2026-07-16T04:04:29.991Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.259Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/asyncapi-npm-packages-poisoned-via-malicious-pr-f0dd9780</loc>
<video:video>
<video:title>AsyncAPI npm Packages Poisoned via Malicious PR</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/f0dd9780.jpg</video:thumbnail_loc>
<video:description>Attackers compromised the @asyncapi npm organization by abusing a misconfigured GitHub Actions workflow, then republished multiple AsyncAPI-related packages with a hidden loader. The malware ran automatically when the poisoned packages were imported (not during install), pulled a second-stage payload from IPFS, and connected to command-and-control infrastructure. This incident could expose developer machines and CI/CD environments that built or ran code during the brief exposure window.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/533e4e2238316610d25d0c215b046f34991a99d1c481c8a1812eee02179d6677/mp4/media.mp4</video:content_loc>
<video:duration>62</video:duration>
<video:publication_date>2026-07-16T03:04:02.039Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.999Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-mac-crash-reporter-steals-passwords-2dbfce8e</loc>
<video:video>
<video:title>Fake Mac Crash Reporter Steals Passwords</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/2dbfce8e.jpg</video:thumbnail_loc>
<video:description>Researchers warn about a new macOS infostealer called “CrashStealer” that pretends to be Apple’s Crash Reporter. It uses a legitimate-looking installer and a fake macOS-style password prompt to trick users into unlocking Keychain, then steals credentials and crypto wallet data.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/7e9ff9606fa7fd860137ff5212c96b649f451891ae30091dab5bec0b88d00fd0/mp4/media.mp4</video:content_loc>
<video:duration>51</video:duration>
<video:publication_date>2026-07-15T18:05:11.985Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.894Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-celine-dion-tickets-trap-fans-on-facebook-570769c3</loc>
<video:video>
<video:title>Fake Céline Dion Tickets Trap Fans on Facebook</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/570769c3.jpg</video:thumbnail_loc>
<video:description>Scammers are approaching Céline Dion fans on Facebook and steering them into paying for “tickets” outside official resale channels. Victims may even receive a real-looking Ticketmaster transfer link, but scammers send the same ticket to multiple buyers so only the first person scanned at the venue gets in. A parallel campaign uses Ticketmaster/AXS lookalike websites (including Shopify-based stores) to collect payments and personal details.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/2c537267f0088f9b008c8ee09857cd0c6959c6ea8121440f0a6d0522d73ad8fd/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-15T17:05:07.268Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.846Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/okobot-fakes-wallet-app-screens-to-steal-seed-phrases-2ec1086b</loc>
<video:video>
<video:title>OkoBot Fakes Wallet App Screens to Steal Seed Phrases</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/2ec1086b.jpg</video:thumbnail_loc>
<video:description>A real malware campaign called OkoBot is infecting Windows PCs and then showing a fake “recovery phrase” prompt inside legitimate Ledger and Trezor desktop apps. Victims are tricked into typing their wallet seed phrase into a malicious page that looks like it came from the trusted app, allowing attackers to steal cryptocurrency. Kaspersky reports hundreds of victims across more than 25 countries, with notable concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/ccb7d6e3a278fa38f166a129377b346a0162b1276669c63a91bd7a9217dd1815/mp4/media.mp4</video:content_loc>
<video:duration>70</video:duration>
<video:publication_date>2026-07-15T17:05:07.268Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.270Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/routine-finance-emails-now-power-phishing-4cfb6fc7</loc>
<video:video>
<video:title>Routine Finance Emails Now Power Phishing</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/4cfb6fc7.jpg</video:thumbnail_loc>
<video:description>Cofense reports real finance-themed phishing campaigns are shifting from obvious “urgent” language to routine, process-sounding subject lines that blend into daily finance workflows. These emails commonly mimic invoices, remittance advice, procurement requests, and contract/e-sign steps to trick recipients into opening attachments or clicking credential-theft links. The shift makes both employees and email security tools less likely to spot the messages because they look like normal business operations.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/4cbff8d775d8af7ecb4387941f195151f3329333a03eed08cc2f83ae0723b26d/mp4/media.mp4</video:content_loc>
<video:duration>54</video:duration>
<video:publication_date>2026-07-15T16:05:51.035Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.950Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-ecards-trick-users-into-installing-rmm-0af18ece</loc>
<video:video>
<video:title>Fake eCards Trick Users Into Installing RMM</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/0af18ece.jpg</video:thumbnail_loc>
<video:description>A long-running phishing campaign used fake electronic greeting cards and seasonal themes to lure people into installing legitimate remote-management software that gave attackers control. Victims were sent to a page impersonating a greeting-card service that auto-downloaded Windows or macOS installers, then prompted users to approve the install. Because the tools were commercially signed and legitimate, they were harder for typical defenses to flag as malware.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/223256483c42d400c7490b847251becec01705c37f3d575ec176089aa38c1b26/mp4/media.mp4</video:content_loc>
<video:duration>56</video:duration>
<video:publication_date>2026-07-15T15:05:19.607Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.385Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/claude-desktop-link-bug-auto-ran-hidden-prompts-a3062faa</loc>
<video:video>
<video:title>Claude Desktop Link Bug Auto-Ran Hidden Prompts</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/a3062faa.jpg</video:thumbnail_loc>
<video:description>Researchers found a flaw in Anthropic’s Claude Desktop where clicking a specially crafted link could automatically submit an attacker’s prompt without the user reviewing it. Attackers could hide harmful instructions in a long, collapsed message to trick users into thinking it was harmless. In some setups, the prompt could even trigger data uploads or plant malicious code changes via connected tools until Anthropic fixed the behavior.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/bf1fbcbeb2194c826b46a375bd3f6ba7f53c0d520269b668fc86937bbea79938/mp4/media.mp4</video:content_loc>
<video:duration>57</video:duration>
<video:publication_date>2026-07-15T13:06:13.238Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.284Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-ssms-on-github-spreads-crypto-stealing-okobot-425b58d6</loc>
<video:video>
<video:title>Fake SSMS on GitHub Spreads Crypto-Stealing OkoBot</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/425b58d6.jpg</video:thumbnail_loc>
<video:description>Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake “SQL Server Management Studio” installer from GitHub. Once a victim runs it, the attackers set up remote access and quietly install browser-stealing tools designed to capture crypto wallet and browser data.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/e0bf6f8e109ffcf8124f4c22f511955a3c6b553539e4dd3ccfe850f6f19bcea9/mp4/media.mp4</video:content_loc>
<video:duration>58</video:duration>
<video:publication_date>2026-07-15T11:05:53.108Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.407Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/clickfix-lures-trick-users-into-pasting-commands-e8b8b23b</loc>
<video:video>
<video:title>ClickFix Lures Trick Users Into Pasting Commands</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/e8b8b23b.jpg</video:thumbnail_loc>
<video:description>ClickFix is a fast-growing social engineering tactic that gets people to run malware themselves by pasting a command into Windows Run or macOS Terminal. Attackers use fake CAPTCHA pages, browser/OS update prompts, meeting errors, and IT/vendor impersonation to push the workflow, often delivered via phishing, malvertising, or compromised websites. Researchers warn it’s become “industrialized” through Malware-as-a-Service kits that let low-skill criminals launch high-volume campaigns.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c7b84a12a3becbc6b2dd6743cc8d324d4857207d074245d1edbd87b12c06564d/mp4/media.mp4</video:content_loc>
<video:duration>48</video:duration>
<video:publication_date>2026-07-15T11:05:53.108Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.933Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/deepfake-cfo-call-triggers-25m-transfer-scam-7a28f6af</loc>
<video:video>
<video:title>Deepfake CFO Call Triggers $25M Transfer Scam</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/7a28f6af.jpg</video:thumbnail_loc>
<video:description>A worker received an email that appeared to be from the company’s CFO requesting a confidential transaction. When the employee tried to verify, attackers escalated to a video call using AI deepfakes of the CFO and other colleagues, convincing the employee to make 15 transfers totaling about $25 million. The piece argues AI-driven personalization is making phishing far more effective and harder to spot by “looking for mistakes.”</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c1c43abba5445632fe88866bfef6f78655ec35630f24e5e73d0a395dbf73ae33/mp4/media.mp4</video:content_loc>
<video:duration>63</video:duration>
<video:publication_date>2026-07-15T08:05:15.054Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:32:18.986Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/slack-claude-text-may-trigger-risky-agent-actions-b605f413</loc>
<video:video>
<video:title>Slack “@Claude” Text May Trigger Risky Agent Actions</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/b605f413.jpg</video:thumbnail_loc>
<video:description>Security researchers at Tego AI report that Anthropic’s Claude Tag integration for Slack may respond to plain text containing “@Claude,” even when it is not a real Slack mention. They demonstrated that messages delivered via bots or webhooks could be treated as instructions, potentially causing Claude Tag to pull internal data into Slack and even delete connected internal resources. Anthropic disputes this behavior under default configuration, but the report highlights a realistic workflow to simulate and defend against.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/11d4e5dba544a71d502f3087a072aeea3ef9410e5f9405f663fee4fd901220de/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-14T17:04:48.410Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.896Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/doxbin-admin-jailed-for-encouraging-swatting-6fe5733f</loc>
<video:video>
<video:title>Doxbin Admin Jailed for Encouraging Swatting</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/6fe5733f.jpg</video:thumbnail_loc>
<video:description>A Welsh Doxbin administrator, Callum Dare, was jailed after investigators linked him to encouraging and assisting others to place dangerous “swatting” hoax calls in the UK, US, and Canada. The hoaxes included false reports of bombs, hostages, shootings, and explosives, designed to trigger armed police responses and public evacuations.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/95696393bf19f9b7eb28c8acccf2b06ba3e39f2a12047c1482de53f70b26637d/mp4/media.mp4</video:content_loc>
<video:duration>54</video:duration>
<video:publication_date>2026-07-14T17:04:48.410Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.419Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-apple-support-facetime-calls-drain-accounts-23448b3a</loc>
<video:video>
<video:title>Fake “Apple Support” FaceTime Calls Drain Accounts</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/23448b3a.jpg</video:thumbnail_loc>
<video:description>Apple warns that scammers are placing unsolicited FaceTime calls and sending urgent-looking messages that appear to come from “Apple Support” or a bank. The callers use pressure and fear (fraud alerts, refunds, account issues) to trick victims into sharing passwords, banking details, or one-time passcodes, and sometimes to install remote-access software.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/652f6c4e20a971532219d45fa5e93b7ab021e9e63a9881f73d12772005f11fde/mp4/media.mp4</video:content_loc>
<video:duration>48</video:duration>
<video:publication_date>2026-07-14T12:04:30.311Z</video:publication_date>
</video:video>
<lastmod>2026-07-31T00:49:27.459Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/forg365-makes-m365-takeovers-phishing-for-dummies-4abfc5d4</loc>
<video:video>
<video:title>Forg365 Makes M365 Takeovers “Phishing for Dummies”</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/4abfc5d4.jpg</video:thumbnail_loc>
<video:description>Researchers documented a real phishing-as-a-service platform called Forg365, sold via Telegram, that helps attackers take over Microsoft 365 accounts using convincing document-themed lures. It uses device-code phishing and adversary-in-the-middle methods to get access, and adds tooling (including a cookie-refresh browser extension) that can let attackers keep access even after a password reset.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/d738b0d598edde80777e4e690bcd7c4c5afd551d329b1cf6bd603cc3d2f5bea2/mp4/media.mp4</video:content_loc>
<video:duration>53</video:duration>
<video:publication_date>2026-07-14T10:03:42.334Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.625Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-student-proxy-sites-turn-browsers-into-ddos-bots-7eacb300</loc>
<video:video>
<video:title>Fake Student Proxy Sites Turn Browsers Into DDoS Bots</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/7eacb300.jpg</video:thumbnail_loc>
<video:description>Researchers found 148 npm packages that weren’t meant for developers to install, instead they hosted “student proxy” websites that looked like tutoring pages. Students visiting the sites to bypass school filters unknowingly ran code in their browser that could be switched on to flood targets (including a nursing school domain) and overload proxy infrastructure via mass WebSocket connections.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/da8146f97b5d9def29f51577fa2bb47fd8b5e656b965d584013daebcfa816af7/mp4/media.mp4</video:content_loc>
<video:duration>59</video:duration>
<video:publication_date>2026-07-14T09:04:45.945Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.906Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/russian-coms-vishing-platform-busted-dc1f4252</loc>
<video:video>
<video:title>“Russian Coms” Vishing Platform Busted</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/dc1f4252.jpg</video:thumbnail_loc>
<video:description>UK authorities charged five people linked to “Russian Coms,” a vishing (phone-scam) platform used to make large volumes of spoofed calls that appeared to come from trusted organizations. Victims were told their accounts were under fraud and were pressured to move money to “safe” accounts controlled by criminals.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/48cb624b6a41a7d4f5fb4acb6c53309c41d6f5154b6e91cccbac37a2888599bd/mp4/media.mp4</video:content_loc>
<video:duration>46</video:duration>
<video:publication_date>2026-07-14T09:04:45.945Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.881Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/crashstealer-hides-as-apple-crash-reporter-8255d543</loc>
<video:video>
<video:title>CrashStealer Hides as Apple Crash Reporter</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/8255d543.jpg</video:thumbnail_loc>
<video:description>Researchers found a real macOS infostealer campaign that tricks users into running a signed, Apple-notarized app (“Werkbit Setup”) that passes Gatekeeper and then quietly installs a credential-stealing payload. The malware impersonates Apple’s Crash Reporter, prompts users for their Mac password and broad permissions, steals browser and wallet data, then encrypts what it steals before sending it to attacker servers.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/40dade8fd9895f5906de6d2b701b7e5871c5b62c4bdb5637229a40a5cc431155/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-14T09:04:45.945Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.057Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/shinyhunters-style-vishing-tricks-staff-into-oauth-access-cfe644fb</loc>
<video:video>
<video:title>ShinyHunters-Style Vishing Tricks Staff Into OAuth Access</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/cfe644fb.jpg</video:thumbnail_loc>
<video:description>Microsoft reports attackers linked to ShinyHunters spent a year getting into corporate Salesforce data without exploiting Salesforce bugs. One key method was vishing calls that persuaded employees to approve a malicious “connected app,” giving attackers ongoing API access that looked like normal activity. Microsoft also describes token theft from trusted vendors and misconfigured guest access as additional paths used in real incidents.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/af963b6121b4a28655755281d44f7df45376ba34a4505207879d7b8a89d769e5/mp4/media.mp4</video:content_loc>
<video:duration>48</video:duration>
<video:publication_date>2026-07-14T07:03:31.314Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.404Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/apt-lures-shift-to-jobs-code-reviews-cloud-apps-8419a241</loc>
<video:video>
<video:title>APT Lures Shift to Jobs, Code Reviews, Cloud Apps</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/8419a241.jpg</video:thumbnail_loc>
<video:description>This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and breach/security notifications) to trick targets into clicking links, opening files, or installing malicious packages. It highlights how attackers increasingly abuse trusted platforms (GitHub, Google Docs/Drive, npm, LinkedIn, Telegram, and cloud storage) to deliver malware or steal accounts and tokens.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/3f5bf31c6cb05eea044ba5fe4cb46e23aacbbf25a9340a55563643fa11cc3820/mp4/media.mp4</video:content_loc>
<video:duration>56</video:duration>
<video:publication_date>2026-07-14T06:03:29.834Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.916Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/crashstealer-fakes-macos-crash-reporter-to-steal-passwords-4ea9c004</loc>
<video:video>
<video:title>CrashStealer Fakes macOS Crash Reporter to Steal Passwords</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/4ea9c004.jpg</video:thumbnail_loc>
<video:description>Researchers found a macOS infostealer that disguises itself as a legitimate collaboration app and then impersonates Apple’s crash-reporting tools. After the user installs it, the malware shows a convincing macOS password prompt to trick the user into entering their password, then steals keychain and browser credentials.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/75e12b8564dc7eaafc8b0c60c24e69c4b0b6e97664ac5e24cc2b3a7ba44c4033/mp4/media.mp4</video:content_loc>
<video:duration>48</video:duration>
<video:publication_date>2026-07-14T03:03:46.850Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.059Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/shinyhunters-linked-vishing-tricks-users-into-oauth-consent-8650d963</loc>
<video:video>
<video:title>ShinyHunters-Linked Vishing Tricks Users into OAuth Consent</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/8650d963.jpg</video:thumbnail_loc>
<video:description>Microsoft reports multiple real-world campaigns (mid-2025 to mid-2026) where attackers used voice phishing and trusted SaaS integrations to gain access to customer Salesforce environments. The key pattern is abusing OAuth “connected apps” and trusted integrations so access looks legitimate, enabling quiet, large-scale CRM data theft and long-term persistence.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/cfefac5f430f20f237c486a15e3ac294359f102ea0a5d7ae64bbfde70603bde7/mp4/media.mp4</video:content_loc>
<video:duration>47</video:duration>
<video:publication_date>2026-07-14T00:05:04.272Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.997Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/crashstealer-tricks-users-to-bypass-macos-gatekeeper-eca7de34</loc>
<video:video>
<video:title>CrashStealer Tricks Users to Bypass macOS Gatekeeper</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/eca7de34.jpg</video:thumbnail_loc>
<video:description>Researchers found a macOS info‑stealing malware, CrashStealer, delivered through a signed and Apple‑notarized installer so it looks legitimate and passes Gatekeeper checks. The installer instructs users to manually right‑click and choose “Open,” then silently downloads additional payloads and prompts for the user’s login password to unlock the keychain and steal credentials and wallet data.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/ef3db810c88127efb2421efe9874bf833826bcfc8ecd81354ab2317162edde3e/mp4/media.mp4</video:content_loc>
<video:duration>47</video:duration>
<video:publication_date>2026-07-13T18:04:20.812Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.638Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/open-server-exposes-m365-phishing-playbooks-ae5110fa</loc>
<video:video>
<video:title>Open Server Exposes M365 Phishing Playbooks</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/ae5110fa.jpg</video:thumbnail_loc>
<video:description>Researchers found a misconfigured server exposing the tools and logs of multiple active phishing operators targeting corporate Microsoft 365 accounts. The exposed data included phishing configurations, stolen credentials/tokens, and tooling for maintaining access, including a campaign abusing Microsoft’s OAuth Device Code Flow to keep refreshing access in the background.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/925e428aa86180f00e2731ce86ef010dac24877857c05432e1f9bffeadab3f47/mp4/media.mp4</video:content_loc>
<video:duration>69</video:duration>
<video:publication_date>2026-07-13T16:06:54.748Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.961Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/booking-themed-spam-delivers-node-js-backdoor-ad3e33cb</loc>
<video:video>
<video:title>Booking-Themed Spam Delivers Node.js Backdoor</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/ad3e33cb.jpg</video:thumbnail_loc>
<video:description>The recap describes a real spam campaign targeting hospitality workers with booking-related messages. Victims are lured to click a Google-hosted link that leads to a malicious ZIP file; opening it triggers a hidden PowerShell command that installs a Node.js-based backdoor.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/9e1bf82f907d8a134f37123d3b95af1837e22df42bb3647bb15c49deccf506bf/mp4/media.mp4</video:content_loc>
<video:duration>46</video:duration>
<video:publication_date>2026-07-13T16:06:54.748Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.427Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/forg365-phishing-kit-steals-microsoft-365-sessions-cc098c93</loc>
<video:video>
<video:title>Forg365 Phishing Kit Steals Microsoft 365 Sessions</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/cc098c93.jpg</video:thumbnail_loc>
<video:description>Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that can bypass normal login protections by stealing sessions or abusing Microsoft device codes. The service is sold via Telegram and uses legitimate email infrastructure (e.g., Amazon SES and SendGrid) plus anti-bot checks to blend in and avoid detection, then supports follow-on mailbox monitoring and message drafting.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c62ca2fe97420640a0c903cfa807e693265f8fb4f151f76616baa9b63fc8ddd0/mp4/media.mp4</video:content_loc>
<video:duration>43</video:duration>
<video:publication_date>2026-07-13T14:05:44.679Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:32:18.984Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/ghostcommit-hides-prompt-injection-in-pr-images-10bc6ccd</loc>
<video:video>
<video:title>Ghostcommit Hides Prompt Injection in PR Images</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/10bc6ccd.jpg</video:thumbnail_loc>
<video:description>Researchers demonstrated “Ghostcommit,” a method to trick AI code-review assistants using hidden instructions embedded inside an image added in a pull request. The AI agent may later follow those hidden instructions to read sensitive files and leak secrets back into source code, even when the pull request looks normal to human reviewers. The risk depends heavily on the coding tool (“harness”) and its permissions, not just the AI model.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c4689981b17fb88cf13b792551036e8ee7ac5f5eea299532113f02737ddc3e07/mp4/media.mp4</video:content_loc>
<video:duration>51</video:duration>
<video:publication_date>2026-07-13T14:05:44.679Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:27:48.544Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/student-job-scam-uses-school-email-google-forms-0f49a620</loc>
<video:video>
<video:title>Student Job Scam Uses School Email + Google Forms</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/0f49a620.jpg</video:thumbnail_loc>
<video:description>Researchers reported a real student employment phishing campaign that used compromised school email accounts to send messages that passed common email authenticity checks. The lure pushed students to a Google Form to collect sensitive personal and banking details, consistent with money-mule recruitment and account takeover prep.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/6e0c69b01577169265aff65cbe72f30c04820b4709cfec56cddcbdd002b8ccdd/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-13T14:05:44.679Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.414Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-it-caller-tied-to-odido-phishing-breach-45bf9ae7</loc>
<video:video>
<video:title>Fake IT Caller Tied to Odido Phishing Breach</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/45bf9ae7.jpg</video:thumbnail_loc>
<video:description>Dutch police say the February 2026 breach at Dutch telecom Odido, where data on more than six million customers was stolen, was enabled by social engineering and phishing. Investigators cite a Dutch-speaking caller who allegedly posed as an Odido IT employee shortly before the intrusion, after which phishing led to the compromise and data theft.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/cec70d2b708339602483895e4c2815e843a78cf1e97f5a3762bb827a4229f9af/mp4/media.mp4</video:content_loc>
<video:duration>49</video:duration>
<video:publication_date>2026-07-13T10:04:33.658Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.982Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/three-live-m365-phish-ops-exposed-by-open-server-b23bf6e4</loc>
<video:video>
<video:title>Three Live M365 Phish Ops Exposed by Open Server</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/b23bf6e4.jpg</video:thumbnail_loc>
<video:description>Researchers found a live Microsoft 365 phishing server accidentally left open with directory listing enabled, exposing phishing configs, stolen credential logs, and tooling. The exposed artifacts revealed three separate phishing operations using Evilginx-style adversary-in-the-middle logins and Microsoft device-code sign-ins to capture tokens and keep access even with MFA. The write-up includes clear workflows that can be used to build realistic security-awareness simulations (fake Microsoft login proxy and device-code “Authenticator” lure).</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/e11c5fe74180cada149341d51b712ea7893b0a1cbf1715d2596435910d51c0da/mp4/media.mp4</video:content_loc>
<video:duration>60</video:duration>
<video:publication_date>2026-07-13T09:03:48.090Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.263Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-project-proposal-emails-drop-keylogger-b9e61c41</loc>
<video:video>
<video:title>Fake Project Proposal Emails Drop Keylogger</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/b9e61c41.jpg</video:thumbnail_loc>
<video:description>AhnLab reports an active phishing campaign using emails disguised as project proposals to trick recipients into opening a compressed attachment. The attachment contains JavaScript malware that launches PowerShell and loads SnakeKeylogger, which steals browser data, system details, and keystrokes and sends it out via SMTP or Telegram.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/616f42e96bf61c0a4d235422989cb21d7d0eed865b5e2eadd5ac47014a46c613/mp4/media.mp4</video:content_loc>
<video:duration>53</video:duration>
<video:publication_date>2026-07-13T07:03:49.849Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.869Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/phishing-payment-confirmation-drops-remcos-rat-6173f5ad</loc>
<video:video>
<video:title>Phishing “Payment Confirmation” Drops Remcos RAT</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/6173f5ad.jpg</video:thumbnail_loc>
<video:description>AhnLab reports a real phishing campaign where emails masquerade as payment confirmation notices to trick employees into opening a malicious Excel (XLS) attachment. The spreadsheet shows a legitimate-looking payment slip as a decoy, but it silently pulls malware from attacker servers and ultimately installs Remcos RAT for remote control and data theft.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/c2034c58f62f5360c8091cc36ab02331ed4e28c27a635033fe96cdb41bf3623a/mp4/media.mp4</video:content_loc>
<video:duration>59</video:duration>
<video:publication_date>2026-07-13T07:03:49.849Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.567Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/extortion-crew-fakes-passkey-setup-by-phone-19192493</loc>
<video:video>
<video:title>Extortion Crew Fakes Passkey Setup by Phone</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/19192493.jpg</video:thumbnail_loc>
<video:description>A weekly roundup highlighted a real social-engineering campaign where the “Pink” extortion group calls employees and pretends to be IT to push a fake Microsoft Entra passkey enrollment. The goal is to trick the victim into helping the attacker gain access to the victim’s Microsoft 365 account while the victim stays occupied with the staged “setup.”</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/d48e33793069cabf1e6c4b5c8cee013a30853e1bbddab279a82afeb357b45ef5/mp4/media.mp4</video:content_loc>
<video:duration>48</video:duration>
<video:publication_date>2026-07-12T08:04:49.232Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:29.396Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://www.miragesecurity.ai/attacks/article/fake-portal-updates-hit-pakistan-police-systems-5a78286d</loc>
<video:video>
<video:title>Fake Portal Updates Hit Pakistan Police Systems</video:title>
<video:thumbnail_loc>https://d8kdvmcak9dxaujo.public.blob.vercel-storage.com/threatwatcher/posters/5a78286d.jpg</video:thumbnail_loc>
<video:description>Researchers report a real multi-year espionage campaign targeting Pakistani law enforcement systems, including a public-facing complaints portal used by both police staff and citizens. Attackers planted malware disguised as a legitimate portal update and also used law-enforcement-themed decoy documents to trick targets into running malicious files.</video:description>
<video:content_loc>https://media.miragesecurity.ai/media-e8abba8a-0fad-47de-bb31-3cb3b6a2802f/videos/930bfc4189b45f28e4bbbb29f4033aceec07a19d027f9d273be900f686933d85/mp4/media.mp4</video:content_loc>
<video:duration>48</video:duration>
<video:publication_date>2026-07-11T19:03:49.181Z</video:publication_date>
</video:video>
<lastmod>2026-07-30T23:20:28.910Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
</urlset>
