search
phishing
Trends
- 1Australian bank criticised over poorly formatted customer email●Bank email today... * Shows up in Gmail inbox as coming from "statements" * No sender icon * No header image * No sign o
A customer has raised concerns about a suspicious-looking email from an Australian bank. The message arrived in Gmail from the generic name "statements", with no sender icon, header image or sign-off, and was described as an unprofessional wall of text with poor punctuation. Notably, it was sent from the domain xyz.bank rather than the bank's website domain xyzbank.com.au, prompting questions about why the bank uses a different address and whether the email is legitimate.
- 2Fake Facebook login page spreading via Blogspot flagged as phishing●Possible Phishing 🎣 on: ⚠️hxxp[:]//facebookloginsignub[.]blogspot[.]com 🧬 Analysis at: https:// urldna.io/scan/6abf80c63
Security researchers are warning about a phishing site hosted on a Blogspot address that imitates the Facebook login page to steal credentials. A link-analysis service has published a scan of the malicious URL, and cybersecurity accounts are circulating the warning with the address deliberately defanged to prevent accidental clicks. Users are advised to avoid entering Facebook login details on unfamiliar domains.
- 3Users report wave of odd spam text messages●Getting some pretty weird spam text messages lately. (We park in our garage.) # tech
A user in the technology community reports receiving strange spam text messages recently, noting that a message about parking in their garage was irrelevant to them since they park in a garage. The remark suggests the spam texts use generic or mismatched content, a common sign of mass phishing or scam campaigns, and the observation is resonating with others who have seen similar junk texts.
- 4Phishing warning issued over malicious Google Slides link●Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vQtDdGcOPhuzmqinl-zROR_QZmTkYHXgVq8TEmqX
Cybersecurity researchers are flagging a phishing campaign hosted through a Google Slides sharing link. The URL has been defanged and submitted to a URL analysis service for inspection, and warnings are circulating among infosec accounts urging users not to open such links. The case highlights how attackers continue to abuse trusted Google-hosted pages to deliver scams.
- 5Fake Binance phishing site flagged by security researchers●Possible Phishing 🎣 on: ⚠️hxxps[:]//bitbaink[.]web[.]app 🧬 Analysis at: https:// urldna.io/scan/6abf3a5b3b77500 006cd65a
Security researchers have flagged a suspected phishing site impersonating the Binance cryptocurrency exchange, hosted at a lookalike domain on a web app platform. The malicious link was deliberately defanged to prevent accidental clicks, and a public URL analysis has been shared so other defenders can inspect the site's infrastructure and indicators of compromise.
- 6Chinese hackers posed as ex-US official to target AI experts●Chinese hackers impersonated ex-US official to steal emails from AI experts https:// fed.brid.gy/r/https://www.rapp ler.
Chinese hackers impersonated a former US official in phishing attacks aimed at stealing emails from artificial intelligence experts, according to a Rappler report. The operation suggests foreign espionage efforts are increasingly focused on the AI field, targeting specialists to gain access to sensitive research and communications. The report has drawn attention to ongoing concerns about cyber espionage between the US and China.
- 7Security researchers flag possible phishing site on Blogspot●Possible Phishing 🎣 on: ⚠️hxxps[:]//nxreionnrryytddee[.]blogspot[.]com/ 🧬 Analysis at: https:// urldna.io/scan/6abedfac3
Cybersecurity observers are warning about a suspected phishing page hosted on a Blogspot address, sharing the link in deliberately defanged form to prevent accidental clicks. A link analysis scan has been published so others can inspect the site's infrastructure, redirects and content. The random-looking domain name is typical of throwaway pages used in phishing campaigns.
- 8US Department of War promotes 'Brilliant at the Basics' for Cybersecurity Awareness Month▼Department of War Champions 'Brilliant at the Basics' for Cybersecurity Awareness Month
The US Department of War is marking Cybersecurity Awareness Month by promoting its 'Brilliant at the Basics' campaign, urging staff and the wider public to follow fundamental cyber hygiene such as strong passwords, phishing awareness and multi-factor authentication. The initiative highlights how basic defensive practices remain the department's core message against growing digital threats.
- 9Security researchers flag phishing campaign hosted on Google Drawings●Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/drawings/d/1mhjJHXA_69uh993SRr5QvxWSN1yYnDNolBbiror8T0c/edit 🧬 A
Cybersecurity analysts are warning about a suspected phishing link distributed through a Google Drawings document, with a scan published on the URLDNA analysis platform showing details of the flagged address. The warning circulated among infosec communities, with observers urged to treat unexpected Google Docs or Drawings links as potentially malicious and to verify such links before opening them.
- 10Security Researchers Flag New Phishing Site on Weebly●Possible Phishing 🎣 on: ⚠️hxxps[:]//djdkkdjbdhshaww[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abf56913b7750
Cybersecurity observers are warning about a suspected phishing website hosted on a free Weebly subdomain with a randomly generated address. The site has been defanged to prevent accidental visits, and a public URL analysis has been shared so others can inspect its infrastructure. The warning circulates among infosec communities, who regularly report such scam pages to help blocklists and alert potential victims.
- 11North Dakota launches 'Stay Cyber SMART' campaign for Cybersecurity Awareness Month▼North Dakota Information Technology Encourages North Dakotans to ‘Stay Cyber SMART’ During Cybersecurity Awareness Month
North Dakota Information Technology is urging residents to 'Stay Cyber SMART' throughout Cybersecurity Awareness Month, a national campaign held every October. The state agency is promoting basic cyber hygiene practices to help residents protect themselves from online threats such as phishing and fraud.
- 12Security Researchers Flag Possible Phishing on Google Docs●Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vQ5HCwyHkL7fkCprouiofT1aYvBsFuTwTO8btKBZ
Cybersecurity researchers are warning of a possible phishing campaign using a Google Docs presentation link. A scan published on urldna.io is being circulated as an analysis of the suspicious address, which was shared in defanged form so readers cannot accidentally open it. Users are urged to treat unexpected Google Docs links with caution, as attackers commonly abuse legitimate hosting services to distribute malicious pages.
- 13TA419 phishing campaign targeted AI-policy specialists●Proofpoint says TA419 impersonated AI-policy figures and used a real-time Microsoft 365 phishing proxy against fewer tha
Security firm Proofpoint reports that the threat group TA419 impersonated prominent AI-policy figures and used a real-time Microsoft 365 phishing proxy to steal authenticated login sessions. The highly targeted campaign hit fewer than ten specialists. Researchers say it shows how attackers can capture live sessions, though successful compromises and government attribution remain unclear.
- 14Interpol warns AI is making cyberattacks faster and harder to detect●AI is making cyberattacks faster and harder to detect, Interpol warns. Here’s what companies should watch
Interpol has issued a warning that artificial intelligence is enabling cyberattacks that are faster, more automated and harder to detect, according to CNBC. The alert highlights what companies should watch for as criminals use AI tools to scale phishing, malware and other attacks. Businesses are being urged to reassess their cyber defenses as threats grow more sophisticated.
- 15Fake Google sign-in page flagged in phishing warning●Possible Phishing 🎣 on: ⚠️hxxp[:]//49[.]51[.]43[.]12/v3/signin/identifier?amp%3Bfollowup=hxxps%3A%2F%2Faccounts[.]google
Security researchers are warning about a phishing site that mimics the Google account sign-in page but is hosted on a raw IP address rather than a Google domain. The fake login page is designed to steal usernames, passwords and two-factor codes from people who click links in scam emails or messages. Users are advised to check that the address is accounts.google.com before entering credentials.
- 16Security researchers flag possible phishing site●Possible Phishing 🎣 on: ⚠️hxxps[:]//nmbghfgdrtuyjh[.]wpenginepowered[.]com 🧬 Analysis at: https:// urldna.io/scan/6abf25
Cybersecurity observers are warning about a possible phishing website hosted on a suspiciously named domain at nmbghfgdrtuyjh.wpenginepowered.com. The alert includes a link to a technical scan breaking down the site's characteristics, shared with hashtags covering phishing, scams and infosec. The warning advises people to avoid interacting with the address. The site's target and origin have not been disclosed in the alert.
- 17Fake DHL Australia site flagged as phishing●Possible Phishing 🎣 on: ⚠️hxxps[:]//dhlaustralia[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abe45083b77500 0
A fake DHL Australia website hosted on a free weebly.com domain is being flagged as a phishing attempt. Security researchers have published an automated analysis of the URL, warning users to avoid entering personal or payment details on sites imitating delivery companies. The alert serves as a reminder that fraudsters frequently impersonate DHL and other couriers, especially around busy shipping periods.
- 18Security researcher flags possible phishing site on web.app●Possible Phishing 🎣 on: ⚠️hxxps[:]//gnmznbck[.]web[.]app/ 🧬 Analysis at: https:// urldna.io/scan/6abeadcf3b77500 0046927
A cybersecurity analyst has warned of a suspected phishing site hosted at a randomly named subdomain of Google's web.app hosting platform. The site's address was shared in defused form so it cannot be clicked, along with a link to a URL analysis report detailing its characteristics. The warning serves as a reminder that attackers increasingly abuse free app-hosting services to deploy scam pages that look credible because of their legitimate underlying domains.
- 19Security researchers flag fake BT authentication phishing site●Possible Phishing 🎣 on: ⚠️hxxps[:]//bteesecureauthentication[.]weebly[.]com/ 🧬 Analysis at: https:// urldna.io/scan/6abe
Cybersecurity researchers are warning about a phishing website imitating BT's secure authentication page, hosted on a Weebly subdomain. The suspicious link has been defanged and shared with a link to a URL analysis scan so others can inspect it safely. Users are advised to avoid entering login credentials on such pages and to report suspicious BT-related messages.
- 20Security researchers flag phishing site hosted on pages.dev●Possible Phishing 🎣 on: ⚠️hxxps[:]//connect-captcha[.]pages[.]dev/?iduser=TkRnek9RPT0=&N3=o1ub8 🧬 Analysis at: https://
Cybersecurity analysts are warning about a phishing operation using a fake captcha page hosted on a Google pages.dev subdomain. The link carries an encoded user identifier in its address, a common trick used to track individual targets in credential-stealing campaigns. A public URL analysis of the malicious page has been shared so others can verify and block it.
- 21Security researchers flag phishing attempt hosted on Google Docs●Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vT3_JvqNI1WComFJRNVHBsLBF8UvvlBxqjlmVMD9
Cybersecurity analysts are warning of a suspected phishing campaign using a malicious Google Docs presentation link. The URL was shared in defanged form on an infosec forum, alongside a scan link for further analysis. Hosted Google Docs presentations are a common phishing vector because they appear legitimate and bypass some email filters. Users are advised to avoid opening unsolicited document links.
- 22English schools recovering faster from cyber incidents●England's schools are getting better at mopping up cyber incidents Two-thirds report immediate recovery, although teache
Two-thirds of schools in England now report recovering immediately from cyber incidents, suggesting improved resilience to attacks such as ransomware and phishing. Despite the progress, teachers remain divided over who bears responsibility for security and whose job security is at risk when breaches occur, with staff often left handling technical problems outside their expertise.
- 23Phishing warning issued for Godaddy-hosted scam site●Possible Phishing 🎣 on: ⚠️hxxps[:]//winning3000[.]godaddysites[.]com 🧬 Analysis at: https:// urldna.io/scan/6abe2f483b77
Security researchers are flagging winning3000.godaddysites.com as a suspected phishing site. The warning was shared on the infosec exchange platform, with a technical analysis of the domain published on urldna.io so others can inspect hosting details and verify the finding. The defanged link format is used to prevent accidental clicks. Users are advised to avoid the site and report similar scams.
- 24Security researchers flag football ladders phishing site●Possible Phishing 🎣 on: ⚠️hxxps[:]//footballladdup[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abe4b763b77500
Cybersecurity observers are warning about a suspected phishing website hosted on footballladdup.weebly.com, sharing a link analysis via the URL scanning service urlDNA. The defanged address is being circulated so users can inspect or block it safely. No specific victims or details of the scam have been disclosed, but the alert serves as a reminder to treat unfamiliar sports-themed sites cautiously.
- 25Microsoft: Attackers lead defenders in early AI race●Microsoft: Attackers lead defenders in early AI race https:// fawkes.rocks/2026/10/02/micros oft-attackers-lead-defender
Microsoft says malicious actors are currently ahead of defenders in the race to use artificial intelligence, according to a new assessment. The company warns that attackers are quicker to exploit AI tools for phishing, malware and reconnaissance, while defensive adoption lags behind. Security teams are now being urged to accelerate AI deployment before the gap widens further.
- 26Experts urge skepticism to avoid online scams●Be skeptical, avoid on-line scams. # cybersecurity https:// cromwell-intl.com/cybersecurit y/basics/09-scams.html?s=mb
Cybersecurity guidance circulating online urges internet users to be skeptical of unsolicited messages and offers in order to avoid falling victim to online scams. The reminder points readers to basic security advice on recognizing fraud attempts, a perennial concern as phishing and social engineering scams continue to target people through email, social media and messaging platforms.
- 27Chinese hackers impersonated ex-US official to target AI experts▼Chinese hackers impersonated ex-US official to steal emails from AI experts
Chinese-linked hackers posed as a former US official in a phishing scheme aimed at stealing emails from artificial intelligence specialists, Reuters reports. The operation used a spoofed identity to trick targets into handing over sensitive correspondence, highlighting growing concern over espionage campaigns targeting the AI sector and US expertise in the field.
- 28Chilean link flagged in new phishing warning●Possible Phishing 🎣 on: ⚠️hxxps[:]//1818[.]cl/jipoggh[.]html?eta= 🧬 Analysis at: https:// urldna.io/scan/6abe61483b77500
Cybersecurity observers are circulating a warning about a suspected phishing site hosted on the Chilean domain 1818.cl, urging people not to click the link. A technical analysis of the URL has been published on URLDNA so others can inspect its behaviour. Alerts like this help security researchers and defenders track active phishing campaigns and block the domains involved.
- 29A cyber awareness professional shares phishing training lessons●True stories of Cyber Awareness: Phishing I ran the company and customer wide cyber awareness programs where I developed
A security practitioner who ran company-wide and customer-facing cyber awareness programmes has described how the work was organised, with the first weeks of each month devoted to specific training sessions and the latter part of the month used for simulated phishing campaigns. The account offers a practical look at how organisations try to prepare staff to recognise phishing attempts before real attacks succeed.
- 30Security researchers flag phishing site hosted on GitHub Pages●Possible Phishing 🎣 on: ⚠️hxxps[:]//publicmanageraccountpages[.]github[.]io 🧬 Analysis at: https:// urldna.io/scan/6abe4
Cybersecurity analysts are warning about a suspected phishing site operating at publicmanageraccountpages.github.io, a malicious page abusing GitHub's hosting service. The alert was shared with a link to a detailed technical analysis on the URL scanning platform urlDNA, which breaks down the site's infrastructure and behavior. The defanged link format suggests a deliberate effort to prevent readers from accidentally visiting the fraudulent page.