This is a monthly newsletter I put together for an internal security awareness program. Feel Free to grab and use for your own program.
Fake “Calendly” Invites Used to Spoof Major Brands and Hijack Ad Manager Accounts
A phishing campaign is impersonating well-known brands by sending fake Calendly-style meeting invites designed to harvest credentials. The invites lead users to a fraudulent scheduling page, followed by a CAPTCHA and a spoofed login prompt. Attackers target users with access to Google Workspace, Facebook Business, and other advertising platforms, aiming to steal credentials or session tokens and take over ad-manager accounts.
Key Insights
Further Reading: BleepingComputer
Cybercrime Goes SaaS: Renting Tools, Access, and Infrastructure
Cybercriminals are increasingly operating like SaaS providers, offering subscription-based access to phishing kits, info-stealer data, malware loaders, OTP bots, and even compromised network access. This model lowers the technical barrier for newcomers, enabling less skilled attackers to run large-scale campaigns using ready-made tools and infrastructure.
Key Insights
Further Reading: BleepingComputer
California’s New Browser Privacy Requirement Could Have Nationwide Effects
California’s upcoming “Opt Me Out” requirement will mandate that web browsers include a built-in setting allowing users to automatically signal that their data should not be sold or shared. While designed for California residents, browser makers are expected to roll this out broadly, which could result in nationwide changes to how websites handle data privacy and tracking.
Key Insights
Further Reading: The Record
Storm-0900 Uses Fake Parking Tickets to Deliver Malware
A recent campaign by Storm-0900 sent fake parking-ticket notices and fabricated medical-alert messages to lure people into interacting with a malicious site. The attackers used a bogus CAPTCHA page as the trigger for delivering XWorm, a remote-access malware designed for credential theft, surveillance, and persistent access.
Key Insights
Further Reading: Cybersecurity News
Threat Actors Exploit Foxit PDF Reader to Deliver Malware
A recent campaign is targeting job-seekers with fake recruitment documents packaged in ZIP or RAR archives. The files impersonate a legitimate Foxit PDF Reader executable, but launching them triggers a multi-stage malware chain that ultimately installs ValleyRAT, enabling remote access and data theft.
Key Insights
Further Reading: Cybersecurity News
Phishing Attack Leveraging Microsoft Teams Notifications
A recent campaign abuses Microsoft Teams by adding users to fake Teams groups with names referencing invoices, payments, or account issues. The groups generate legitimate-looking Teams notification emails that prompt users to call a fraudulent support number. Because the messages originate from trusted Teams infrastructure, they are more likely to pass filtering and appear credible.
Key Insights
Further Reading: Cybersecurity News
PowerShell 5.1 Now Warns Before Executing Scripts from Web Content
Microsoft has updated Windows PowerShell 5.1 so that running Invoke-WebRequest (including the curl alias) against a webpage now triggers a security confirmation prompt. The prompt warns that embedded scripts in the retrieved content could run if processed using the legacy HTML parser. Users must choose to proceed or cancel, and declining halts the action. Using the -UseBasicParsing parameter avoids script execution entirely and prevents the prompt, making it the safer option for automation.
Key Insights
Further Reading: Microsoft Support
ConsentFix: Browser-Native OAuth Consent Hijacking
A newly identified phishing technique called ConsentFix combines ClickFix-style interaction tricks with OAuth consent abuse. Attackers direct victims to compromised, high-reputation sites where fake verification prompts are shown. Victims are manipulated into completing a legitimate OAuth authorization flow and then pasting the resulting authorization code into the attacker-controlled page. This grants persistent account access without stealing passwords or bypassing MFA, because the attacker leverages legitimate OAuth mechanisms used by trusted applications such as Azure CLI.
Key Insights
Further Reading: Push Security
Is Your Android TV Streaming Box Part of a Botnet?
An investigation has uncovered that many low-cost Android TV streaming boxes are being shipped with hidden malware that quietly enrolls devices into botnets. These compromised devices can be used for large-scale ad fraud, proxy abuse, credential stuffing, and other criminal activity — often without any visible signs to the owner. The issue largely affects off-brand devices sold online that run modified versions of Android and receive little to no security updates.
Key Insights
Further Reading: Krebs on Security
Uncovering a Calendly-Themed Phishing Campaign
A recent phishing campaign uses fake Calendly-style scheduling pages to trick users into surrendering their credentials. Instead of a legitimate meeting invite, victims are shown a cloned scheduling interface that prompts them to log in with their corporate credentials. Behind the scenes, the attacker captures those credentials — and often MFA tokens or session cookies — enabling full account takeover or further abuse.
Key Insights
Further Reading: Push Security
Access Granted: Phishing Abuse of Device Code Authorization
A new phishing trend is exploiting Device Code Authorization flows — a common method many services use to let users sign in on shared or secondary devices (like TVs) by entering a code shown elsewhere. Attackers are crafting phishing lures that direct victims to fake “authorization” pages where they’re prompted to enter a device code. Once entered, the code links the attacker’s session to the victim’s account, giving the attacker instant access without the victim ever entering credentials or MFA codes.
Key Insights
Further Reading: Proofpoint
SMS Phishers Pivot to Points, Taxes, and Fake Retailers
A surge in SMS phishing (smishing) campaigns is using new lures — including rewards-points alerts, tax refund notices, and “order issues” from well-known retailers — to trick recipients into clicking malicious links. These texts are crafted to look like legitimate communications from brands or government agencies, and they direct users to spoofed login pages or fake offers designed to capture credentials or financial information. The shift shows how attackers are evolving beyond traditional banking scams to exploit trends and behaviors that feel more routine or beneficial to users.
Key Insights
Further Reading: Krebs on Security
Android Expands Pilot for In-Call Scam Protection for Financial Apps
Google is expanding its Android in-call scam protection pilot specifically for interactions involving financial applications. This feature aims to intercept and block scam calls that impersonate banks, payment services, or other financial institutions before they reach users. By analyzing call metadata and patterns, the protection can warn users or automatically prevent known scam call types — reducing the likelihood that someone answers a phone-based phishing or social-engineering attempt targeting financial credentials or sensitive data.
Key Insights
Further Reading: Google Security Blog
Cybercriminals Exploiting .onmicrosoft.com Domains to Launch TOAD Scam Attacks
Cybercriminals are abusing legitimate Microsoft tenant domains that end in “.onmicrosoft.com” to deliver TOAD (Telephone-Oriented Attack Delivery) scams. By sending messages from these trusted-looking domains, attackers can bypass security filters and convince recipients that the communication is associated with Microsoft. Victims are then prompted to call fraudulent support numbers, where they are manipulated into disclosing credentials or other sensitive information.
Key Insights
Further Reading: Cybersecurity News
Calendar-Invite Phishing Campaigns Use Meeting Invites as Lures
Attackers are increasingly using fake calendar invitations as a phishing vector. These malicious invites may arrive by email or through synced calendar apps, often appearing to come from familiar contacts or trusted services. When a recipient interacts with the invite — for example, by clicking a link to join a “meeting” — they can be led to spoofed login pages designed to harvest credentials or other sensitive information. This technique leverages the trust people place in calendar events and routine scheduling workflows to bypass skepticism.
Key Insights
Further Reading: HoxHunt
Google Malvertising Attack Uses Search Ads to Deliver Phishing and Malware
A recently analyzed campaign showed how attackers are abusing Google Search Ads to distribute malicious redirects and phishing lures. Instead of relying on compromised websites or email alone, the adversary purchased search ad placements that appeared for high-traffic queries. When users clicked these ads, they were taken through a chain of redirects and deceptive pages that ultimately led to credential-harvesting forms or malware delivery. Because the initial entry point came from legitimate ads, many victims didn’t suspect the content was malicious — and traditional web-filtering tools often trust paid search results by default.
Key Insights
Further Reading: Push Security
Top Phishing Trends for 2025
Security researchers have identified several key phishing trends that defined 2025 — highlighting how attackers continue to evolve both their techniques and delivery mechanisms. These trends emphasize that phishing is no longer confined to simple email links, but increasingly combines social engineering with platform abuse, deceptive flows, and legitimate-looking vectors to bypass defenses and capture credentials, session tokens, and MFA responses.
Key Insights
Further Reading: Push Security
Most Parked Domains Now Serving Malicious Content
Security researchers report that a majority of parked domains — web addresses registered but not actively used for legitimate content — are now repurposed to serve malicious material. Cybercriminals are leveraging these unused or abandoned domains to host deceptive content that can deliver malware, phishing pages, or exploit kits. Because these domains often lack reputation and oversight, they present a growing risk to users who accidentally visit them through typos, shady links, or bundled ad networks.
Key Insights
Further Reading: Krebs on Security
The Kimwolf Botnet Is Stalking Local Networks
The Kimwolf botnet highlights how modern botnets are expanding beyond traditional IoT targets to compromise consumer-grade devices such as Android TV boxes, set-top boxes, and other smart devices. Once infected, these systems are folded into a large distributed botnet and can be abused for activities like DDoS attacks and proxying traffic into private networks, weakening the assumption that home and small-office networks are naturally isolated.
Key Insights
Further Reading: Krebs on Security