Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Dark Reading
darkreading.com > cyberattacks-data-breaches > css-hidden-threat-lurking-inbox

CSS: The Hidden Threat Lurking in Your Inbox

1+ hour, 16+ min ago   (779+ words) CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared. Black Hat USA 2026 – Las Vegas – Using email platforms to target users is nothing new in the world of…...

Dark Reading
darkreading.com > application-security > phishing-campaigns-auto-adapt-victims-device-os

Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

1+ mon, 4+ day ago   (641+ words) Threat actors are moving away from spray-n-pray phishing attacks in favor of campaigns that can automatically adapt to a target's device and operating system. "One method of detection that is appearing more often is the use of Cloudflare user-agent blocking,…...

Dark Reading
darkreading.com > cyber-risk > fbi-flagged-phishing-kit-kali365-expands-its-reach

FBI-Flagged Phishing Kit Kali365 Expands Its Reach

2+ mon, 2+ day ago   (355+ words) Once targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing. The operators of Kali365, a phishing-as-a-service platform that drew considerable attention for helping attackers bypass multifactor authentication (MFA) on Microsoft…...

Dark Reading
darkreading.com > vulnerabilities-threats > microsoft-exchange-zero-day-no-patch

Microsoft Exchange Zero-Day Under Attack, No Patch Available

2+ mon, 2+ week ago   (623+ words) CVE-2026-42897 stems from a cross-site scripting (XSS) vulnerability and can allow an attacker to compromise Outlook Web Access (OWA) mailboxes. Microsoft on Thursday disclosed a zero-day vulnerability in Exchange that's under active exploitation, but four days later customers are still…...

Google News
darkreading.com > ics-ot-security > serial-ip-devices-thousands-of-bugs

Google News

3+ mon, 2+ week ago   (12+ words) Serial-to-IP Devices Hide Thousands of Old and New Bugs Dark Reading...

Dark Reading
darkreading.com > threat-intelligence > why-call-this-number-toad-emails-beat-gateways

Why 'Call This Number' TOAD Emails Beat Gateways

5+ mon, 1+ week ago   (753+ words) Attackers are bypassing email gateways through telephone-oriented attack delivery (TOAD), in which the only email payload is a phone number. While much of the conversation surrounding phishing concerns not clicking a suspicious link or downloading a malicious attachment, there's an…...