The FTC is warning that phishing emails disguised as Evite and Paperless Post invitations are hijacking email accounts and, in one case, draining a bank account, often forwarded by real friends whose accounts were compromised first.
IEH Corporation Discloses Microsoft 365 Phishing Breach at Defense Connector Maker
A phished employee credential gave an attacker access to a Brooklyn defense supplier's Microsoft 365 mailbox, exposing engineering files and export-controlled data tied to Patriot and THAAD programs, IEH told the SEC.
CZ Warns of Phishing Risk After Trezor’s Shipping Partner Exposes 13,689 Customers
Binance founder Changpeng Zhao warned that a data breach at Trezor's shipping partner ShipMonk, which exposed 13,689 customers' names and addresses, hands attackers a ready-made list for phishing and physical targeting.
Hudson Valley Guide Traces Four Small Business Breaches to the Same Preventable Gaps
A Hudson Valley MSP's new guide traces four small business ransomware and phishing incidents back to unpatched firewalls, missing MFA, and spoofed domains, a pattern CISOs should recognize from breaches at companies many times their size.
Criminal AI Service MessiahGPT Sells Ransomware and Phishing Kits for $8 a Month
Trellix found a criminal AI service, MessiahGPT, selling on BreachForums for as little as $8 a month, generating ransomware, phishing kits and rootkits on demand with no ethical guardrails claimed by its operator, and no coding skill required.




