The Tacklebox is your one-stop reference guide to unraveling the intricate world of scams and fraudulent schemes. This comprehensive resource is designed to equip you with the knowledge and insights needed to recognize, understand, and protect yourself against various types of scams and social engineering tactics.
- Active Exploitation of WordPress Vulnerabilities: CVE-2026-60137 and CVE-2026-63030
- Analysis of Dirty Frag: New Risks in Linux Kernel for Social Engineering Exploits
- Analyzing CVE-2025-67038: Lantronix EDS5000 Code Injection Exploitation in Phishing Attacks
- Analyzing CVE-2026-12569: Phishing Exploits Targeting PTC Windchill Vulnerability
- Analyzing Nyx Console Malicious Code Campaign: Credential Harvesting Tactics
- Analyzing the Evil MSI Background Phishing Campaign: Techniques and Impacts
- Analyzing the Impact of CVE-2026-35273: Oracle PeopleSoft PeopleTools Vulnerability in Phishing Attacks
- Analyzing the Impact of CVE-2026-9082: Exploiting Drupal Core SQL Injection for Phishing Campaigns
- Anti-antivirus
- Are you Busy?
- Bogus Offers
- Comment Stuffing in Phishing Attachments for AI Evasion
- Comment Stuffing Phishing Campaigns Evasion Analysis
- Comment Stuffing Technique in Phishing: Advanced Evasion Recorded
- Coordinated SSH Brute Force Attacks: Recent Trends and Patterns
- COVID-19 Scams
- Cross-Platform NPM Stealer Uncovered: Analysis and Impact
- Current Phishing Campaign Targeting MetaMask Users
- CVE-2026-48283 and CVE-2026-48313: Adobe ColdFusion Exploitation via Phishing Campaigns
- CVE-2026-9181: Exploiting Esri ArcGIS Server in Phishing Attacks
- Dating Scam
- Deep Dive into the Cross-Platform NPM Stealer
- Dirty Frag: New Linux Kernel Vulnerability and Phishing Implications
- eBanking Phishing by IPv4-Mapped IPv6 Address: A New Attack Strategy
- eBanking Phishing Campaign Using IPv4-Mapped IPv6: New Developments
- eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address: A Current Campaign
- eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address: Targeting Belgian Bank Clients
- Emerging Phishing Threat to MetaMask Users: Exploiting Secret Codes
- Evasion Tactics in HTML Phishing: Analysis of Comment Stuffing
- Exploiting BerriAI LiteLLM SQL Injection Vulnerability for Unauthorized Access
- Exploiting CVE-2026-10520: Ivanti Sentry Vulnerability in Phishing Campaigns
- Exploiting CVE-2026-11645: Google Chromium V8 Vulnerability in Phishing Campaigns
- Exploiting CVE-2026-20230: Cisco Unified Communications Manager SSRF Vulnerability in Phishing Campaigns
- Exploiting CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Attack Pattern
- Exploiting CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation in Phishing Attacks
- Exploiting CVE-2026-58644: Microsoft SharePoint Deserialization Vulnerability in Phishing Attacks
- Exploiting CVE-2026-6973: Ivanti Endpoint Manager Mobile Vulnerability in Phishing Campaigns
- Exploiting Fortinet FortiSandbox via OS Command Injection: CVE-2026-39808
- Exploiting JPEG Payloads: The Return of Evil MSI Background
- Exploiting Metamask via Phishing: A Look at Recent Campaigns
- Exploiting SonicWall SMA1000 Vulnerabilities for Phishing Campaigns: CVE-2026-15409 and CVE-2026-15410
- Exploring ACR Stealer: A Fraudulent Page Impersonating Claude
- Exploring CVE-2026-12569: Phishing Exploits Targeting PTC Windchill Vulnerability
- Fake Charity Wants Your Donations
- Fake Docusign Phish
- Fake shipping notices
- Fake Tech Support
- Financial Aid Refund Scam
- From a VHDX File to a Remcos RAT: A Detailed Analysis of a Recent Real-World Phishing Campaign
- From a VHDX File to a Remcos RAT: Analyzing the Latest Phishing Technique
- From a VHDX File to Remcos RAT: Exploring Recent Phishing Techniques
- Gift Card Scam
- Impersonation of an Authority
- Invoice Phishing
- Job Scams
- Messages from HR
- Microsoft Patch Tuesday July 2026: The AI Apocalypse is Here
- NetSupport RAT Deployment via Unidentified RAT: New Techniques Uncovered
- New Metamask Phishing Campaign Exploits Secret Codes
- New MetaMask Phishing Campaigns Exploit Secret Codes: July 2026 Update
- New Metamask Phishing Campaigns: Secret Codes Leveraged Again in July 2026
- New Wave of Phishing Emails Delivering Malicious SVG Files
- New Wave of Phishing Emails Utilizing SVG Files Uncovered
- New Wave of SVG-Based Phishing Attacks Documented
- Nx Console Embedded Malicious Code Campaign: Exploiting Credential Harvesting
- Overly Aggressive Salesperson
- Phishing with Forms
- Pick Your Poison
- Reconstructing the Akira Ransomware Kill Chain: A Log Analysis Perspective
- Remote Work Phish
- Scanning for MCP Servers and AI Assistant Credentials: A New Wave of Cyber Threats
- Shared with you Phishy docs
- SonicWall SMA1000 Exploitation: Active Campaign Using CVE-2026-15409 and CVE-2026-15410
- Stranded traveler
- Sweepstakes Phish
- Tax and IRS Phishes
- TeamPCP Supply Chain Campaign Targets Multiple Ecosystems
- TeamPCP Supply Chain Campaign: Expanding Threat Vectors and Strategies
- TeamPCP Supply Chain Campaign: Latest Moves and Impacts
- The Return of MSI-Branded JPEG Payloads in Phishing Campaigns
- The Return of the Evil MSI Background Phishing Campaign
- Tracking the TeamPCP Supply Chain Attack: Latest Developments
- Uncovering Akira Ransomware Campaign: Forensic Insights and Entry Methods
- Unpacking the TeamPCP Supply Chain Campaign: Recent Activities and Threats
- Verification Phish
- Webcam Exploitation Ransom
- WordPress Exploitation Campaign: wp2shell Vulnerability CVE-2026-63030
- Your bank, or is it?























































































