The Tacklebox is your one-stop reference guide to unraveling the intricate world of scams and fraudulent schemes. This comprehensive resource is designed to equip you with the knowledge and insights needed to recognize, understand, and protect yourself against various types of scams and social engineering tactics.
- 22 Seconds to Compromise: Automated SSH Actors and Fast-Paced Attacks
- Active Exploitation of Sangoma Switchvox CVE-2026-9586
- Active Exploitation of WordPress Vulnerabilities: CVE-2026-60137 and CVE-2026-63030
- Analysis of Dirty Frag: New Risks in Linux Kernel for Social Engineering Exploits
- Analyzing CVE-2025-67038: Lantronix EDS5000 Code Injection Exploitation in Phishing Attacks
- Analyzing CVE-2026-12569: Phishing Exploits Targeting PTC Windchill Vulnerability
- Analyzing Nyx Console Malicious Code Campaign: Credential Harvesting Tactics
- Analyzing the Evil MSI Background Phishing Campaign: Techniques and Impacts
- Analyzing the Impact of CVE-2026-35273: Oracle PeopleSoft PeopleTools Vulnerability in Phishing Attacks
- Analyzing the Impact of CVE-2026-9082: Exploiting Drupal Core SQL Injection for Phishing Campaigns
- Anti-antivirus
- Are you Busy?
- Atomic MacOS (AMOS) Stealer: In-Depth Analysis of Recent Infection Patterns
- Bogus Offers
- Case Study: The Impact of Polymorphic Phishing Pages Breaking Themselves
- Comment Stuffing in Phishing Attachments for AI Evasion
- Comment Stuffing Phishing Campaigns Evasion Analysis
- Comment Stuffing Technique in Phishing: Advanced Evasion Recorded
- Coordinated SSH Brute Force Attacks: Recent Trends and Patterns
- COVID-19 Scams
- Cross-Platform NPM Stealer Uncovered: Analysis and Impact
- Current Phishing Campaign Targeting MetaMask Users
- CVE-2026-19478: Exploiting GitLab GraphQL Directive Code Injection
- CVE-2026-48283 and CVE-2026-48313: Adobe ColdFusion Exploitation via Phishing Campaigns
- CVE-2026-72530: Exploiting TrueConf Server Code Injection Vulnerability
- CVE-2026-73570: Leveraging Zimbra Command Injection Vulnerability in Phishing Attacks
- CVE-2026-9181: Exploiting Esri ArcGIS Server in Phishing Attacks
- Dating Scam
- Deep Dive into the Cross-Platform NPM Stealer
- Dirty Frag: New Linux Kernel Vulnerability and Phishing Implications
- Don’t Revoke That Token Yet: Inside the keyv/cacheable npm Worm
- DOUBLECUP Campaign: Exploring the Use of PNG Payloads
- eBanking Phishing by IPv4-Mapped IPv6 Address: A New Attack Strategy
- eBanking Phishing Campaign Using IPv4-Mapped IPv6: New Developments
- eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address: A Current Campaign
- eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address: Targeting Belgian Bank Clients
- Emerging Phishing Threat to MetaMask Users: Exploiting Secret Codes
- Evasion Tactics in HTML Phishing: Analysis of Comment Stuffing
- Exploiting BerriAI LiteLLM SQL Injection Vulnerability for Unauthorized Access
- Exploiting Cloud Metadata Services for Credential Theft: Current Tactics
- Exploiting CVE-2026-10520: Ivanti Sentry Vulnerability in Phishing Campaigns
- Exploiting CVE-2026-11645: Google Chromium V8 Vulnerability in Phishing Campaigns
- Exploiting CVE-2026-20230: Cisco Unified Communications Manager SSRF Vulnerability in Phishing Campaigns
- Exploiting CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Attack Pattern
- Exploiting CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation in Phishing Attacks
- Exploiting CVE-2026-58644: Microsoft SharePoint Deserialization Vulnerability in Phishing Attacks
- Exploiting CVE-2026-6973: Ivanti Endpoint Manager Mobile Vulnerability in Phishing Campaigns
- Exploiting Fortinet FortiSandbox via OS Command Injection: CVE-2026-39808
- Exploiting Gitea Code Injection Vulnerability (CVE-2026-60004) in Phishing Attacks
- Exploiting JPEG Payloads: The Return of Evil MSI Background
- Exploiting Metabase SQL Injection Vulnerability: Real-World Phishing Campaign Patterns
- Exploiting Metabase SQL Injection: Current Threat Actor Campaign Patterns
- Exploiting Metamask via Phishing: A Look at Recent Campaigns
- Exploiting MLflow SSRF Vulnerability: Emerging Attack Techniques
- Exploiting PaperCut NG/MF Vulnerabilities in Phishing Campaigns
- Exploiting Sangoma Switchvox CVE-2026-9586: SQL Injection and Remote Code Execution
- Exploiting SonicWall SMA1000 Vulnerabilities for Phishing Campaigns: CVE-2026-15409 and CVE-2026-15410
- Exploring ACR Stealer: A Fraudulent Page Impersonating Claude
- Exploring CVE-2026-12569: Phishing Exploits Targeting PTC Windchill Vulnerability
- Fake Charity Wants Your Donations
- Fake Docusign Phish
- Fake shipping notices
- Fake Tech Support
- Financial Aid Refund Scam
- From a VHDX File to a Remcos RAT: A Detailed Analysis of a Recent Real-World Phishing Campaign
- From a VHDX File to a Remcos RAT: Analyzing the Latest Phishing Technique
- From a VHDX File to Remcos RAT: Exploring Recent Phishing Techniques
- Gift Card Scam
- Guildma (Astaroth) Malware: A New Wave of Infection via Brazilian Portuguese Emails
- Guildma: Analyzing Astaroth Malware Deployment via Brazilian Portuguese Emails
- Impersonation of an Authority
- Inside the keyv/cacheable npm Worm: A Supply-Chain Attack Case Study
- Invoice Phishing
- Job Scams
- keyv/cacheable NPM Worm: When Revoking Tokens Backfires
- Messages from HR
- Metabase Pre-Authentication SQL Injection Exploitation: A Current Threat Landscape
- Metabase SQL Injection Vulnerability Exploitation in the Wild
- Metabase SQL Injection Vulnerability in Real-World Phishing Campaigns
- Microsoft Patch Tuesday July 2026: The AI Apocalypse is Here
- NetSupport RAT Deployment via Unidentified RAT: New Techniques Uncovered
- New Metamask Phishing Campaign Exploits Secret Codes
- New MetaMask Phishing Campaigns Exploit Secret Codes: July 2026 Update
- New Metamask Phishing Campaigns: Secret Codes Leveraged Again in July 2026
- New Wave of Phishing Emails Delivering Malicious SVG Files
- New Wave of Phishing Emails Utilizing SVG Files Uncovered
- New Wave of SVG-Based Phishing Attacks Documented
- Nx Console Embedded Malicious Code Campaign: Exploiting Credential Harvesting
- Obfuscating IP Addresses in Phishing Attacks: Recent Campaign Trends
- Overly Aggressive Salesperson
- Phishing Campaigns Targeting AI Solutions Providers
- Phishing Campaigns Targeting AI Solutions Providers: Latest Developments
- Phishing with Forms
- Pick Your Poison
- Polymorphic Phishing Page Observed with Self-Destructive Tendencies
- Polymorphic Phishing Page: A Self-Breaking Attack Pattern
- Polymorphic Phishing Pages Observed in the Wild: A Recent Case Study
- Progress LoadMaster Command Injection Exploitation: Real-World Campaign Analysis
- Recent Phishing Campaigns Exploiting AI Services Like ChatGPT
- Reconstructing the Akira Ransomware Kill Chain: A Log Analysis Perspective




































































































