The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Real Estate/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Real Estate/Mortgage sector.
Explore Other Sectors
Real Estate/Mortgage Threat Reports
Major Passkey Phishing Campaign Compromises Microsoft Cloud Environments in 2026
Between May and September 2026, threat actors including Storm-3121 and Storm-3032 conducted sophisticated social engineering campaigns targeting Microsoft cloud environments. The attacks involved AI-assisted executive impersonation for invoice fraud, sending over one million scam emails in August 2026, and passkey-themed phishing operations. Attackers impersonated IT help desk personnel to trick employees into updating authentication methods through fraudulent websites, enabling adversary-in-the-middle attacks and device code authentication bypasses. Once successful, threat actors established persistent access by registering their own MFA methods and conducted extensive data exfiltration through Microsoft Graph API abuse, SharePoint downloads, and mailbox collection. This incident demonstrates the evolution of identity-focused attacks targeting cloud infrastructure and the increasing sophistication of social engineering tactics combined with legitimate cloud service abuse.
1 week ago
Kill Chain
AI Weaponizes Phishing: How Threat Actors Generated 1 Million Personalized Attacks in 72 Hours
In August 2026, an unattributed threat actor leveraged artificial intelligence to orchestrate a sophisticated phishing campaign that generated over one million personalized fraudulent emails within just three days. The campaign targeted accounts payable departments across multiple industries, primarily in the United States, impersonating ServiceNow with fake invoices claiming companies owed nearly $50,000 for annual subscriptions. The attackers used AI to research and incorporate real executive names, create convincing email threads, and personalize each message at unprecedented scale, representing a significant evolution in business email compromise tactics. This incident demonstrates the rapid industrialization of AI-enhanced cyberattacks, where threat actors no longer must choose between volume and personalization. The campaign's success highlights an emerging trend where artificial intelligence is amplifying traditional attack vectors, making previously labor-intensive social engineering techniques scalable to millions of targets while maintaining convincing levels of personalization and authenticity.
1 week ago
Kill Chain
PREY-0058: How Vishing Attacks Are Bypassing Microsoft 365 Security
Arctic Wolf identified PREY-0058, a widespread data theft and extortion campaign targeting Microsoft 365 and SaaS platforms through sophisticated vishing attacks. The threat actors impersonate IT help desk personnel, directing executives to fraudulent authentication pages that harvest credentials and MFA tokens via adversary-in-the-middle techniques. Using residential proxy infrastructure like NodeMaven, attackers perform session replay attacks to access SharePoint, OneDrive, Exchange, and Box for mass data exfiltration before issuing extortion demands. The campaign primarily targets directors and executives across construction, healthcare, finance, and professional services sectors. This incident highlights the growing sophistication of identity-based attacks that bypass traditional security controls. As organizations increasingly rely on cloud services and remote access, vishing campaigns exploiting human factors and legitimate authentication flows represent a critical threat vector requiring enhanced user education and phishing-resistant authentication measures.
2 weeks ago
Kill Chain
Critical Elementor Pro Vulnerability Enables WordPress Site Takeovers
In September 2026, threat actors began actively exploiting CVE-2026-32475, a critical vulnerability in the Elementor Pro WordPress plugin with over 6 million installations. The flaw allows attackers to bypass file upload validation by submitting an empty file as the first array element and a malicious PHP file as the second, enabling arbitrary code execution on vulnerable WordPress sites. Wordfence recorded nearly 200,000 exploitation attempts within days of the August 19 patch release, with attackers successfully deploying webshells to the /wp-content/uploads/elementor/forms/ directory for remote command execution. This incident highlights the persistent risk of web application vulnerabilities in popular content management systems, particularly when exploitation begins immediately after patch availability. The rapid weaponization demonstrates sophisticated threat actor capabilities in identifying and exploiting plugin vulnerabilities that affect millions of websites worldwide.
3 weeks ago
Kill Chain
Spark RAT Exploits Vulnerable OPSWAT Driver in Sophisticated Cambodia Campaign
Between June and August 2026, threat actors conducted a sophisticated campaign targeting individuals and organizations in Cambodia using Spark RAT, an open-source remote access trojan. The multi-stage attack leveraged phishing emails with localized lures including government notices and health materials to distribute Inno Setup executables. The campaign employed advanced techniques including DLL sideloading, bring-your-own-vulnerable-driver (BYOVD) tactics using OPSWAT's ardrv.sys driver, and multi-layered persistence mechanisms to disable security software and maintain access to compromised systems. This incident highlights the growing sophistication of nation-state and advanced persistent threat actors who are increasingly leveraging legitimate-but-vulnerable drivers to bypass modern endpoint security solutions, representing a critical evolution in attack methodologies that organizations must address immediately.
4 weeks ago
Kill Chain
Critical Rently Smart Home Vulnerability Exposes IoT Access Control Risks
In August 2026, CISA published advisory ICSA-26-237-01 detailing a critical vulnerability (CVE-2026-75960) in Rently Smart Home systems version 20.1.0 and prior. The vulnerability, classified as Insufficiently Protected Credentials with a CVSS score of 8.1, allows attackers to retrieve pins including the Master Pin and override standard user permissions. The flaw affects smart home access control systems deployed across commercial facilities in the United States and India, potentially compromising physical security for properties using Rently's keyless entry solutions. Rently patched the vulnerability in late June 2026, requiring no user action for remediation. This incident highlights the growing security risks in IoT and smart building infrastructure as organizations increasingly adopt connected access control systems. The vulnerability underscores critical gaps in credential protection mechanisms that could enable unauthorized physical access to commercial and residential properties.
4 weeks ago
Kill Chain
Critical Elementor Pro Vulnerability Exposes 10M+ WordPress Sites to Remote Code Execution
A critical vulnerability (CVE-2026-32475) in Elementor Pro WordPress plugin versions before 4.2.2 allows unauthenticated attackers to upload executable PHP files for remote code execution. The flaw stems from inconsistent file validation logic in the File Upload module, where empty filename entries are handled differently by validation and processing loops. Attackers can exploit this by crafting multipart uploads with empty first entries followed by malicious PHP payloads, bypassing validation and uploading executable files to public directories. With over 10 million WordPress installations using Elementor, this vulnerability poses significant risk to websites using Elementor Pro forms with file upload functionality enabled. This incident highlights the growing trend of supply chain vulnerabilities targeting popular WordPress plugins and website builders. As organizations increasingly rely on third-party components for web development, plugin vulnerabilities have become a primary attack vector for gaining initial access to web infrastructure and conducting broader network compromises.
1 month ago
Kill Chain
French Tax Authority Data Breach 2026: ZeroBytes Compromises 678,000 Records
In August 2026, the French Ministry of the Economy and Finance disclosed a significant data breach involving the General Directorate of Public Finances (DGFiP). A threat actor known as "ZeroBytes" accessed DGFiP systems, extracting sensitive data of approximately 678,000 individuals and professionals. The compromised information included tax data such as reference tax income, family quotient, withholding tax rates, company names, and SIREN numbers. Additionally, cadastral data related to property addresses and sizes were accessed. The breach was discovered when ZeroBytes listed the stolen database for sale on a hacking forum on August 12, 2026. Upon detection, the French tax administration promptly shut down access to sensitive systems and initiated an investigation with the National Cybersecurity Agency of France (ANSSI) to assess the full impact of the breach. Affected individuals were notified, and measures were taken to prevent further unauthorized access. This incident underscores the escalating trend of cyberattacks targeting governmental institutions, highlighting the critical need for robust cybersecurity measures and vigilant monitoring to protect sensitive citizen data.
1 month ago
Kill Chain
Spanish Authorities Dismantle €140 Million Cyber Fraud Network
In July 2026, Spanish authorities dismantled a cybercrime and money-laundering network responsible for defrauding €140 million through investment fraud and Business Email Compromise (BEC) schemes. The operation led to the arrest of four individuals across Spain, Portugal, and Panama. The criminals managed over 800 bank accounts, utilizing sophisticated social engineering tactics such as impersonating executives and issuing false invoices to divert funds into accounts they controlled. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/spanish-police-take-down-140-million-cyber-fraud-ring-arrest-four/?utm_source=openai)) This incident underscores the escalating threat of BEC attacks, which exploit organizational trust and email communications to execute financial fraud. The substantial financial impact highlights the necessity for organizations to implement robust email security measures, employee training, and stringent verification processes to mitigate such risks.
2 months ago
Kill Chain
FBI Issues Warning on Fake Permit Fee Phishing Scam
In March 2026, the FBI issued a public alert regarding a sophisticated phishing campaign where cybercriminals impersonated city and county planning officials to defraud property owners. By leveraging publicly accessible permit records, these actors sent emails to individuals with active applications, demanding payments for fictitious permit fees via wire transfers, peer-to-peer transfers, or cryptocurrency. The emails were meticulously crafted, incorporating real permit details to enhance credibility, leading victims to authorize payments that bypassed traditional fraud detection mechanisms. This scheme resulted in significant financial losses and highlighted vulnerabilities in existing payment verification processes. The urgency of this issue is underscored by the rapid escalation of government impersonation scams, which nearly doubled in reported losses to approximately $798 million in 2025. The increasing sophistication of these attacks, particularly their ability to exploit publicly available data and evade standard fraud detection systems, necessitates immediate attention and the development of more robust security measures to protect individuals and businesses from such fraudulent activities.
2 months ago
Kill Chain
Defending Against AI-Enhanced Business Email Compromise in 2026
In 2026, Business Email Compromise (BEC) attacks have evolved into sophisticated, multi-stage operations. Threat actors gain access to organizational mailboxes or SaaS accounts, meticulously analyze internal communications, and exploit financial processes to execute fraudulent transactions. The integration of AI technologies has enhanced the quality and efficiency of these scams, making them increasingly difficult to detect. The prevalence of BEC attacks has surged, with 74% of organizations reporting incidents in 2025, up from 63% in 2024. ([nacha.org](https://www.nacha.org/news/business-email-compromise-attempts-rose-sharply-2025-report-finds?utm_source=openai)) This trend underscores the urgent need for organizations to bolster their cybersecurity measures and employee training to mitigate the escalating threat posed by BEC schemes.
2 months ago
Kill Chain
Urgent Update: WP Maps Pro Vulnerability (CVE-2026-8732) Threatens WordPress Sites
In May 2026, a critical vulnerability (CVE-2026-8732) was discovered in the WP Maps Pro plugin for WordPress, affecting versions up to and including 6.1.0. This flaw allowed unauthenticated attackers to create administrator accounts by exploiting an insecure AJAX endpoint, leading to potential full site takeovers. The vulnerability stemmed from inadequate nonce protection, making it possible for attackers to bypass authentication mechanisms and gain elevated privileges. The exploitation of this vulnerability underscores the persistent risks associated with third-party plugins in content management systems. It highlights the necessity for website administrators to maintain rigorous update practices and implement robust security measures to mitigate such threats.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports