MEDIUMPhishing
Global

One URL, Three Different Tricks, (Thu, Sep 24th)

·Source: SANS ISC

Updated:

Executive Summary

Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link:

Analysis

Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link:
Source Attribution

Originally published by SANS ISC on Sep 24, 2026.

Related Threats

CRITICALPhishing

ABB Protection and Control IED Manager PCM600

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files.</strong></p> <p>The following versions of ABB Protection and Control IED Manager PCM600 are affected:</p> <ul> <li>Pro

CVE-2026-15952CVE-2026-15953
CISA Advisories
MEDIUMPhishing

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. "Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected

The Hacker News
MEDIUMPhishing

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud

The Hacker News