PhishFort Blog

Our Research and Announcements

Stay informed with our latest blog posts.

Company News 2 min read

Fortmatic and PhishFort Team Up!

PhishFort and Fortmatic team up to protect Web3 dApps from phishing attacks. Learn how this partnership enhances crypto security, user trust, and safe authentication for decentralized apps.

Read more: Fortmatic and PhishFort Team Up!
Company News 2 min read

PhishFort Teams Up With Binance Labs

PhishFort and Binance Labs join forces to make crypto safer. Discover how this investment strengthens phishing protection, innovation, and user trust across the global crypto ecosystem.

Read more: PhishFort Teams Up With Binance Labs
Blog

Latest posts

Research 4 min read

UAC-0099 Weaponizes Notepad++ and WinRAR Plugins to Deliver Malware

UAC-0099 is hijacking trusted apps like Notepad++ and WinRAR through malicious plugins and DLL sideloading. Here's the full infection chain, based on CERT-UA's technical advisory.

Read more: UAC-0099 Weaponizes Notepad++ and WinRAR Plugins to Deliver Malware
Crypto 4 min read

How Impersonation Fuels Gift Card and Crypto Scams

Gift card and crypto scams work because attackers borrow someone else's identity: a celebrity, an investment manager, even a loved one's voice. Here's how the impersonation angle actually plays out.

Read more: How Impersonation Fuels Gift Card and Crypto Scams
Research 2 min read

How a Real ChatGPT Link Delivers Phishing via a Fake Codex Install

A malicious Google Ad leads to a real chatgpt.com link, where a fake "Codex" install command hides a base64 payload that drops the MacSync infostealer. Here's the full chain.

Read more: How a Real ChatGPT Link Delivers Phishing via a Fake Codex Install
Research 3 min read

Fake Data Breach Claims: Why Scam-Style Extortion Is Surging in 2026

Scam-style extortion is rising: attackers post fake data breach claims on leak sites with no real intrusion. Here's how the bluff works and how to verify before you panic.

Read more: Fake Data Breach Claims: Why Scam-Style Extortion Is Surging in 2026
Research 3 min read

Click to Pray Exposes 700k Users: Inside a Textbook IDOR Failure

The Vatican's Click to Pray app leaked the personal data of 700,000 users for over six months through a basic IDOR flaw. Here's how sequential user IDs and zero auth checks did the damage.

Read more: Click to Pray Exposes 700k Users: Inside a Textbook IDOR Failure