惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Human Risk Management Blog

Beyond the Chatbot: Why Your AI Agents are Your Newest (and Most Vulnerable) Colleagues Report: Adversarial Use of AI is Evolving AI Agent Governance Part 1 - Beyond the Chatbot: Mastering AI Agent Governance Report: The Tycoon 2FA Phishing Kit Has Evolved KnowBe4 CEO Bryan Palma Q&A From KB4-CON 2026 How Agentic AI and Automation Are Changing Cybersecurity AI Alone Won’t Stop the Breach: Why Email Security Needs Humans-on-the-Loop [Heads Up] GitHub Breach Shows Developer Tools Are Social Engineering Targets Build Custom, High-Impact Training with KnowBe4’s Content Creation Agent Reducing Phish-Prone Rates Without Training Fatigue: A Practical Playbook for Traditional Organizations Report: Romance Scams Cost UK Victims £102 Million Last Year Warning: Phishing Attacks Are Abusing the Kuse AI App CyberheistNews Vol 16 #20 [Heads Up] Today You Have Only 60 Seconds to Stop That Breach. Are You Ready? Phishing Campaign Exploits Google AppSheets to Target Facebook Accounts FTC: Americans Lost $2.1 Billion to Social Media Scams Last Year What Is an Al Agent in Cybersecurity? Why Integrate Threat Intelligence Feeds into Email Security? Traffic-Themed SMS Phishing Targets Users Around the World Redesigning Security Culture for the Agentic Age Fighting AI-Assisted Ransomware Threats Phishing Attacks Begin Targeting the 2026 FIFA World Cup Warning: Netflix Phishing Scams Can Lead to Serious Consequences Navigating the Cybersecurity Landscape in India Empowering Human and AI Agents The Rise of Cyber Threats and AI in the Philippines: A New Era Beyond Legacy Security Report: 4 in 10 UK Businesses Were Breached by Phishing Last Year Navigating Human and Agentic Risks for Financial Institutions in the APJ Region CyberheistNews Vol 16 #19 Crafty Criminals Continue to Pose as Help Desks in Social Engineering Attacks From Cyberwar to Cognitive Warfare: The Geopolitical Impact on Cybersecurity in Africa You Have 60 Seconds to Stop the Breach. Are You Ready? World Password Day 2026: Treat Identity as the Perimeter (and Act Like It) Attackers Continue to Pose as Help Desks in Social Engineering Attacks Introducing the New AI-Native KnowBe4 SAT Report: Deepfake Fraud Causes Billions in Losses Your KnowBe4 Fresh Content Updates from April 2026 Alert: Payroll-Hijacking Attacks Are Targeting Canadian Employees How to Design Security for Agentic AI Why Your Email Security Needs a Global Human Network to Close the Detection Gap Phishing Attacks Target Executives via Microsoft Teams CyberheistNews Vol 16 #17 [Heads Up] This Sophisticated Scam Should Be a Warning to All Companies FBI: Americans Lost More Than $20 billion to Fraud Last Year Phishing Campaigns Abuse AI Workflow Automation Platforms Nobody runs a marathon by accident This Sophisticated Scam Should Be a Warning To All Companies CyberheistNews Vol 16 #16 How Identity at the Edge Highlights the New Frontiers of Trust Alert: WhatsApp Phishing Campaign Delivers Malware Alert: WhatsApp Phishing Campaign Delivers Malware Survey: Security Leaders Emphasize Need for Workforce Education Identity at the Edge: How the Sixth Annual Identity Management Day Highlights the New Frontiers of Trust Early Results From KnowBe4’s AI Agents Show Easier Administration and Lower Cyber Risk CyberheistNews Vol 16 #15 Anthropic's Mythos Is Not Just a Tool. It's Something You Have to Contain. New KnowBe4 Agent Risk Manager Addresses Pervasive AI Agent Risk Anthropic's Mythos Preview: Why the Human Layer Matters More, Not Less New Phishing Kit Streamlines ClickFix Attacks Phishing Campaign Targets Japanese Firms During Tax Season Rising Compliance Oversight Pressure: From Audit Fatigue to Continuous Readiness AI Phishing Attack Prevention Strategies: How AI Identifies and Limits Human Risk Phishing Campaign Impersonates Palo Alto Networks Recruiters Voice Phishing is a Growing Social Engineering Threat AI-Powered Human Risk Management Shifts the Focus to Adaptive, Behavior-Based Training CyberheistNews Vol 16 #14 [Heads Up] Clever Hackers Use Custom Fonts to Bypass AI Defenses Campaign Mode: Because Your SOC Team Has a Life Your KnowBe4 Fresh Compliance Plus Content Updates | March 2026 Detection and Prevention of Misdirected Emails: What to Know
Robinhood Glitch Allowed Attackers to Send Phishing Emails to Customers
KnowBe4 Team · 2026-05-22 · via Human Risk Management Blog

A phishing campaign exploited a glitch in Robinhood’s account creation process to send phishing emails from the investment platform’s own systems, SecurityWeek reports.

“On Sunday evening, some customers received a falsified email from noreply@robinhood.com with the subject line ‘Your recent login to Robinhood,’” Robinhood said in a statement. “This phishing attempt was made possible by an abuse of the account creation flow. It was not a breach of our systems or customer accounts, and personal information and funds were not impacted. If you received this email, please delete it and do not click any suspicious links. If you have clicked a suspicious link or have any questions about your account, please contact us directly within the Robinhood app or website.”

According to SecurityWeek, the attackers took advantage of the fact that Gmail addresses ignore periods placed within the email username before the “@” symbol. If a third-party service allows users to create accounts using a Gmail address, the process needs to take this into consideration. Otherwise, as in the case of Robinhood, attackers can create multiple accounts using the same Gmail address.

SecurityWeek explains, “Specifically, they leveraged the fact that Gmail ignores periods inserted into or removed from a username, whereas Robinhood treats each variation as distinct, allowing the attackers to create a new account that Gmail would point to an existing account. During signup, the attackers injected malicious HTML code containing phishing links into device name fields. The hackers’ actions triggered legitimate ‘recent login’ notification emails from Robinhood, which rendered the unsanitized HTML and embedded clickable phishing links.”

SecurityWeek has the story: Robinhood Vulnerability Exploited for Phishing Attacks