Blog

Security tips, product updates, and threat intelligence. RSS feed

What's new in PhishClean 1.5.0: reported phishing sites blocked, fake virus pages caught

About 378,000 reported phishing sites blocked for free and checked on your device, a warning on fake virus pages before you call the number, and a fix for plain http:// pages.

Read more →

What's new in PhishClean 1.4.0: breached sites and leaked passwords

A heads-up when a site you sign in to has had a data breach, and a private check that tells you if the password you type has already leaked. Powered by Have I Been Pwned.

Read more →

Weekly phishing roundup: EvilTokens taken down, Revolut texts, fake Bitrefill checkouts

Microsoft and UK police take down EvilTokens, Revolut customers get phishing texts days after a breach, fake Bitrefill checkouts turn up in search results, and a Zoom/DocuSign wave hits inboxes.

Read more →

Fake e-Challan messages: how India's traffic-fine scam steals cards, OTPs and UPI PINs

An SMS says you owe a traffic fine. The link opens a copy of the Parivahan site that only takes cards, or asks you to install "RTO Challan.apk". How the scam works and how to check a challan safely.

Read more →

FBI warns of OAuth consent phishing: the "Allow" button that survives a password reset

No fake login page, no stolen password. The victim signs in on the real Google or Microsoft page and clicks Allow, and a malicious app keeps access even after a password change.

Read more →

Invisible characters, real phishing: Microsoft finds ASCII smuggling used to slip past email filters

A technique from AI prompt-injection research turned up in a phishing campaign that peaked at 2.37 million messages a day. The words look normal to you, but the filter reads something different.

Read more →

"This is IT, we need to migrate your account": the vishing campaign hitting financial firms

Callers pose as the IT helpdesk, push an urgent "security migration", and send employees to login portals that capture passwords and MFA codes as they are typed. Ransom demands reach $3 million.

Read more →

What's new in PhishClean 1.3.0: see your protection working

A pages-checked count on the toolbar, a weekly safety report, a what-to-do-now guide for bad clicks, detection for common Indian scam pages, and rupee pricing.

Read more →

What's new in PhishClean 1.2.0: subscribe without an account

Pay in two clicks with no account, a one-time heads-up on the day the trial ends, two checks that never expire, and a fix for paid status carrying over to a new account.

Read more →

What's new in PhishClean 1.1.6: a harder-to-fool detection engine

Lookalike and homograph domain detection, live re-scanning on SPA navigation and DOM changes, deeper secret scanning, and a more accessible warning modal.

Read more →

Ghost phishing: why a clean URL scan no longer means a clean page

The EvilTokens wave ships its page as encrypted code that only decrypts inside your browser, so URL and email scanners see nothing. Why the browser is the real blind spot.

Read more →

Attackers are now phishing your passkey enrollment, not just your password

Okta warns of a vishing campaign that calls employees, walks them through a fake Microsoft Entra passkey setup, and quietly registers the attacker's own passkey on the real account.

Read more →

24 billion stolen logins: what a record credential dump means for you

A 24-billion-record credential database built from infostealer logs and enriched with live CVE data was found exposed. Why it fuels credential stuffing - and what actually helps.

Read more →

GitBait: when a trusted GitHub URL hosts a fake bank login

The GitBait campaign abused GitHub Pages to host fake banking portals, borrowing a trusted domain's reputation to steal logins and card details. Why trusted-host phishing works.

Read more →

Surge in OAuth redirect phishing: why it matters

A look at why OAuth consent and redirect abuse is rising, and how to spot risky authorization flows.

Read more →

Chrome extension malvertising wave: what users should know

Extensions injecting ads and redirects can push users into phishing pages; how to audit extensions and reduce risk.

Read more →

MFA fatigue attacks are rising: how to defend

Understanding MFA fatigue and steps to reduce exposure, including phishing-resistant second factors and browser signals.

Read more →

Supply-chain SMS phishing: attackers leverage messaging channels

Why supply-chain or provider-abuse phishing via SMS is growing, and what to check in the browser after clicking links.

Read more →

OAuth redirect campaign mitigation: browser and identity controls

A practical mitigation guide for consent settings, redirect review, user education, browser checks, and response steps.

Read more →

European Commission cloud breach shows how one AWS account can spill sensitive data

A recent europa.eu breach tied to a compromised cloud account is a reminder that public-facing infrastructure can still expose directories, keys, and documents with real downstream risk.

Read more →

CareCloud breach filing shows why an eight-hour healthcare incident still matters

CareCloud's SEC filing shows why a short-lived healthcare breach can still become material when patient information may have been reachable or exfiltrated.

Read more →

Best affiliate products for cybersecurity bloggers in 2026

What security creators should look for in affiliate products and why narrower browser-security SaaS can be easier to recommend credibly.

Read more →

Best browser security affiliate programs in 2026

A practical look at browser-security affiliate programs, what audiences actually care about, and why phishing-focused tools are easier to explain honestly.

Read more →

How to promote affiliate products without losing trust

How creators can write affiliate content that still feels credible, especially in privacy, security, and technical niches.

Read more →

Microsoft says OAuth redirect abuse is helping phishing links look trustworthy

Microsoft says attackers are abusing legitimate identity-provider redirects to move users from trusted login URLs to phishing pages and malware.

Read more →

FBI warns permit applicants about city and county zoning-fee phishing emails

The FBI says criminals are using real permit details and urgent payment lures to make city and county phishing emails feel routine.

Read more →

That purchase order PDF might just be a browser phishing page

A fake purchase-order attachment reported this month shows how a browser page can hide inside a so-called PDF and steal business credentials.

Read more →

Fake Google security checks are now installing browser-based phishing apps

Researchers say a fake Google security page is abusing PWA installation and browser permissions to steal OTPs, contacts, and more.

Read more →

Fake Google Meet updates are turning a single click into device enrollment

A recent report says a fake Meet update page can push users into attacker-controlled device management without starting with a password prompt.

Read more →

Starbucks employee breach shows how phishing against HR portals turns into identity risk

Nearly 900 Starbucks employees were reportedly affected after phishing sites impersonated the company's HR portal. Here is why HR logins are such a high-value target.

Read more →

The browser has become the most overlooked security risk in everyday life

Why ordinary users and teams keep getting hurt by browser-level risk, and why the modern web is very good at looking trustworthy while doing something dangerous underneath.

Read more →

A CAPTCHA told me to press Win+R. Is it a virus?

Fake verification pages are increasingly telling users to paste commands into Run or PowerShell. Here is why that is dangerous and what to do if you already did it.

Read more →

Why do sites ask you to click Allow notifications?

A lot of scam pages only want one thing from you: notification permission. Here is what happens after that click and how to undo it.

Read more →

I scanned a QR code. Now what?

A practical response guide for suspicious QR scans, including what matters if you only opened the page, entered a password, or made a payment.

Read more →

Why a phishing site can look safe on desktop but not on phone

Mobile screens hide context attackers want you to miss. Here is why suspicious pages often feel more convincing on phones.

Read more →

Can a browser extension steal my login session?

Why extension permissions matter more than most users think, and how session theft risk fits into the broader browser-security picture.

Read more →

Why phishing pages look real now

Modern phishing pages are built to feel familiar in the first two seconds. Here is why they work and what still gives them away.

Read more →

How to spot a phishing email that looks legitimate

Polished phishing emails are the dangerous ones. Learn the signs that still matter when a message looks professional.

Read more →

Why browser warnings often come too late

Why a dangerous page can still look normal before any browser warning appears, and why attackers rely on that delay.

Read more →

What can go wrong on public Wi-Fi even with HTTPS

The lock icon helps, but it does not eliminate every risk on public Wi-Fi. Here is what still matters.

Read more →

How to tell if a Microsoft 365 login page is fake

One stolen Microsoft 365 login can expose an entire workday. Here is what to check before entering your password.

Read more →

What to do after a phishing attack — step-by-step damage control

You clicked the link. You entered your password. Now what? A step-by-step guide to limiting the damage — from changing passwords to freezing accounts.

Read more →

How to check if a website is safe — 7 things to look for

Before you enter your password, check these 7 things. Most phishing pages fail at least two of them — if you know what to look for.

Read more →

Is localStorage safe for tokens? Here's the honest answer.

If you're storing JWTs in localStorage, every script on the page can read them. That's not a bug — it's how localStorage was designed. Here's why it matters and what to do instead.

Read more →

What are API key leaks?

API keys are the passwords of the modern web. When they leak, attackers get direct access to your cloud infrastructure, payment systems, and user data. Here's everything you need to know.

Read more →

I clicked a phishing link — what do I do now?

What to do next depends on what happened: whether you only clicked, entered a password, shared payment details or downloaded a file. A step-by-step triage.

Read more →

How to remove fake virus popups that keep coming back

Still getting the warning after a virus scan? It is almost always a site allowed to send notifications. Exact steps for Chrome, Edge, Firefox, Safari, Android and iPhone.

Read more →

How to protect elderly parents from online scams

A practical guide to protecting elderly parents from phishing, tech support scams and fake virus popups — without being condescending about it.

Read more →

Guides & resources

Comparison hub

PhishClean comparisons

All comparison pages in one crawlable hub for buyers and researchers.

Threat guide

Phishing attacks

How phishing works, real examples, and how to protect yourself.

Threat guide

SSL stripping attacks

How HTTPS gets silently downgraded and why HSTS isn't enough.

Threat guide

Formjacking attacks

Invisible card skimmers injected into legitimate checkout pages.

Threat guide

Hidden iframe attacks

Clickjacking, credential theft, and crypto mining via invisible iframes.

Comparison

PhishClean vs Chrome Safe Browsing

20 on-device checks alongside Google's blocklist.

Comparison

PhishClean vs Malwarebytes Browser Guard

Page analysis vs blocklist blocking — detailed breakdown.

Comparison

PhishClean vs Microsoft Defender Browser Protection

Page analysis compared with reputation and enterprise-friendly protection.

Comparison

PhishClean vs Norton Safe Web

Site reputation vs live browser-side analysis of phishing behavior.

Feature

Secret Leak Scanner

Detect exposed API keys and credentials on any web page.

Feature

JWT token leak detection

Catch leaked session tokens before attackers can use them.

Feature

HTTPS downgrade detection

Catch silent protocol downgrades from HTTPS to HTTP.

Feature

Hidden iframe detection

Find invisible iframes used for credential theft and clickjacking.

Threat guide

Session hijacking

How attackers steal active sessions and what you can do about it.

Threat guide

Credential stuffing

Why reused passwords turn one breach into dozens.

Comparison

PhishClean vs uBlock Origin

Ad blocking vs phishing detection — different tools, different jobs.

Comparison

PhishClean vs McAfee WebAdvisor

Download and destination warnings versus on-page phishing analysis.

Comparison

PhishClean vs Avira Browser Safety

Safe-search reputation help versus local browser threat analysis.

Last updated: