Here are the 7 Golden Phool Rules to keep you safe from scammers.
Your bank is not going to call you. That's the takeaway lesson from an Oakland woman who received a fake call from her bank and lost her life savings.
WKYT Carolina
link
New phishing scam targets Apple Pay users
— One reason customers choose Apple is the company’s commitment to privacy and security. Scammers are exploiting that trust by posing as Apple and warning customers about fraudulent Apple Pay charges. They claim that unless the customer calls immediately, they could lose their money.
The Hacker News
link
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
— Microsoft's security team is warning about a phishing campaign, first spotted in early February 2026, that borrows a trick from the AI world and repurposes it for old-school spam filtering evasion.
The original technique, called ASCII smuggling, uses invisible Unicode "tag" characters (special characters that don't render or show up visually to a human reading the text) to hide content inside normal-looking messages. It first became known as a way to sneak hidden instructions to AI models, since a person looking at the text would see nothing unusual while an AI system processing the same text could pick up the concealed content.
What Microsoft found is a twist on that idea. Rather than hiding instructions for an AI, these attackers are using the same invisible characters to break up suspicious words, things like "funding", so that automated email filters can't recognize them as a whole word and flag the message as spam or phishing. Since the invisible characters don't display, the email still looks completely normal to the person reading it, but the "word" behind the scenes is now fragmented and unreadable to filters scanning for known phishing or financial-fraud keywords.
Microsoft's broader point is that this shows evasion techniques developed for tricking AI systems are migrating into ordinary phishing and spam campaigns, not just AI-specific attacks, and defenders should expect that crossover to continue.
Sources: Microsoft Security Blog: "ASCII Smuggling" crosses over from AI prompt injection to phishing evasion
AP News
link
Scam Victims Seek Help Only to get Victimized Again
— An AP/FRONTLINE investigation finds that online scams in the U.S. have reached record levels, but victims often receive little help from law enforcement, banks, or government agencies, and almost never recover their stolen money. Victims can face additional financial burdens such as fees and taxes after being scammed. Worst of all, victims looking for help sometimes find themselves the victims of new scams!
Atlanta News First
link
Phishing scams disguised as party invitations target email accounts
— ATLANTA, Ga. (Atlanta News First) - As weddings, end-of-summer and fall holiday gatherings fill calendars, federal investigators are warning that scammers are disguising phishing attempts as online invitations, messages that can look polished, name a familiar host and even appear to arrive from a friend’s real email address.
The Federal Trade Commission (FTC) has issued a consumer alert about unexpected messages impersonating well-known invitation platforms such as Evite and Paperless Post. The messages prompt recipients to enter an email address and password to view event details, or ask for a phone number and a one-time code to RSVP. The FTC said that is not how legitimate invitations work.
AL.com
link
FBI warns that clicking one link can give scammers full access to your email
— A new scam that starts with a legitimate login can give malicious cyber actors access to your email even after you’ve changed your password. According to a warning issued Tuesday by the FBI, the scam is known as “OAuth consent phishing” and is targeting people across the country.
OAuth is an often used and legitimate permission screen used by services like Google and Microsoft. The feature gives apps the ability to access a user’s data without the user providing sign-in credentials or a password.
Fast Company
link
4 devious email scams hitting inboxes right now, and how to spot them
— For the last decade, email scams have run rampant on the internet. And corporate IT departments have handed out the exact same advice like clockwork: Look for bad grammar, hover over links, and turn on two-factor authentication.
But those recommendations have fallen behind the times. Thanks to AI and clever architectural work-arounds, today’s email scams don’t look like scams. They don’t contain spelling errors. And in many cases, they don’t even care if you have 2FA enabled.
CNN-News18
link
Cyber Criminals Target World Cup Fans with Fake Ticket Sites
— With World Cup fever raging, cyber criminals have created fake ticket sales sites complete with duplicated logos, stadium details, game schedules, and even live-chat support. But once you pay, your money is gone with no ticket.
BBC
link
Traitors Star Loses Life Savings to a Scam
— Sam Little, a former contestant on the BBC show Traitors, lost his £40,000 life savings in an cryptocurrency scam that he calls "gut-wrenching". It all began with a few fake text messages.
Fast Company
link
The FBI just issued an urgent warning for anyone using Microsoft Teams, Outlook, or OneDrive over a new phishing scheme
— The security measure millions rely on to protect their accounts may not be as foolproof as they think.
The Federal Bureau of Investigation is warning the public about a fast-spreading scam targeting users of popular Microsoft 365 products, including Outlook, Teams, and OneDrive. The scheme allows cybercriminals to capture Microsoft authentication tokens, bypassing multifactor authentication without needing a user’s password.
NBC News
link
California woman dead in murder-suicide may have given thousands to a scammer claiming to be Tom Selleck
— On Thursday, the sheriff’s office said that Karen had been a victim of financial elder abuse and that officials believe the couple died in a murder-suicide. Authorities said there is no evidence that the unknown scammer or scammers were involved in the deaths, but that the incident remains under investigation.