The phishing simulation platform built by red teamers. Emulate real attacks. Measure resilience. ↓ Join the waitlist

We're officially introducing PhishCore. PhishCore helps organizations test, measure, and improve their defenses against phishing attacks using realistic simulations and security awareness training. We’re currently building the platform and have opened a waitlist for early adopters. If you’re interested, sign up for the waitlist: phishcore.io We’re building in public and will share more updates soon.
3
14
76
832,936
Can a Flipper Zero steal your credit card?
2
5
16,043
PhishCore™️ retweeted
YES Most successful CCTV hacks require factory default credentials. "admin/admin". "admin/12345". In 2025, Nozomi Networks found that default credential brute-forcing was the single leading attack technique across all IoT incidents they tracked. Hikvision cameras are used in airports, hospitals, government buildings, and millions of homes. they are also the cameras the US government just banned as a national security risk. the ban covers new imports. the cameras already installed are still running. Iranian-linked attackers targeted Hikvision and Dahua cameras across Israel and the Gulf in March 2026, timed to coincide with missile strikes. real-time reconnaissance. damage assessment. target selection. using cameras installed to provide security. What to do: — change default credentials the moment you set the system up. — never use port forwarding for remote access. use a VPN instead. — keep NVR and camera firmware updated. — disable UPnP on your router. — put cameras on a separate VLAN from your laptops and phones. — if you have Hikvision or Dahua equipment: check firmware versions against known CVEs regularly.
Can an attacker access a CCTV system remotely?
1
18
88
4,463
Can an attacker access a CCTV system remotely?
4
5,451
Can a smart plug become a gateway into your network?
1
2
2,786
Can a smart bulb be hacked?
1
13
146,935
PhishCore™️ retweeted
YES and NFC attacks just surged 188% in the first four months of 2026. What NFC is: Near Field Communication. The technology behind tap-to-pay, transport cards, and those square stickers on restaurant tables that open menus when you scan them. Range: about 4 centimeters. you have to physically tap or get very close. The simple attack: tag tampering An attacker replaces a legitimate NFC tag on a poster, restaurant table, parking meter, or public kiosk with their own. your phone taps it. instead of opening the menu or paying the parking, it opens a phishing site. you enter your card details. done. An NFC tag costs under $1. a Flipper Zero can read and clone most unlocked tags in seconds. no technical skill required. The advanced attack: NFC relay This is where it gets serious. Malware called NFCGate turns your phone into an NFC relay device. here's the chain: — you're tricked into installing a fake banking or security app — the app runs silently — when you tap your physical bank card to pay for something, the malware intercepts the NFC signal from your card — it transmits that signal in real time to an attacker's phone anywhere in the world — the attacker taps their phone to a payment terminal — the terminal thinks it's talking to your card — the transaction goes through You tapped to pay at a coffee shop, someone in another city just bought a laptop with your card. simultaneously. What to do: — never scan NFC tags in public unless you know exactly what they link to. preview the URL before opening. — never install apps from links sent via WhatsApp, SMS, or messaging apps. not even from people you know. — enable transaction notifications on your bank app. real-time alerts catch unauthorized charges immediately. — some card holders and phone cases block NFC signals. useful in crowded areas. — on iPhone: NFC only activates in specific contexts. the risk is lower. not zero. — on Android: check which apps have NFC permission. revoke anything that doesn't need it. the tap that takes a second and can cost you everything in your account.
Can an NFC tag be used for phishing?
5
42
199
7,884
Can smart cameras be hacked?
1
6
4,686
Can an NFC tag be used for phishing?
3
9,109
PhishCore™️ retweeted
YES and it already has happened repeatedly. Your doorbell sits on the same WiFi network as your laptop, your phone, your NAS drive, and every other device in your home. it's also outside your house. exposed to anyone walking past with a laptop. Bitdefender found a high-severity vulnerability in Amazon Ring Video Doorbell Pro devices. An attacker standing near your home during the setup process could intercept an unencrypted network packet and steal your WiFi password. Smaller brands are worse. A $70 Ctronics doorbell was found sending your WiFi credentials unencrypted to Chinese servers. In 2025 a critical vulnerability in popular smart doorbell firmware allowed attackers to unlock doors remotely. the manufacturer released a patch but 67% of affected devices remained unpatched six months later because users didn't know updates were available. your doorbell from two years ago may be running firmware with a known vulnerability patched last month. you just never applied the update. Put your doorbell on a separate IoT VLAN or guest network. Change the default password on setup. Enable auto-updates and check manually every 90 days also avoid unbranded cheap doorbells entirely.
Can a smart doorbell become an entry point into a network?
20
145
591
39,628
Your smart doorbell is basically a tiny computer attached to the outside of your house It has a processor, memory, an operating system, Wi-Fi and usually a connection to the internet Which means it can have the same security problems as any other computer If an attacker finds a vulnerability in the doorbell and compromises it, they haven't necessarily stopped at the camera They now have a device sitting inside your network And that's where things can get interesting The attacker can use the compromised doorbell to discover what else is connected to the network Your laptop, NAS, printer, and other cameras Even network services that were never meant to be exposed to the internet The doorbell has effectively become a foothold This is one of the reasons security engineers don't like putting IoT devices on the same network as computers containing sensitive information A compromised smart bulb isn't nearly as interesting if it can only talk to other smart-home devices A compromised smart bulb that can reach your workstation is a very different problem So if you have a lot of smart devices at home, don't think of them as harmless appliances They're computers They're connected to your network And if one gets compromised, the attacker may already be inside your house
Can a smart doorbell become an entry point into a network?
1
3
14
1,130
Can a smart doorbell become an entry point into a network?
1
10
39,202
PhishCore™️ retweeted
YES and it's more likely than most people think. Your smart TV sits on the same network as your laptop, your phone, your NAS drive, your work computer most home networks have no segmentation everything can talk to everything. A smart TV is a Linux computer running Android or Tizen. It has a browser, app runtime, Bluetooth, WiFi, and in many cases a microphone and camera. it also has a notoriously poor security update cycle. A researcher found a Samsung TV in 2026 running security patches from 2019 on a device sold new. Once a TV is compromised the attacker has a foothold inside your network: — ARP scanning to map every device on your home network — man-in-the-middle attacks on unencrypted local traffic — lateral movement to routers, NAS drives, printers, and work laptops — credential theft from saved streaming service logins stored in the TV — botnet recruitment, your TV's processing power used for DDoS attacks or cryptomining without you knowing A documented CVE: CVE-2022-44636 affected certain Samsung TVs a Bluetooth spoofing vulnerability in the smart remote that could enable microphone access when the user pressed a button. Samsung patched specific firmware versions well not all users updated. the FBI issued a public warning about smart TV security in 2019. their specific concern: TV manufacturers and bad actors could exploit built-in cameras and microphones. they recommended covering cameras with black tape. what to actually do: — create a separate IoT network on your router (most modern routers support a guest network or VLAN). put your TV on that. it cannot reach your laptop or phone. — keep TV firmware updated. manually check — auto-update is not always reliable. — disable features you don't use: Bluetooth, microphone, camera if present. — if your TV has a camera: tape it. the FBI said so.
Can your smart TV be used to attack your home network?
28
168
873
58,524
PhishCore™️ retweeted
Well it depends... Johns Hopkins researchers published a paper called iSeeYou: Disabling the MacBook Webcam Indicator LED. they reprogrammed the webcam's firmware the small internal software running on the camera's own chip to operate the camera independently of the LED. Camera on. light off. The same paper noted the technique also enabled a virtual machine escape, allowing malware inside a VM to reprogram the camera to act as a USB keyboard and execute code on the host system. This was 2013. It was covered by the Washington Post and the New York Times. the technique still applies to any webcam where the LED is controlled by firmware rather than hardwired to the camera's power circuit. If the LED is hardwired to the camera's power, meaning it physically cannot receive power without the light also turning on. It cannot be bypassed by software. This is how most modern MacBooks and some newer laptops are designed. if the LED is firmware-controlled meaning software tells the light when to turn on it can potentially be decoupled from the camera itself. External USB webcams are the highest risk category. their firmware is often unsigned and flashable. A researcher demonstrated this on a ThinkPad X230 in 2024. What to do: — use a physical webcam cover. a piece of tape. a sliding cover. anything that physically blocks the lens. — for external webcams: unplug them when not in use. no firmware exploit works on a device with no power. — for built-in cameras: check if your laptop has a hardware privacy switch. Lenovo and some HP models include them.
Can a webcam be accessed without the camera light turning on?
4
10
79
4,882
🤯
They exposed data on 8.8 million people with no exploit, no malware, and no access to MAG’s servers. Three server-side API keys sat in public JavaScript for 4+ years and FulcrumSec found them. They could have modified and deleted data too. I verified how the Manchester Airports Group breach happened: scotthelme.co.uk/no-hacking-…
3
205
Can a webcam be accessed without the camera light turning on?
4
5,738
Can your smart TV be used to attack your home network?
1
2
9
72,274
Can your phone automatically connect to a malicious Wi-Fi network?
3
214
Always use your own cable, never a stranger's.
Can a charging cable steal data?
2
2
17
1,413
Can a charging cable steal data?
3
7
111,974
phishing is still the most common cyberattack method in 2026 because it's the only attack that scales infinitely and costs almost nothing. an attacker sends thosands of emails. one person clicks. the entire network is now at risk. phishing works because it exploits the same cognitive patterns in every person in every organization. urgency. authority. fear. reward. those are features of the human brain. And AI has removed the last signals people used to identify phishing. perfect grammar. perfect formatting. personalized to your name, your role, your manager's name, your vendor list. indistinguishable from legitimate. Pairing technical controls with behavior-based awareness training cuts phishing susceptibility by up to 75%. not knowledge-share. not annual compliance videos. behavior-based. simulated. repeated. fewer than 25% of employees remain susceptible after sustained simulation-based training.
Why is phishing still the most common method hackers use to carry out their attacks?
2
2
15
1,610