Tag: phishing
-
Über 1000 verseuchte Domains zu den Amazon-Prime-Deal-Days
Check Point Research (CPR), die Sicherheitsforschungs-abteilung von Check Point Software Technologies, hat vor den Amazon-Prime-Deal-Days am 6. und 7. Oktober betrügerische Domains und Phishing-Kampagnen im Zusammenhang mit den Angebotstagen entdeckt. CPR beobachtete seit Juli einen stetigen Anstieg neu registrierter Domains im Zusammenhang mit den Stichwörtern ‘Amazon” und ‘Prime Day”. In den letzten drei Monaten sind neu…
-
5th October Threat Intelligence Report
Arizona’s state court system has suffered a phishing-led cyberattack after an employee clicked a malicious link. Attackers copied backup files containing protective-order records and more than 150,000 Foster Care Review Board reports […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/5th-october-threat-intelligence-report/
-
Fake brand discounts on social media prey on shoppers’ fear of missing out
Cybercriminals are using fake discounts posted on Facebook and TikTok to lure shoppers to phishing sites that steal their payment card details and one-time passwords, Group-IB … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/05/milk-dragon-phishing-fake-discounts/
-
Cybersecurity Awareness Month “cannot be the strategy”: why awareness must become a year-round capability
Every October, security teams roll out refreshed training, posters and phishing simulations. But according to Rob Gregory, CISO at Optiv, organizations that treat the month as the centerpiece of their awareness efforts are missing the point. “I believe Cyber Awareness Month (CAM) is a valuable amplifier and another reminder about the importance we all play in an organization’s cybersecurity…
-
Star Blizzard Targets 100+ Organizations with Phishing and RedFlick Technique
Russian group Star Blizzard expands phishing campaigns with a new malware delivery RedFlick technique, using scheduled tasks to deliver the CosmicPulse backdoor. First seen on hackread.com Jump to article: hackread.com/star-blizzard-organizations-phishing-redflick-technique/
-
Attackers Abuse Legitimate ScreenConnect Client in Phishing Campaign to Gain Remote Access
Threat actors are increasingly bypassing conventional malware detection by abusing legitimate remote monitoring and management software instead of deploying custom implants. In a recent phishing operation, attackers delivered a genuine, digitally signed ConnectWise ScreenConnect client configured to establish remote access to infrastructure controlled by the operator. The message claimed that a payment of $5,745.65 had…
-
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations.The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at…
-
‘They call every week’: the phishing attacks targeting past victims
Scammers reuse personal details harvested from fake Esta websites and texts and calls can keep arriving for monthsWhen the British actor Lisa Riley was preparing to travel to the US last year, she applied online for an Esta so she would not need a visa. After finding the site through a Google search she filled…
-
Phishing Toolkit Taps Social Media Posts and Advertisements
Adversary-in-the-Middle Attacks Come Courtesy of Chinese-Language ‘Milk Dragon’ Kit. Want to amass more phishing scam victims? Offering targets soon-to-expire discounts on well-known consumer brand items is one of the strategies being practiced by subscribers to a Chinese-language, adversary-in-the-middle phishing toolkit called Nailong, aka Milk Dragon. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/phishing-toolkit-taps-social-media-posts-advertisements-a-33006
-
State-linked actor targets US AI policy experts in credential phishing campaigns
The China-linked espionage attacks were designed to gain insight into the country’s strategy and regulatory environment. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/state-linked-actor-us-ai-policy-experts-credential-phishing/831887/
-
Cyberangriff auf die Ludwig-Maximilians-Universität München
Vom Cyberangriff auf die Ludwig-Maximilians-Universität München sind rund 600.000 aktuelle und ehemalige Studierende betroffen. Sven Janssen, VP Sales DACH bei Sophos, ordnet ein, warum die eigentliche Gefahr jetzt erst kommt, etwa durch KI-gestützte Phishing-Angriffe auf Basis echter Daten, und was der Vorfall über die Cybersicherheit im gesamten Bildungswesen aussagt. Eine aktuelle Sophos-Umfrage unter 200 IT-Verantwortlichen…
-
Chinese spies impersonate White House, Anthropic figures to phish AI policy experts
A China-aligned espionage group has been posing as a former White House official and a prominent economist to get into the cloud accounts of AI policy experts in the US, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/
-
Milk Dragon Phishing Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA
A phishing-as-a-service operation dubbed Milk Dragon, also known as NaiLong, is abusing discount-themed Facebook and TikTok posts to steal payment-card data and intercept multi-factor authentication (MFA) challenges. Group-IB identified 258 phishing pages linked to the kit since October 2025, with victims across 66 countries. Rather than relying on classic delivery-failure notices, bank alerts, or account-lockout…
-
China-Linked TA419 Hackers Target US AI Policy Experts With Credential Phishing Attacks
Tags: ai, attack, china, control, credentials, cyber, hacker, infrastructure, intelligence, microsoft, phishing, regulation, threatA China-linked threat actor known as TA419 has targeted U.S. artificial intelligence policy specialists through highly customized credential-phishing operations. This campaign, which involves impersonation, adversary-in-the-middle infrastructure, and a modified Browser-in-the-Browser toolkit, aims to steal Microsoft 365 sessions. This activity indicates a focused effort to collect intelligence on individuals who influence U.S. AI regulation, export controls,…
-
Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
Two separate reports by cybersecurity companies highlight China-linked hacking operations, including a phishing campaign that impersonated Western experts. First seen on therecord.media Jump to article: therecord.media/china-linked-phishing-scheme-backdoor-taiwan
-
Cryptohack Roundup: $387M Bitget Hack
Also: Sentencing in $16M Phishing Case, Charges in $16M Fraud Case. This week, Bitget lost $387 million, hackers used famous personalities to make malicious extensions look legit, an American was sentenced in a $16 million phishing case, a Vietnamese man was charged for a $16 million scam and an old Magic Eden access left $5.7…
-
Cryptohack Roundup: $387M Bitget Hack
Also: Sentencing in $16M Phishing Case, Charges in $16M Fraud Case. This week, Bitget lost $387 million, hackers used famous personalities to make malicious extensions look legit, an American was sentenced in a $16 million phishing case, a Vietnamese man was charged for a $16 million scam and an old Magic Eden access left $5.7…
-
The Cyber Express Weekly Roundup: Renfe Confirms Breach, Australia Warns of Hijacked AI Keys, and Europol Sounds the Alarm on AI-Driven Crime
This weekly roundup covers a customer data breach at Spain’s national rail operator, an Australian government warning about attackers hijacking corporate AI services, a patient data theft from a Polish medical software platform, phishing campaigns that turn legitimate remote management tools against their victims, and a gathering of Europe’s police leaders focused on how AI…
-
AI policy circles targeted in China-linked phishing operation
Cybersecurity firm Proofpoint said TA419 impersonated officials and AI industry figures in an effort to gain access to cloud accounts held by U.S. think tank, university and legal-sector experts. First seen on cyberscoop.com Jump to article: cyberscoop.com/china-cyber-espionage-ta419-phishing-us-ai-policy-experts/
-
China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders
TA419 posed as AI policymakers and economists to phish US AI policy experts’ Microsoft 365 accounts First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ta419-impersonates-ai-experts-us/
-
CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer
CloudSyncD uses a fake Zoom installer to phish Mac passwords and launch a two-stage backdoor First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cloudsyncd-macos-backdoor-fake/
-
Many expect AI in the SOC to make entry jobs harder to get
A junior analyst in a security operations center, or SOC, has usually learned the job the slow way. You work the same phishing lure dozens of times, chase the same familiar … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/01/ai-soc-entry-jobs/
-
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises. First seen on hackread.com Jump to article: hackread.com/global-group-ransomware-winmerge-deploy-encryptor/
-
Russia’s Star Blizzard Ditches ClickFix to Widen Phishing Net
The APT actor is using a new tactic, dubbed RedFlick, against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/russia-star-blizzard-apt-ditches-clickfix-widen-phishing-net
-
RedFlick Uses Scheduled Tasks and Password-Protected Archives to Deploy CosmicPulse Backdoor
Russian state-linked threat actor Star Blizzard has expanded its cyberespionage operations in 2026 with a phishing and malware-delivery technique tracked by Microsoft as RedFlick. Microsoft Threat Intelligence reported that the group, which CISA attributes to Russia’s Federal Security Service (FSB) Center 18, conducted at least 13 phishing campaigns between January and August 2026. The activity…
-
Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters
The Russian state-backed hacking group Star Blizzard has expanded its phishing operations this year, using a new technique that makes it easier to infect victims with malware. First seen on therecord.media Jump to article: therecord.media/russia-hackers-ukraine-blizzard
-
Amazon Prime Phishing Scam Uses Fake Billing Alert to Steal Logins and Card Details
An Amazon Prime phishing campaign is using fake payment alerts to steal account logins, personal data and complete credit or debit card details from unsuspecting customers. First seen on hackread.com Jump to article: hackread.com/amazon-prime-phishing-fake-billing-steal-login-card/
-
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure.By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud First seen on thehackernews.com…

