Tag: phishing
-
Extensive credential theft conducted by new CoGUI phishing kit
First seen on scworld.com Jump to article: www.scworld.com/brief/extensive-credential-theft-conducted-by-new-cogui-phishing-kit
-
Phishing-Attacken mittels Missbrauch legitimer Web-Plattformen wie Google
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/phishing-attacken-missbrauch-google
-
38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases
Cybersecurity researchers have exposed what they say is an “industrial-scale, global cryptocurrency phishing operation” engineered to steal digital assets from cryptocurrency wallets for several years.The campaign has been codenamed FreeDrain by threat intelligence firms SentinelOne and Validin.”FreeDrain uses SEO manipulation, free-tier web services (like gitbook.io, webflow.io, and github.io First seen on thehackernews.com Jump to article:…
-
Japan orgs targeted by CoGUI phishing kit impersonating Amazon, Rakuten
People and organizations across Japan are being inundated with phishing messages from cybercriminals who are using CoGUI, a sophisticated toolkit that lets them avoid detection. First seen on therecord.media Jump to article: therecord.media/japan-orgs-targeted-by-cogui-phishing
-
DHL-Masche: Betrüger plündern Konten von Zehntausenden Deutschen
Cyberkriminelle haben Zehntausende Menschen in Deutschland mit gefälschten DHL-Nachrichten getäuscht.Laut einer Recherche des Bayerischen Rundfunks (BR) hat eine internationale Betrügerbande Zehntausende Menschen in Deutschland mit Phishing-Nachrichten abgezockt. Die Täter sollen sich in Asien befinden und weltweit an Kreditkartendaten von knapp 900.000 Menschen gekommen sein davon 20.000 aus Deutschland. Dem Bericht zufolge wurden die Opfer hierzulande vor…
-
Phishing-Report Q1 2025 Interne Kommunikation am häufigsten missbraucht
Die Ergebnisse des Phishing-Reports Q1 2025 von KnowBe4 zeigen die betrügerischsten E-Mail-Betreffzeilen, auf die Benutzer in Phishing-Simulationen klicken, und machen deutlich, dass E-Mails mit HR- und IT-Bezug mehr als 60 Prozent der am häufigsten angeklickten Phishing-E-Mails ausmachen. Alle Daten in diesem Bericht wurden der KnowBe4-HRM+-Plattform zwischen dem 1. Januar 2025 und dem 31. März 2025…
-
MirrorFace Targets Japan and Taiwan with ROAMINGMOUSE and Upgraded ANEL Malware
The nation-state threat actor known as MirrorFace has been observed deploying malware dubbed ROAMINGMOUSE as part of a cyber espionage campaign directed against government agencies and public institutions in Japan and Taiwan.The activity, detected by Trend Micro in March 2025, involved the use of spear-phishing lures to deliver an updated version of a backdoor called…
-
How Escape Enabled Deeper Business Logic Testing for Arkose Labs
Arkose Labs is a global cybersecurity company that specializes in account security, including bot management, device ID, anti-phishing and email intelligence. Its unified platform helps the world’s biggest enterprises across industries, including banking, gaming, e-commerce and social media, protect user accounts and digital ecosystems from malicious automation, credential First seen on securityboulevard.com Jump to article:…
-
UK government websites to replace passwords with secure passkeys
Government websites are to replace difficult-to-remember passwords with highly secure passkeys that will protect against phishing and cyber attackers First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366623776/UK-government-websites-to-replace-passwords-with-secure-passkeys
-
How To Secure Digital Wallets from Phishing Attacks
Digital wallets have become increasingly popular, offering users an easy way to make payments, store cryptocurrencies, and manage their money. But as more people use digital wallets, the risk of cyber threats, especially phishing attacks, has also grown. Phishing is a trick used by hackers to steal sensitive information like passwords and financial details. This…
-
KnowBe4 veröffentlicht Phishing-Report Q1 2025: Interne Kommunikation bleibt Schwachstelle
Der Bericht unterstreicht die anhaltende Bedrohung durch in E-Mails eingebettete Phishing-Links, die nach wie vor eine Hauptangriffstaktik darstellen. Die Analyse zeigt, dass die Befragten eher auf Links klicken, die sich auf interne Themen beziehen First seen on infopoint-security.de Jump to article: www.infopoint-security.de/knowbe4-veroeffentlicht-phishing-report-q1-2025-interne-kommunikation-bleibt-schwachstelle/a40705/
-
Neuer Phishing-Trick: Microsoft Dynamics 365 Customer Voice täuscht Kunden
Eine neu entdeckte Phishing-Kampagne nutzt Microsoft Dynamics 365 Customer Voice aus, um betrügerische E-Mails zu versenden. Check Point warnt vor gefälschten Umfrage-Links, die täuschend echt wirken und sensible Daten stehlen sollen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/dynamics-365-customer-voice
-
‘CoGUI’ Phishing Kit Helps Chinese Hackers Target Japan
Japan is being peppered with an overwhelming volume of spam, thanks to a new platform popular across the East China Sea. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/cogui-phishing-kit-chinese-hackers-japan
-
CoGUI phishing platform sent 580 million emails to steal credentials
A new phishing kit named ‘CoGUI’ sent over 580 million emails to targets between January and April 2025, aiming to steal account credentials and payment data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cogui-phishing-platform-sent-580-million-emails-to-steal-credentials/
-
Ongoing Passkey Usability Challenges Require ‘Problem-Solving’
While passkeys offer enhanced security against phishing and credential theft, implementation hurdles, cross-platform inconsistencies, and user experience challenges pose significant barriers to widespread adoption. First seen on darkreading.com Jump to article: www.darkreading.com/identity-access-management-security/passkey-usability-challenges-require-problem-solving
-
Popular Instagram Blogger’s Account Hacked to Phish Users and Steal Banking Credentials
A high-profile Russian Instagram blogger recently fell victim to a sophisticated cyberattack, where scammers hijacked her account to orchestrate a fake $125,000 cash giveaway. The attackers employed advanced techniques, including AI-generated deepfake videos and meticulously crafted phishing campaigns, to deceive followers into surrendering sensitive banking information. This incident highlights the growing threat of cyber fraud…
-
Ongoing Passkey Usability Challenges Require ‘Problem Solving’
While passkeys offer enhanced security against phishing and credential theft, implementation hurdles, cross-platform inconsistencies, and user experience challenges pose significant barriers to widespread adoption. First seen on darkreading.com Jump to article: www.darkreading.com/identity-access-management-security/passkey-usability-challenges-require-problem-solving
-
Darcula PhaaS: 884,000 Credit Card Details Stolen from 13 Million Global User Clicks
The Darcula group has orchestrated a massive phishing-as-a-service (PhaaS) operation, dubbed Magic Cat, compromising an estimated 884,000 credit card details from over 13 million user interactions worldwide. This smishing (SMS phishing) campaign, first detected in December 2023, impersonates trusted brands like the Norwegian Postal Service to lure victims into divulging sensitive information. Sophisticated Phishing-as-a-Service Operation…
-
Darcula Phishing as a Service Operation Snares 800,000+ Victims
Prolific PhaaS operation Darcula uses Magic Cat software to steal over 800,000 cards in a seven-month period First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/darcula-phishing-as-a-service/
-
Top tips for successful threat intelligence usage
Tags: ai, attack, automation, cloud, computing, data, ddos, detection, exploit, firewall, group, guide, incident response, infosec, infrastructure, intelligence, law, mitigation, network, phishing, siem, skills, soar, software, threat, tool, update, vulnerability, vulnerability-managementMake sure you don’t have more intel than you need: Next is the matching phase: the most sophisticated TIP may be overkill if you have a small infosec department with limited skills or have a relatively simple computing environment. According to this 2025 report from Greynoise, threat feeds must match your own environment in terms…
-
Phishing-Tests: Bereits über 90 Prozent halten diese für sinnvoll
Tags: phishingFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/phishing-tests-90-prozent-bewertung-sinnhaftigkeit
-
Luna Moth extortion hackers pose as IT help desks to breach US firms
The data-theft extortion group known as Luna Moth, aka Silent Ransom Group, has ramped up callback phishing campaigns in attacks on legal and financial institutions in the United States. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/luna-moth-extortion-hackers-pose-as-it-help-desks-to-breach-us-firms/
-
‘Venom Spider’ Targets Hiring Managers in Phishing Scheme
Researchers from Arctic Wolf Labs detailed a new spear-phishing campaign that targets hiring managers and recruiters by posing as a job seeker. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/venom-spider-phishing-scheme
-
Darcula PhaaS steals 884,000 credit cards via phishing texts
The Darcula phishing-as-a-service (PhaaS) platform stole 884,000 credit cards from 13 million clicks on malicious links sent via text messages to targets worldwide. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/darcula-phaas-steals-884-000-credit-cards-via-phishing-texts/
-
Darcula PhaaS steals 884,000 credit cards via SMS phishing texts
The Darcula phishing-as-a-service (PhaaS) platform stole 884,000 credit cards from 13 million clicks on malicious links sent via text messages to targets worldwide. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/darcula-phaas-steals-884-000-credit-cards-via-sms-phishing-texts/

