Tag: phishing
-
Got a Microsoft Teams invite? Storm-2372 gang exploit device codes in global phishing attacks
Security experts have warned that a cybercriminal group has been running a malicious and inventive phishing campaign since August 2024 to break into organizations across Europe, North America, Africa, and the Middle East. First seen on tripwire.com Jump to article: www.tripwire.com/state-of-security/microsoft-teams-storm-2372-exploit-device-codes
-
Immer mehr Ransomware-Bedrohungen in SaaS-Umgebungen
Ransomware ist und bleibt eines der höchsten Risiken für Unternehmen. Laut Aussagen von Security-Experten sind knapp 60 Prozent der Unternehmen Opfer eines Ransomware-Angriffs Tendenz steigend. Nach Angaben von Microsoft haben Cyber-Bedrohungen, die es auf SaaS-Umgebungen abgesehen haben, stark zugenommen. Demnach wurden 7.000 Passwort-Angriffe pro Sekunde blockiert (allein in Entra ID) und Phishing-Attacken sind um 58 […]…
-
Betrügerische Mails sind immer schwerer zu durchschauen
Phishing-Mails sind eine weit verbreitete Betrugsmasche, bei der Cyberkriminelle die Namen großer Unternehmen wie Sparkasse, Postbank, Telekom oder PayPal missbrauchen, um ahnungslose Nutzer:innen in eine Falle zu locken. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/betruegerische-mails-sind-immer-schwerer-zu-durchschauen
-
Password managers under increasing threat as infostealers triple and adapt
Tags: access, attack, authentication, automation, breach, ceo, cloud, credentials, crypto, cyber, cybercrime, cybersecurity, dark-web, data, data-breach, defense, email, encryption, exploit, finance, hacker, identity, intelligence, least-privilege, login, malicious, malware, mfa, password, phishing, ransomware, risk, service, switch, tactics, theft, threat, tool, vulnerability, zero-trustMalware-as-a-service infostealers: For example, RedLine Stealer is specifically designed to target and steal sensitive information, including credentials stored in web browsers and other applications. It is often distributed through phishing emails or by tricking prospective marks into visiting booby-trapped websites laced with malicious downloaders.Another threat comes from Lumma stealer, offered for sale as a malware-as-a-service,…
-
Sicherheitskultur als Antwort – So wehren Unternehmen sich gegen KI-gestützte Phishing-Angriffe
First seen on security-insider.de Jump to article: www.security-insider.de/ki-phishing-techniken-und-ihre-folgen-a-562a18dd955d3e7c52b7349d3124ad48/
-
Fake Timesheet Report Emails Linked to Tycoon 2FA Phishing Kit
Cybersecurity researchers have uncovered a novel phishing campaign distributing the notorious Tycoon 2FA phishing kit through fraudulent timesheet notification emails, marking a concerning evolution in multi-layered credential theft operations. The operation utilizes Pinterest’s visual bookmarking service as an intermediary redirector, demonstrating attackers’ increasing sophistication in bypassing traditional email security filters. Campaign Mechanics and Delivery Vector…
-
Cyberbedrohungen im Jahr 2025: Wie KI Phishing-Taktiken verändert
Die Fortschritte innerhalb der künstlichen Intelligenz (KI) haben das Erscheinungsbild von Phishing-E-Mails drastisch verändert. Noch bis vor kurzem gab es einige Indikatoren, an denen man Phishing-Versuche recht zuverlässig erkennen konnte: inkorrekte Grammatik, Logos in schlechter Auflösung, allgemein gehaltene/generische Begrüßungsformeln und unpassender Kontext. Dank KI erstellen Cyberkriminelle mittlerweile hochkomplexe und personalisierte Angriffe, die sehr viel schwerer……
-
Storm-2372: Russian-Linked Hackers Exploit Device Code Phishing in Global Campaign
Microsoft Threat Intelligence has uncovered an active and ongoing phishing campaign conducted by the threat actor Storm-2372, a First seen on securityonline.info Jump to article: securityonline.info/storm-2372-russian-linked-hackers-exploit-device-code-phishing-in-global-campaign/
-
Why is DMARC Important? [2025 Updated]
Learn why DMARC is important for blocking phishing, securing your domain, and ensuring email deliverability in 2025. Stay compliant and protected. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/02/why-is-dmarc-important-2025-updated/
-
Privacy Roundup: Week 7 of Year 2025
Tags: access, antivirus, api, apple, attack, breach, business, cctv, cve, cybersecurity, data, data-breach, detection, email, exploit, firmware, flaw, google, group, law, leak, malware, microsoft, military, network, password, phishing, privacy, router, scam, service, software, technology, threat, tool, update, virus, vpn, vulnerability, windows, zero-dayThis is a news item roundup of privacy or privacy-related news items for 9 FEB 2025 – 15 FEB 2025. Information and summaries provided here are as-is for warranty purposes. Note: You may see some traditional “security” content mixed-in here due to the close relationship between online privacy and cybersecurity – many things may overlap;…
-
DEF CON 32 Evading Modern Defenses When Phishing With Pixels
Authors/Presenters: Melvin Langvik Our sincere appreciation to DEF CON, and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/02/def-con-32-evading-modern-defenses-when-phishing-with-pixels/
-
Russian State Hackers Target Organizations With Device Code Phishing
Russian hackers have been targeting government, defense, telecoms, and other organizations in a device code phishing campaign. The post Russian State Hackers Target Organizations With Device Code Phishing appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/russian-state-hackers-target-organizations-with-device-code-phishing/
-
âš¡ THN Weekly Recap: Google Secrets Stolen, Windows Hack, New Crypto Scams and More
Welcome to this week’s Cybersecurity News Recap. Discover how cyber attackers are using clever tricks like fake codes and sneaky emails to gain access to sensitive data. We cover everything from device code phishing to cloud exploits, breaking down the technical details into simple, easy-to-follow insights.âš¡ Threat of the WeekRussian Threat Actors Leverage Device Code…
-
Hacker greifen Microsoft 365 mit Device Code Phishing an
Eine mutmaßlich russische Hackergruppe namens Storm-237 hat eine Phishing-Kampagne gestartet, die sich gezielt gegen Microsoft 365-Konten richtet. Die Angreifer nutzen dabei eine eigentlich für Geräte ohne Tastatur gedachte Authentifizierungsmethode aus, wie Microsoft nun berichtet. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/hacker-greifen-microsoft-365-mit-device-code-phishing-an
-
Astaroth Phishing Kit Bypasses 2FA, Steals Accounts
Cybersecurity researchers at SlashNext have discovered a sophisticated new phishing kit dubbed >>Astaroth
-
Fake ‘Adobe Drive X’ App Sneaks Through Microsoft Login to Steal Credentials
Cofense’s Phishing Defense Center (PDC) has uncovered a phishing campaign that uses a legitimate Microsoft login page to First seen on securityonline.info Jump to article: securityonline.info/fake-adobe-drive-x-app-sneaks-through-microsoft-login-to-steal-credentials/
-
Storm-2372 used the device code phishing technique since August 2024
Russia-linked group Storm-2372 used the device code phishing technique since Aug 2024 to steal login tokens from governments, NGOs, and industries. Microsoft Threat Intelligence researchers warn that threat actor Storm-2372, likely linked to Russia, has been targeting governments, NGOs, and various industries across multiple regions since August 2024. The attackers employ a phishing technique called…
-
Microsoft 365 accounts targeted in device code spear-phishing scheme
First seen on scworld.com Jump to article: www.scworld.com/news/microsoft-365-accounts-targeted-in-device-code-spear-phishing-scheme
-
Phishing-Mails AOK Rückzahlung: Vorsicht vor dieser neuen Masche
Phishing-Mails verheißen eine AOK-Rückzahlung über eine größere Geldsumme. Hinter dem unerwarteten Geldregen steckt jedoch Phishing-Betrug. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/online-betrug/phishing-mails-aok-rueckzahlung-vorsicht-vor-dieser-neuen-masche-310335.html
-
Hackers steal emails in device code phishing attacks
An active campaign from a threat actor potentially linked to Russia is targeting Microsoft 365 accounts of individuals at organizations of interest using device code phishing. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-hackers-steal-emails-in-device-code-phishing-attacks/
-
Scammers Exploit JFK Files Release with Malware and Phishing
Veriti Research reported a developing cyber threat campaign centred around the declassification and release of the RFK, MLK… First seen on hackread.com Jump to article: hackread.com/scammers-exploit-jfk-files-release-malware-phishing/
-
Russian Hackers Target Microsoft 365 Accounts with Device Code Phishing
Volexity highlighted how Russian nation-state actors are stealing Microsoft device authentication codes to compromise accounts First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/russian-microsoft-device-code/
-
Raffinierte Phishing-Kampagne überzieht Deutschland
Es wird vor einer neuen, besonders raffinierten Phishing-Kampagne gewarnt, die gezielt Nutzer in Deutschland und Polen ins Visier nimmt. Ziel dieser Kampagne ist die Verbreitung unterschiedlicher Malware-Varianten, darunter eine neuartige Backdoor mit dem Namen ‘TorNet”. First seen on itsicherheit-online.com Jump to article: www.itsicherheit-online.com/news/cybersecurity/raffinierte-phishing-kampagne-ueberzieht-deutschland/
-
What is device code phishing, and why are Russian spies so successful at it?
Overlooked attack method has been used since last August in a rash of account takeovers. First seen on arstechnica.com Jump to article: arstechnica.com/information-technology/2025/02/russian-spies-use-device-code-phishing-to-hijack-microsoft-accounts/
-
CISO success story: How LA County trains (and retrains) workers to fight phishing
Tags: ai, awareness, breach, business, chatgpt, cio, ciso, cloud, compliance, computing, control, corporate, cybersecurity, data, dos, election, email, endpoint, government, hacker, healthcare, incident response, jobs, law, lessons-learned, malicious, marketplace, network, phishing, privacy, regulation, risk, risk-management, service, software, strategy, supply-chain, tactics, technology, threat, tool, training, vulnerability(The following interview has been edited for clarity and length.)At first glance, LA County’s reporting structure who reports to whom seems, well, fairly complex.We have a federated model: I report to the county CIO. Each department acts as an independent business and has its own department CIO and information security officer. Their job is to…
-
Sophisticated Phishing Campaign Abuses Webflow CDN to Steal Credit Card Data
A new report from Netskope Threat Labs has revealed a sophisticated phishing campaign that abuses the Webflow content First seen on securityonline.info Jump to article: securityonline.info/sophisticated-phishing-campaign-abuses-webflow-cdn-to-steal-credit-card-data/
-
Threat researchers spot ‘device code’ phishing attacks targeting Microsoft accounts
Suspected Russian nation-state threat groups have duped multiple victims into granting potentially persistent access to networks via authentication requests and valid tokens. First seen on cyberscoop.com Jump to article: cyberscoop.com/russia-threat-groups-device-code-phishing-microsoft-accounts/
-
If you dread a Microsoft Teams invite, just wait until it turns out to be a Russian phish
Roses aren’t cheap, violets are dear, now all your access token are belong to Vladimir First seen on theregister.com Jump to article: www.theregister.com/2025/02/15/russia_spies_spoofing_teams/

