Tag: phishing
-
Scammers Exploit JFK Files Release with Malware and Phishing
Veriti Research reported a developing cyber threat campaign centred around the declassification and release of the RFK, MLK… First seen on hackread.com Jump to article: hackread.com/scammers-exploit-jfk-files-release-malware-phishing/
-
Russian Hackers Target Microsoft 365 Accounts with Device Code Phishing
Volexity highlighted how Russian nation-state actors are stealing Microsoft device authentication codes to compromise accounts First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/russian-microsoft-device-code/
-
Russian-Linked Hackers Using ‘Device Code Phishing’ to Hijack Accounts
Microsoft is calling attention to an emerging threat cluster it calls Storm-2372 that has been attributed to a new set of cyber attacks aimed at a variety of sectors since August 2024.The attacks have targeted government, non-governmental organizations (NGOs), information technology (IT) services and technology, defense, telecommunications, health, higher education, and energy/oil and gas First…
-
Astaroth 2FA Phishing Kit Targets Gmail, Yahoo, Office 365, and Third-Party Logins
Tags: 2fa, authentication, credentials, cyber, cybercrime, cybersecurity, login, mfa, network, office, phishing, threatA new phishing kit named Astaroth has emerged as a significant threat in the cybersecurity landscape by bypassing two-factor authentication (2FA) mechanisms. First advertised on cybercrime networks in January 2025, Astaroth employs advanced techniques such as session hijacking and real-time credential interception to compromise accounts on platforms like Gmail, Yahoo, Office 365, and other third-party…
-
Device Code Phishing Attack Exploits Authentication Flow to Hijack Tokens
Tags: attack, authentication, cyber, defense, exploit, government, intelligence, microsoft, phishing, service, threatA sophisticated phishing campaign leveraging the device code authentication flow has been identified by Microsoft Threat Intelligence, targeting a wide range of sectors, including government, NGOs, IT services, and critical industries such as defense and energy. The campaign, attributed to a threat actor known as Storm-2372, has been active since August 2024 and is assessed…
-
New Phishing Kit Bypasses Two-Factor Protections
Astaroth Kit Offered for $2,000 on Telegram, Intercepts Authentication in Real Time. A new phishing kit called Astaroth bypasses two-factor authentication through session hijacking and real-time credential interception from services like Gmail, Yahoo, AOL and Microsoft 365. Acting as a man-in-the-middle, it captures login credentials, tokens and session cookies in real time. First seen on…
-
Immigration-themed Phishing Attack Uncovered
First seen on scworld.com Jump to article: www.scworld.com/brief/immigration-themed-phishing-attack-uncovered
-
Hackers Use CAPTCHA Trick on Webflow CDN PDFs to Bypass Security Scanners
A widespread phishing campaign has been observed leveraging bogus PDF documents hosted on the Webflow content delivery network (CDN) with an aim to steal credit card information and commit financial fraud.”The attacker targets victims searching for documents on search engines, resulting in access to malicious PDF that contains a CAPTCHA image embedded with a phishing…
-
Astaroth Phishing Kit Bypasses 2FA to Hijack Gmail and Microsoft Accounts
New Astaroth Phishing Kit bypasses 2FA (two-factor authentication) to steal Gmail, Yahoo and Microsoft login credentials using a… First seen on hackread.com Jump to article: hackread.com/astaroth-phishing-kit-bypasses-2fa-hijack-gmail-microsoft/
-
Phishing statt Liebe
Check Point Software Technologies hat über die letzten Jahre eine stetige Zunahme von Phishing-Betrug rund um den Valentinstag beobachtet und regelmäßig gewarnt. Auch in diesem Jahr nahm die Zahl neuer Domänen zu diesem Thema im Jahresvergleich zu und ebenso die Rate der betrügerischen Websites. Ende Januar 2025 deckte Check Point Research (CPR) eine Phishing-E-Mail-Kampagne […]…
-
Astaroth Phishing Kit Bypasses 2FA Using Reverse Proxy Techniques
Astaroth is an advanced phishing kit using real-time credential and session cookie capture to compromise Gmail, Yahoo and Office 365 accounts First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/astaroth-phishing-kit-bypasses-2fa/
-
Check Point Research warnt vor Phishing zum Valentinstag
Tags: phishingIm Januar 2025 beobachteten die Security-Forscher über 18 000 neue Websites zum Thema Liebe und Valentinstag, was einem Anstieg von 5 Prozent im Vergleich zum Vormonat entspricht. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/check-point-research-warnt-vor-phishing-zum-valentinstag/a39804/
-
New Phishing Attacks Abuses Webflow CDN CAPTCHAs to Steal Credit Card details
Tags: attack, captcha, credit-card, cyber, exploit, malicious, network, phishing, technology, threatNetskope Threat Labs has uncovered a sophisticated phishing campaign targeting users across various industries, including technology, manufacturing, and banking. This campaign, active since mid-2024, exploits search engine optimization (SEO) techniques to lure victims into downloading malicious PDFs hosted on the Webflow Content Delivery Network (CDN). These PDFs are embedded with fake CAPTCHA images that redirect…
-
Sprunghafter Anstieg von Phishing-Attacken mit SVG-Grafikdateien
Malware und Phishing, die über die beliebten und viel genutzten SVG-Grafik- und Bilddateien eingeschleust werden, erleben nach den Beobachtungen von Sophos X-Ops seit Januar 2025 einen rasanten Anstieg. In einem neuen Report von Sophos-X-Ops berichten die Sicherheitsexperten von einem sprunghaften Anstieg von Malware- und Phishing-Angriffen, die mit Hilfe von SVG-Dateien durchgeführt werden. Die Cyberkriminellen nutzen…
-
Phishing trotz Zwei-Faktor-Authentifizierung – Erfolgreiche Hacks trotz 2FA das können Unternehmen tun
First seen on security-insider.de Jump to article: www.security-insider.de/-phishing-methoden-zwei-faktor-authentifizierung-herausforderungen-unternehmen-a-f271964311ee60db02f7fc9e62ce5550/
-
WTF: ICANN Opfer von Phishing: Online-Konto für Kryptowährungs-Reklame missbraucht
“Die ICANN gibt dem Internet seine eigene Währung”, schallte es von einem offiziellen ICANN-Konto eines sozialen Netzes. Hinter “$DNS” stecken aber Kriminelle. First seen on heise.de Jump to article: www.heise.de/news/ICANN-Opfer-von-Phishing-Online-Konto-fuer-Kryptowaehrungs-Reklame-missbraucht-10280537.html
-
Cyberkriminelle nutzen SVG-Dateien für raffinierte Phishing-Angriffe
Laut Sophos X-Ops werden diese Angriffe zunehmend raffinierter. Cyberkriminelle optimieren ihre Methoden, um Phishing-Versuche noch überzeugender zu gestalten. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cyberkriminelle-nutzen-svg-dateien-fuer-raffinierte-phishing-angriffe/a39801/
-
Cybercriminals Exploit Valentine’s Day with Romance Scams, Phishing Attacks
As Valentine’s Day approaches, cybercriminals are ramping up their efforts to exploit consumers through romance scams, phishing campaigns and fraudulent e-commerce offers. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/02/cybercriminals-exploit-valentines-day-with-romance-scams-phishing-attacks/
-
Die wachsende Gefahr KI-gestützter Cyberangriffe
Die fortschreitende Integration künstlicher Intelligenz (KI) in das Arsenal von Cyberkriminellen stellt Unternehmen vor beispiellose Herausforderungen. Cyberkriminelle setzen KI ein, um Angriffe effizienter, präziser, agiler und schwerer erkennbar zu machen. Ein besonders besorgniserregender Trend ist der Einsatz von Phishing-as-a-Service-Plattformen, die mithilfe von KI täuschend echte Phishing-Kampagnen erstellen. Diese Plattformen, die gezielt gegen Dienste wie Microsoft-365…
-
Btmob RAT: A New Evolution of Android Malware Targets Users via Phishing Sites
A newly discovered Android malware, Btmob RAT, has been identified as a major threat to mobile users. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/btmob-rat/
-
Neue Malware-Variante ‘TorNet” arbeitet mit gefälschten Überweisungsbestätigungen
Forscher von Cisco Talos warnen vor einer neuen Phishing-Kampagne, die auf Nutzer in Deutschland und Polen abzielt, um verschiedene Arten von Malware zu verbreiten, darunter eine neue Backdoor namens ‘TorNet”. Die Phishing-Mails geben vor, gefälschte Überweisungsbestätigungen von Finanzinstituten oder gefälschte Auftragsbestätigungen von Produktions- und Logistikunternehmen zu sein. ‘Die Phishing-E-Mails sind hauptsächlich in polnischer und deutscher…
-
Facebook-Konten über Salesforce-Mailing-Dienst gehackt
Check Point Software Technologies Ltd. hat neue Sicherheitsforschungen zu Facebook abgeschlossen und eine massive Phishing-Kampagne aufgedeckt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/facebook-salesforce
-
West London Council Faces 20,000 Cyberattack Attempts Every Day Amid Growing Threats
A West London council has revealed that it is the target of around 20,000 attempted cyberattacks every day. Hammersmith and Fulham Council, one of the boroughs in the capital, is no stranger to the growing risks of digital security breaches. In response to these frequent cyber threats, the council has ramped up its defense mechanisms,…
-
Google Chrome’s Safe Browsing Now Protects 1 Billion Users Worldwide
Google’s Safe Browsing technology now ensures enhanced protection for over 1 billion Chrome users worldwide. Launched in 2005, Safe Browsing is a robust system designed to safeguard users from phishing, malware, scams, and other cyber threats. By leveraging advanced artificial intelligence (AI) and machine learning, this cutting-edge technology has become a cornerstone of web security,…
-
Global phishing campaign targets Facebook accounts
Tags: phishingFirst seen on scworld.com Jump to article: www.scworld.com/brief/global-phishing-campaign-targets-facebook-accounts
-
FacebookKampagne gegen Urheberrechtsverletzungen
Check Point Software Technologies hat neue Sicherheitsforschungen zu Facebook abgeschlossen. Die Plattform ist das beliebteste soziale Netzwerk der Welt und übertrifft laut Statista alle anderen Konkurrenten in Bezug auf Reichweite und aktive Nutzer. Außerdem ist Facebook laut Sprout Social die am dritthäufigsten besuchte Website nach Google und YouTube. Wenn also eine Phishing-Kampagne die Marke Facebook ausnutzt,…
-
Neue FacebookWelle bedroht Unternehmen
Die Angreifer nutzen den Mailing-Service von Salesforce für ihre Phishing-Mails, ohne gegen dessen Sicherheitsrichtlinien zu verstoßen. Die E-Mails werden mit der Absenderadresse noreply[ad]salesforce.com versendet, was ihre Echtheit vortäuscht. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/neue-facebook-phishing-welle-bedroht-unternehmen/a39749/
-
Hackers Exploit Valentine’s Day Domains for Sneaky Cyber Attacks
Cybercriminals are capitalizing on the season of love to launch sneaky and deceptive cyberattacks. According to the whoisxmlapi shared on the X, there has been a surge in the registration of Valentine’s Day-themed domains, many of which are likely being used to perpetrate phishing schemes and online fraud. Valentine’s Day is a time when individuals…
-
FinStealer Malware Targets Leading Indian Bank’s Mobile Users, Stealing Login Credentials
Tags: banking, credentials, credit-card, cyber, cybersecurity, finance, india, login, malware, mobile, phishing, threatA new cybersecurity threat has emerged, targeting customers of a prominent Indian bank through fraudulent mobile applications. Dubbed >>FinStealer,
-
Massive Facebook Phishing Attack Targets Hundreds of Companies for Credential Theft
A newly discovered phishing campaign targeting Facebook users has been identified by researchers at Check Point Software Technologies. The attack, which began in late December 2024, has already reached over 12,279 email addresses and impacted hundreds of companies globally. The campaign exploits Facebook’s massive user base recognized as the most popular social network worldwide and…

