Tag: phishing
-
Phishing campaign in Poland and Germany deploys TorNet backdoor
First seen on scworld.com Jump to article: www.scworld.com/brief/phishing-campaign-in-poland-and-germany-deploys-tornet-backdoor
-
Devil-Traff: A New Bulk SMS Platform Driving Phishing Campaigns
Employees in most organizations receive countless communications daily”, emails, Slack messages, or ticket updates, for example. Hidden among these routine interactions are phishing scams designed to exploit trust and compromise security. Imagine an employee receiving a text that appears to be from their bank: “Suspicious activity detected on your account. Click here to secure your…
-
Hackers Exploit OAuth 2.0 Code Flow Using AiTM Attack on Microsoft Azure AD
Security enthusiasts and professionals are turning their focus towards a new angle on phishing attacks in the identity and access management space. During the >>Offensive Entra ID (Azure AD) and Hybrid AD Security
-
Threat Actors Exploit Government Website Vulnerabilities for Phishing Campaigns
Cofense Intelligence has continually observed the abuse or usage of legitimate domain service exploitation. This report highlights observed phishing threat actor abuse of .gov top-level domains (TLDs) for different countries over two years from November 2022 to November 2024. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/01/threat-actors-exploit-government-website-vulnerabilities-for-phishing-campaigns/
-
Clutch grabs $20M to build out its non-human security ID platform
When it comes to the world of cybersecurity, identity is often thought of as a “perimeter” around an organization. So many breaches begin through techniques like password theft, phishing, and credential stuffing; ergo, securing the identities of not only users, but also applications and machines, is the key to securing the whole system. Easier said…
-
Threat Actors Exploit Government Websites for Phishing
Cybercriminals exploit government websites using open redirects and phishing tactics, bypassing secure email gateway protections First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/threat-actors-exploit-gov-websites/
-
New phishing campaign targets users in Poland and Germany
An ongoing phishing campaign, presumably by an advanced persistent threat (APT) actor, is seen dropping a new backdoor on victim systems enabling stealthy C2 operations.The backdoor, which Cisco’s Talos Intelligence Unit is tracking as TorNet, was found connecting victim machines to the decentralized and anonymizing TOR network for C2 communications.”Cisco Talos discovered an ongoing malicious…
-
EBombing und Voice Phishing – Cyberangreifer missbrauchen Microsoft Teams
First seen on security-insider.de Jump to article: www.security-insider.de/-cyberkriminalitaet-microsoft-teams-schadsoftware-angriff-a-8da06486510c1a7322bc275a4f0f765f/
-
Malicious PDFs Used in Large-Scale Phishing Operation
A new report from Fernando Ortega, a malware researcher at Zimperium, exposes an advanced phishing campaign targeting mobile First seen on securityonline.info Jump to article: securityonline.info/malicious-pdfs-used-in-large-scale-phishing-operation/
-
Premium Panel Phishing Toolkit Exposed: Two Years of Global Attacks
Intrinsec’s Cyber Threat Intelligence (CTI) team has uncovered a sophisticated phishing toolkit, named >>Premium Panel
-
Tax Season Cybersecurity Alert: Report Reveals Surge in Tax-Related Cyberattacks
Cybercriminals are capitalizing on the 2025 tax season with a wave of sophisticated phishing and malware campaigns, according First seen on securityonline.info Jump to article: securityonline.info/tax-season-cybersecurity-alert-report-reveals-surge-in-tax-related-cyberattacks/
-
Phishing Campaign Baits Hook With Malicious Amazon PDFs
In their discovery, researchers found 31 PDF files linking to these phishing websites, none of which have been yet submitted to VirusTotal. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/phishing-campaign-malicious-amazon-pdfs
-
Super Bowl LIX Could Be a Magnet for Cyberattacks
Concerns include everything from ransomware, malware, and phishing attacks on the game’s infrastructure to those targeting event sponsors and fans. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/super-bowl-lix-magnet-cyberattacks
-
Novel USPS-Spoofing Phishing Attack Relies On Malicious PDFs
First seen on scworld.com Jump to article: www.scworld.com/brief/novel-usps-spoofing-phishing-attack-relies-on-malicious-pdfs
-
TorNet Backdoor Exploits Windows Scheduled Tasks to Deploy Malware
Cisco Talos researchers have identified an ongoing cyber campaign, active since mid-2024, deploying a previously undocumented backdoor known as >>TorNet.
-
New TorNet Backdoor Exploits TOR Network in Advanced Phishing Attack
Advanced phishing campaign targets Poland and Germany, delivering Agent Tesla, Snake Keylogger and newly identified TorNet backdoor via… First seen on hackread.com Jump to article: hackread.com/tornet-backdoor-exploits-tor-network-phishing-attack/
-
PureCrypter Deploys Agent Tesla and New TorNet Backdoor in Ongoing Cyberattacks
A financially motivated threat actor has been linked to an ongoing phishing email campaign that has been ongoing since at least July 2024 specifically targeting users in Poland and Germany.The attacks have led to the deployment of various payloads, such as Agent Tesla, Snake Keylogger, and a previously undocumented backdoor dubbed TorNet that’s delivered by…
-
Microsoft Unveils Phishing Attack Protection for Teams Chat
Microsoft has taken a significant step toward enhancing cybersecurity by introducing a new phishing attack protection feature for Microsoft Teams. The feature aims to safeguard users from brand impersonation in chats initiated by external domains, a common tactic used by cybercriminals to launch phishing attacks. The new feature, which proactively alerts users to potential impersonation…
-
New Phishing Scam Targets Amazon Prime Membership to Steal Credit Card Data
A recent investigation has uncovered a sophisticated phishing campaign leveraging malicious PDF files to redirect unsuspecting users to fake Amazon-branded phishing websites. Researchers from Unit 42 reported that this campaign utilizes PDFs containing embedded links as an initial lure to compromise users and steal sensitive information such as login credentials and credit card details. Attack…
-
US takes aim at healthcare cybersecurity with proposed HIPAA changes
Tags: access, authentication, best-practice, breach, compliance, control, csf, cyber, cyberattack, cybersecurity, data, defense, detection, dora, encryption, finance, framework, government, group, healthcare, HIPAA, incident response, infrastructure, insurance, intelligence, jobs, law, malware, mfa, network, nist, penetration-testing, phishing, privacy, ransom, ransomware, regulation, resilience, risk, security-incident, service, skills, technology, threat, tool, update, usa, vulnerability, vulnerability-managementThe US Department of Health and Human Services (HHS) has launched a consultation on stricter rules for the safeguarding of electronic health records.The proposed revamp of security rules covered by the Health Insurance Portability and Accountability Act (HIPAA) is designed to address the increased risk from cyberattacks such as ransomware against healthcare environments.The revamped rules…
-
What Makes This “Data Privacy Day” Different?
Tags: access, ai, attack, breach, business, cloud, data, data-breach, finance, identity, infrastructure, malware, monitoring, phishing, privacy, ransomware, risk, scam, threat, tool, training, vulnerabilityAs we celebrate Data Privacy Day, Bernard Montel, Tenable’s EMEA Technical Director and Security Strategist, wants to remind us that we live in a digital world and that we need to protect it. With data breaches a daily occurrence, and AI changing the playing field, he urges everyone to “do better.” Launched in April 2006…
-
New Phishing Trend: Generic Pages Impersonate Any Brand
The CloudSEK Threat Research Team has revealed a new trend in phishing campaigns”, generic phishing pages capable of impersonating First seen on securityonline.info Jump to article: securityonline.info/new-phishing-trend-generic-pages-impersonate-any-brand/
-
In Gaming Item Scams and How to Avoid Them?
The popularity of the TF2 gaming and trading scene attracts scammers with phishing, fake trades, and malicious tools…. First seen on hackread.com Jump to article: hackread.com/in-gaming-item-scams-and-how-to-avoid-them/
-
Privacy Roundup: Week 4 of Year 2025
Tags: access, ai, apt, attack, backup, botnet, breach, cctv, cve, cybersecurity, data, data-breach, detection, email, exploit, firmware, flaw, google, group, identity, infrastructure, korea, lazarus, leak, login, malicious, malware, north-korea, phishing, phone, privacy, regulation, remote-code-execution, risk, router, scam, service, software, startup, technology, threat, tool, update, virus, vulnerability, windowsThis is a news item roundup of privacy or privacy-related news items for 19 JAN 2025 – 25 JAN 2025. Information and summaries provided here are as-is for warranty purposes. Note: You may see some traditional “security” content mixed-in here due to the close relationship between online privacy and cybersecurity – many things may overlap;…
-
Hackers Use Malicious PDFs, pose as USPS in Mobile Phishing Scam
A large-scale phishing campaign is using PDF files and hidden malicious links, as well as posing at the U.S. Postal Service, in phishing campaign targeting mobile device users in hope that victims will divulge credentials and personal information, Zimperium researchers say. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/01/hackers-use-malicious-pdfs-pose-as-usps-in-mobile-phishing-scam/
-
Hidden in Plain Sight: PDF Mishing Attack
As part of our ongoing mission to identify emerging threats to mobile security, our zLabs team has been actively tracking a phishing campaign impersonating the United States Postal Service (USPS) which is exclusively targeting mobile devices. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/01/hidden-in-plain-sight-pdf-mishing-attack/
-
Microsoft Teams phishing attack alerts coming to everyone next month
Microsoft reminded Microsoft 365 admins that its new brand impersonation protection feature for Teams Chat will be available for all customers by mid-February 2025. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-teams-phishing-attack-alerts-coming-to-everyone-next-month/
-
Hidden Text Salting Disrupts Brand Name Detection Systems
A new phishing tactic has been identified by Cisco Talos, using hidden text salting to evade email security measures First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hidden-text-salting-disrupts-brand/
-
Royal Mail SMS Phishing Scam Targets Victims with Fake Delivery Fee Requests
Beware of a convincing Royal Mail SMS phishing scam asking for personal details and payment for re-delivery. Learn… First seen on hackread.com Jump to article: hackread.com/royal-mail-sms-phishing-scam-fake-delivery-fee-requests/

