Tag: phishing
-
New Phishing Campaign Targets Mobile Devices with Malicious PDFs
A novel phishing campaign identified by Zimperium targets mobile users with malicious PDFs, impersonating USPS to steal credentials First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/phishing-campaign-targets-mobile/
-
Steuerung einer hybriden Authentifizierungs-Landschaft
Keeper Security veröffentlicht seinen aktuellsten Insight-Report ‘Navigating a Hybrid Authentication Landscape”. Der Report untersucht, wie sich die Strategien von Organisationen entwickeln, um sensible Daten und Identitäten zu sichern, angesichts einer stetig komplexeren digitalen Umgebung. Während sich die traditionelle Passwort-basierte Authentifizierung wachsenden Gefahren gegenübersieht, inklusive Phishing und Credential-Stuffing (Angreifer nutzen gestohlene Anmeldedaten für unberechtigte Zugänge zu Konten),…
-
Bösartiges WordPress-Plugin hilft, Zahlungsdaten zu stehlen
Cybersicherheitsexperten von Slashnext haben vor kurzem in einem Blogbeitrag ihren neuesten Fund aus einem russischen Cybercrime-Forum vorgestellt: das bösartige WordPress-Plugin . Das Phishing-Plugin ermöglicht es Angreifern, die Zahlungsdaten von Online-Shoppern abzugreifen unerkannt, in Echtzeit und mit erheblichem Schadenspotenzial. Zur Anwendung kommen kann es dabei sowohl in kompromittierten Websites regulärer E-Commerce-Unternehmen als auch in von […]…
-
DMARC Email Security: A Guide to Protecting Your Domain
Learn how DMARC email security can protect your brand, improve deliverability, and prevent phishing attacks. Get expert advice and best practices. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/01/dmarc-email-security-a-guide-to-protecting-your-domain/
-
New Phishing Framework Attack Multiple Brands Login Pages To Steal Credentials
Researchers have identified a sophisticated phishing tactic leveraging Cloudflare’s workers.dev, a free domain name service, to execute credential theft campaigns. The modus operandi involves a generic phishing page that can impersonate any brand, with significant technical ingenuity aimed at deceiving unsuspecting users and evading detection. The phishing page, hosted on the URL >>workers-playground-broken-king-d18b.supermissions.workers.dev,
-
Urteil: Google haftet bei betrügerischen Anzeigen als Störer nach dem DSA
Google muss als Betreiber von Google Ads von Dritten geschaltete Anzeigen überprüfen, um unzulässige, gemeldete Phishing-Versuche auch künftig zu unterbinden. First seen on heise.de Jump to article: www.heise.de/news/Urteil-Google-haftet-bei-betruegerischen-Anzeigen-als-Stoerer-nach-dem-DSA-10256590.html
-
Phishing Emails Targeting Australian Firms Rise by 30% in 2024
For the APAC region as a whole, credential phishing attacks rose by 30.5% between 2023 and 2024. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/phishing-email-attacks-rise-australia/
-
Mögliche Aldi-Talk-Phishing Mail oder legitim?
Nutzer von Aldi-Talk-Mobilfunktarifen (und Medion-Kunden) sollten aufpassen. Die könnten nun mit persönlich adressierten Phishing-Nachrichten, die Name und Kundennummer enthalten, konfrontiert zu werden. Oder der Anbieter hat seine IT-Prozesse nach der Umstellung in 2024 immer noch nicht im Griff. Anmerkung: Die … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/01/23/aldi-talk-phishing-nach-black-basta-ransomware-angriff-auf-medion/
-
GhostGPT: Uncensored Chatbot Used by Cyber Criminals for Malware Creation, Scams
Researchers from Abnormal Security discovered an advert for the chatbot on a cybercrime forum and tested its capabilities by asking it to create a DocuSign phishing email. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/what-is-ghostgpt/
-
BrandRanking aus dem vierten Quartal 2024
Check Point Research (CPR), die Threat-Intelligence-Abteilung von Check Point Software Technologies, hat sein aktuelles Brand-Phishing-Ranking für Q4 2024 veröffentlicht. Der Bericht hebt die Marken hervor, die von Cyberkriminellen am häufigsten nachgeahmt werden, um persönliche Informationen und Zahlungsdaten zu stehlen, und unterstreicht die anhaltende Bedrohung durch Phishing-Angriffe. Im vierten Quartal blieb Microsoft mit 32 Prozent die…
-
Tycoon 2FA Phishing Kit Using Specially Crafted Code to Evade Detection
The rapid evolution of Phishing-as-a-Service (PhaaS) platforms is reshaping the threat landscape, enabling attackers to launch increasingly sophisticated phishing campaigns. One such advanced PhaaS platform, Tycoon, has seen widespread use since its emergence in August 2023. In November 2024, it debuted its latest iteration, Tycoon 2FA, which bypasses multifactor authentication (2FA) using Microsoft 365 session…
-
New GhostGPT AI Chatbot Facilitates Malware Creation and Phishing
Cybercriminals are selling access to the malicious GenAI chatbot via Telegram, providing rapid assistance for a range of nefarious activities, according to Abnormal Security First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ghostgpt-ai-chatbot-malware/
-
Brand Phishing Trend von Check Point zeigt: Microsoft bleibt Spitzenreiter, LinkedIn steigt auf
Angesichts der ständigen Zunahme von Phishing-Versuchen, die auf weltweit bekannte Marken abzielen, müssen Benutzer wachsam bleiben und proaktiv bewährte Sicherheitsverfahren anwenden. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/brand-phishing-trend-von-check-point-zeigt-microsoft-bleibt-spitzenreiter-linkedin-steigt-auf/a39533/
-
What Makes Bulletproof Hosting Providers a Growing Danger in Australia
The Australian Cyber Security Centre has issued a warning about Bulletproof Hosting Providers (BPH), which play a central role in enabling cybercrime. These providers offer infrastructure that helps cybercriminals carry out attacks such as ransomware campaigns, data theft, and phishing scams, all while remaining largely undetectable. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/acsc-targets-bulletproof-hosting-providers/
-
Aldi-Talk-Phishing nach Black BastaAngriff auf Medion?
Nutzer von Aldi-Talk-Mobilfunktarifen (und Medion-Kunden) sollten aufpassen. Die könnten nun mit persönlich adressierten Phishing-Nachrichten, die Name und Kundennummer enthalten, konfrontiert zu werden. Oder Medion hat seine IT-Prozesse nach dem Black Basta-Ransomware-Angriff in 2024 immer noch nicht im Griff. Wäre dann … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/01/23/aldi-talk-phishing-nach-black-basta-ransomware-angriff-auf-medion/
-
New Supply Chain Attack Targeting Chrome Extensions to Inject Malicious Code
A sophisticated supply chain attack targeting Chrome browser extensions has come to light, potentially compromising hundreds of thousands of users. The attack, which unfolded in December 2024, involved phishing campaigns aimed at extension developers and the injection of malicious code into legitimate Chrome extensions. Sensitive user data, including API keys, session cookies, and authentication tokens…
-
ApateWeb Campaign Hijacks Blogspot, Spreads Phishing and Malware
Security researcher Aaron Meese, in collaboration with Validin, has uncovered an ongoing malicious campaign exploiting Blogspot redirectors to First seen on securityonline.info Jump to article: securityonline.info/apateweb-campaign-hijacks-blogspot-spreads-phishing-and-malware/
-
Mastercard’s multi-year DNS cut-and-paste nightmare
Due to a Domain Name System (DNS) setting error, which the security researcher who discovered it said was almost certainly a cut-and-paste problem, Mastercard had a DNS record with a missing character for almost five years. That error would have allowed attackers to potentially take over the subdomain, create a bogus site that mimics the…
-
Cybercriminals Exploit AnyDesk to Impersonate CERT-UA in Sophisticated Phishing Campaign
In a recent alert, CERT-UA researchers have unveiled a series of cyber-attacks leveraging the legitimate remote access tool First seen on securityonline.info Jump to article: securityonline.info/cybercriminals-exploit-anydesk-to-impersonate-cert-ua-in-sophisticated-phishing-campaign/
-
Google Cloud Security Threat Horizons Report #11 Is Out!
Tags: access, api, apt, attack, authentication, breach, business, cloud, corporate, credentials, cybersecurity, data, detection, exploit, extortion, google, identity, intelligence, leak, mfa, password, phishing, ransomware, service, tactics, theft, threat, tool, vulnerabilityThis is my completely informal, uncertified, unreviewed and otherwise completely unofficial blog inspired by my reading of our next Threat Horizons Report, #11 (full version) that we just released (the official blog for #1 report, my unofficial blogs for #2, #3, #4, #5, #6, #7, #8, #9 and #10). My favorite quotes from the report follow below:…
-
Zendesk’s Subdomain Registration Exposed to Phishing, Pig Butchering Scams
CloudSEK uncovers a Zendesk vulnerability allowing cybercriminals to exploit subdomains for phishing and investment scams. Learn about the… First seen on hackread.com Jump to article: hackread.com/zendesk-subdomain-registration-abused-phishing-scams/
-
Supply chain attack hits Chrome extensions, could expose millions
Threat actor exploited phishing and OAuth abuse to inject malicious code First seen on theregister.com Jump to article: www.theregister.com/2025/01/22/supply_chain_attack_chrome_extension/
-
Phishing Clicks Tripled in 2024, Giving MSPs Plenty to Worry About
First seen on scworld.com Jump to article: www.scworld.com/analysis/phishing-clicks-tripled-in-2024-giving-msps-plenty-to-worry-about
-
Tycoon 2FA Phishing Kit Upgraded to Bypass Security Measures
Threat researchers analyzed the updated Tycoon 2FA phishing kit, which bypasses MFA First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/tycoon-2fa-phishing-kit-upgraded/
-
Star Blizzard: WhatsApp-Kontoübernahme durch Phishing-Kampagne
Microsoft berichtet von einer Phishing-Kampagne der kriminellen Gruppe Star Blizzard. Sie versucht, WhatsApp-Konten zu übernehmen. First seen on heise.de Jump to article: www.heise.de/news/Star-Blizzard-WhatsApp-Kontouebernahme-durch-Phishing-Kampagne-10252402.html
-
APAC businesses face surge in email attacks
Sophisticated phishing and business email compromise campaigns are increasingly targeting organisations across the Asia-Pacific region, research reveals First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366618432/APAC-businesses-face-surge-in-email-attacks
-
Account Compromise and Phishing Top Healthcare Security Incidents
Netwrix claims 84% of healthcare organizations detected a cyber-attack in the past year First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/account-compromise-phishing/
-
Hacker nehmen Diplomaten ins Visier
Die russische Hackergruppe Star Blizzard hat offenbar eine neue Spear-Phishing-Kampagne gestartet, um WhatsApp-Accounts von hochrangigen Diplomaten und politisch aktiven Personen zu kompromittieren. First seen on 8com.de# Jump to article: www.8com.de#

