Phishing
Abusing DNS record management controls, the threat actor hides the location of malicious content via Cloudflare.
Hi, what are you looking for?
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets.
Abusing DNS record management controls, the threat actor hides the location of malicious content via Cloudflare.
The attackers are sending out fake alerts claiming unauthorized access or master password changes.
Domains set up by the threat actor suggest attacks aimed at Atlassian, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, and WeWork.
Priced $2,000 - $6,000 on a cybercrime forum, the MaaS toolkit promises publication on the Chrome Web Store.
Threat actors are leveraging the file-sharing service for payload delivery in AitM phishing and BEC attacks.
Threat actors may have wanted to take advantage of the holiday weekend in the United States to increase their chances of success.
Threat actors spoof legitimate domains to make their phishing emails appear to have been sent internally.
The cybercriminals attempted to steal $28 million from compromised bank accounts through phishing.
AI has given cybercriminals the ability to operate like Fortune‑500‑scale marketing departments—except their product is account takeover, data theft, and identity fraud.
The cybercriminals informed customers that their cloud server was shut down due to complaints.
Google is targeting the threat group known as Smishing Triad, which used over 194,000 malicious domains in a campaign.
The malicious Smishing Triad domains were used to collect sensitive information, including Social Security numbers.
The video game software development company says the incident impacted users of its SpeedTree website.
Threat actors used automation to create over 175 malicious NPM packages targeting more than 135 organizations.
Threat actors impersonating PyPI ask users to verify their email for security purposes, directing them to fake websites.
Microsoft and Cloudflare have teamed up to take down the infrastructure used by RaccoonO365.
AI-powered phishing attacks leverage ConnectWise ScreenConnect for remote access, underscoring their sophistication.
Investigators from HMRC joined more than 100 Romanian police officers to arrest the 13 Romanian suspects in the counties of Ilfov, Giurgiu and Calarasi.
Hackers are abusing the Microsoft 365 Direct Send feature to deliver phishing emails that bypass email security controls.
Microsoft flags a new Kremlin hacking team buying stolen usernames and passwords from infostealer markets for use in cyberespionage attacks.