Email Security Businesses Worldwide Targeted in Large-Scale ChatGPT Phishing Campaign Barracuda has observed a large-scale OpenAI impersonation campaign whose goal is to phish for ChatGPT credentials. Eduard KovacsNovember 4, 2024
Phishing AWS Seizes Domains Used by Russia’s APT29 AWS announced the seizure of domains used by Russian hacker group APT29 in phishing attacks targeting Ukraine and other countries. Eduard KovacsOctober 25, 2024
Email Security Be Aware of These Eight Underrated Phishing Techniques There are a number of lesser-known phishing techniques that are often overlooked or underestimated yet increasingly being employed by attackers. Stu SjouwermanOctober 17, 2024
Phishing Quishing Campaign Abuses Microsoft Sway to Host Phishing Pages Threat actors are abusing the Microsoft Sway service to host phishing pages leveraged in QR phishing attacks targeting Office 365 users. Ionut ArghireAugust 29, 2024
Mobile & Wireless New Phishing Technique Bypasses Security on iOS and Android to Steal Bank Credentials New phishing attacks target iOS and Android users with Progressive Web Applications and WebAPKs to steal banking information. Ionut ArghireAugust 21, 2024
Phishing Western, Russian Civil Society Targeted in Sophisticated Phishing Attacks Multiple Russian, Belarusian, and Western entities perceived as Russia’s enemies have been targeted in two recent spear-phishing campaigns. Ionut ArghireAugust 16, 2024
Email Security Unlocking the Front Door: Phishing Emails Remain a Top Cyber Threat Despite MFA SecurityWeek spoke with Mike Britton, CISO at Abnormal Security, to understand what the company has learned about current social engineering and phishing attacks. Kevin TownsendAugust 14, 2024
Malware & Threats CrowdStrike Incident Leveraged for Malware Delivery, Phishing, Scams The major IT outage caused by CrowdStrike is being leveraged by threat actors for phishing, scams, and malware delivery. Eduard KovacsJuly 22, 2024
Phishing Malware Sandbox Any.Run Targeted in Phishing Attack Employees of the Any.Run malware analysis service were recently targeted in a phishing attack that was part of a BEC campaign. Eduard KovacsJune 25, 2024
Cybersecurity Funding Bolster Raises $14 Million for AI-Powered Phishing Protection Bolster has raised $14 million in Series B funding for technology integrations for its AI-powered phishing protection platform. Ionut ArghireMay 23, 2024
Phishing Autodesk Drive Abused in Phishing Attacks A new phishing campaign abuses compromised email accounts and targets corporate users with PDF files hosted on Autodesk Drive. Ionut ArghireApril 25, 2024
Cybercrime Phishing Platform LabHost Shut Down by Law Enforcement LabHost, a major phishing-as-a-service platform, has been shut down as part of a major law enforcement operation. Eduard KovacsApril 18, 2024
Cyberwarfare Cyberespionage Campaign Targets Government, Energy Entities in India Threat intelligence firm EclecticIQ documents the delivery of malware phishing lures to government and private energy organizations in India. Ionut ArghireMarch 28, 2024
Cybercrime Cybercriminals Spoof US Government Organizations in BEC, Phishing Attacks Threat actor tracked as TA4903 spoofing US government entities in phishing and fraud campaigns. Ionut ArghireMarch 7, 2024
Phishing FCC Employees Targeted in Sophisticated Phishing Attacks Advanced phishing kit employs novel tactics in attack targeting cryptocurrency platforms and FCC employees. Ionut ArghireMarch 4, 2024
Cybercrime Discount Retail Giant Pepco Loses €15 Million to Cybercriminals European discount retailer Pepco has lost €15.5 million as a result of what it described as a phishing attack. Eduard KovacsFebruary 29, 2024
Artificial Intelligence The $64k Question: How Does AI Phishing Stack Up Against Human Social Engineers? The Rise of AI in Phishing: Will future phishing attacks that leverage artificial intelligence be more dangerous? Kevin TownsendOctober 24, 2023
Email Security LinkedIn Smart Links Abused in Phishing Campaign Targeting Microsoft Accounts A recently observed phishing campaign targeting Microsoft accounts is using LinkedIn smart links to bypass defenses. Ionut ArghireOctober 12, 2023
Phishing US Executives Targeted in Phishing Attacks Exploiting Flaw in Indeed Job Platform An open redirection vulnerability in the popular job search platform Indeed has been exploited in a series of phishing attacks. Ionut ArghireOctober 3, 2023
Malware & Threats Xenomorph Android Banking Trojan Targeting Users in US, Canada The Xenomorph Android banking trojan can now mimic financial institutions in the US and Canada and is also targeting crypto wallets. Ionut ArghireSeptember 26, 2023