IoT Botnets and Water Systems Top ThreatsDay
A weekly roundup: 296K-device botnet, 100+ water systems targeted, and a SharePoint RCE chain.
30 results for “phishing”
A weekly roundup: 296K-device botnet, 100+ water systems targeted, and a SharePoint RCE chain.
MAG says customer data was stolen from its systems, warning of phishing risks ahead of peak travel.
AnonyMousKIT uses AI calls to trick iPhone owners into giving up passcodes.
Attackers abuse npm mirrors to host HTML phishing pages, bypassing security filters by serving from legitimate domains.
A phishing platform gives attackers live control over victim sessions, adapting prompts as credentials are harvested.
Mirage2FA campaign hit 4,532 companies, bypassing MFA and stealing sessions.
ReliaQuest says ShinyHunters accessed an identity dashboard briefly but no customer data was compromised.
Cybercriminals are using fake IT helpdesk messages on Microsoft Teams to deliver a new backdoor malware, researchers warn.
Threat actor Doubloon Dredger exploits Notion and device codes to steal authentication tokens, researchers say.
An open database from ClarityCheck exposed 9M+ facial images, risking identity theft and phishing.
SafePal warns of phishing risk after order data for nearly 40,000 customers is exposed in a breach.
SafePal reports a breach affecting 39,798 customers, exposing personal data through a plugin flaw.
New Lazarus campaign abuses Windows zero-day and fake job lures to breach defense firms, fooling Google's filters.
North Korea's Kimsuky group is building offline AI tools to automate malware and phishing, a Genians report says.
IEH Corporation disclosed a phishing attack compromising employee emails, potentially exposing sensitive defense-related data.
Recent investigations reveal how attackers leverage legitimate accounts and blockchain data to execute sophisticated financial fraud.
A sophisticated phishing campaign uses adversary-in-the-middle tactics to compromise Microsoft 365 accounts for financial espionage.
Google Threat Intelligence Group links the retired BlackFile extortion brand to the active Redact group through shared infrastructure.
Phishing service Greatness uses spoofed RingCentral emails to bypass MFA and compromise Microsoft 365 accounts.
Researchers identify a sophisticated phishing campaign using brand impersonation to deploy remote access malware on Windows.
A new report identifies a strategic shift among threat actors, moving away from simple malware toward identity and trust-based exploits.
Researchers report a rise in AI-driven malware and evolving social engineering, marking a shift in how attackers scale operations.
New data from eSentire indicates that adversary-in-the-middle phishing has bypassed standard authentication protocols at law firms.
SecurityAn overview of how interception attacks bypass traditional authentication and what defenders can do to protect their data integrity.
North Korean threat actors are leveraging AI-driven lures and Telegram account hijacks to target cryptocurrency and finance professionals.
A malicious Claude Artifact led users to download a remote access trojan, compromising at least 29 organizations in a recent campaign.
An Illinois man was sentenced to 76 months in federal prison for orchestrating a campaign to compromise 750 social media accounts.
New research details how threat actors are ditching delayed credential harvesting for live, session-based account hijacking.
A critical IDOR vulnerability in the Pope's official prayer app has left the personal data of over 700,000 users exposed for months.
Researchers report that compromised hotel network gateways are redirecting business travelers to sophisticated phishing portals.