Advertisement
Casbaneiro Banking Trojan: Evasion and Lateral Movement in Latin America
Analyzing Casbaneiro, a sophisticated banking Trojan employing advanced evasion, process injection, and network worming to target financial institutions and users in…
EvilTokens Fuels Microsoft Device Code Phishing & BEC
New EvilTokens service automates Microsoft device code phishing, enabling account takeover and sophisticated business email compromise (BEC) attacks. Learn how to defend.
UAC-0255 Impersonates CERT-UA to Distribute AGEWHEEZE Malware
UAC-0255 targeted 1 million emails with a phishing campaign impersonating CERT-UA to deploy the AGEWHEEZE RAT. Learn about the TTPs and mitigation steps.
GitHub Malware Campaign: Fake VS Code Alerts Target Developers
Attackers exploit GitHub Discussions to push malware via fake VS Code security alerts. Learn the TTPs used to target developers and how to mitigate risk.
Palo Alto Networks Recruiter Scam and Quantum Security Outlook
Threat actors are impersonating Palo Alto Networks recruiters to target security professionals, while Google sets a 2029 deadline for quantum computing.
AitM Phishing Campaign Targets TikTok Business via Turnstile Evasion
Security researchers have identified a sophisticated AitM phishing campaign using Cloudflare Turnstile to hijack TikTok for Business accounts for malvertising.
Advertisement
Dutch Police Phishing Breach Exposes Internal Contact Data
The Dutch National Police (Politie) confirms a security breach after a phishing attack exposed work contact details for 65,000 police department employees.
TikTok for Business Phishing Campaign Evades Security Bots
A new TikTok for Business phishing campaign uses sophisticated bot-evasion techniques to steal corporate credentials and hijack advertising assets.
Bubble Platform Abuse: Credential Phishing Targets Microsoft Accounts
Threat actors are abusing the Bubble no-code platform to host sophisticated phishing campaigns, bypassing traditional detection and targeting Microsoft account…
Palo Alto Networks Recruitment Fraud: Analysis of Phishing Tactics
Phishing campaigns posing as Palo Alto Networks recruiters leverage LinkedIn data and psychological tactics to defraud job seekers in the security industry.
Silnikau Sentenced: BitPaymer Ransomware Botnet Operator Receives 2 Years
Russian national Maksim Silnikau sentenced for managing a botnet used in BitPaymer ransomware attacks targeting 72 U.S. companies and demanding $100 million.
SmartApeSG Campaign: Multi-RAT Distribution via Malicious Archives
Analysis of the SmartApeSG campaign leveraging phishing, LNK files, and scripts to distribute Remcos RAT, NetSupport RAT, StealC, and Sectop RAT. Learn mitigation.
Lumma Stealer Phishing Campaign: Avoiding Copyright Notice Decoys
Phishing campaign targets healthcare and government sectors with copyright infringement decoys to deliver Lumma Stealer via legitimate cloud services.
Russian Intelligence Phishing Targets Signal and WhatsApp Users
The FBI warns of sophisticated phishing campaigns by Russian intelligence targeting Signal and WhatsApp users to harvest credentials and bypass encryption.
Russian Intelligence Targets Commercial Messaging App Accounts
Russian intelligence services are exploiting commercial messaging applications through phishing to compromise accounts of U.S. government officials, military, and…
Aura Marketing Database Breach: Impact on 900,000 Customer Contacts
Identity protection firm Aura confirms a data breach exposing nearly 900,000 marketing records. Learn about the risks of phishing and social engineering.
7-Stage Phishing Chain Targets Outpost24 C-Suite via Redirects
Security researchers identify a sophisticated 7-stage phishing attack targeting Outpost24 executives using legitimate domains to evade email gateways.
LiveChat Abuse: Phishing Campaign Targets PayPal and Amazon Users
Threat actors are leveraging legitimate LiveChat platforms to impersonate PayPal and Amazon support agents, stealing credit card and personal data.
Security Firm Executive Targeted via DKIM-Signed Phishing
A sophisticated phishing campaign bypassed security filters using DKIM-signed emails and Cloudflare-protected landing pages to target a security executive.
Fake Chrome Update Campaigns Deploying NetSupport RAT
Technical analysis of phishing campaigns using JavaScript-injected websites to distribute NetSupport RAT via fake browser update overlays.
SmartApeSG Leverages ClickFix Pages to Deploy Remcos RAT
Analysis of the SmartApeSG campaign, detailing its use of deceptive 'ClickFix' pages to distribute Remcos RAT.
Smartphone Phishing Bypasses Protections: AI's Role in Defense
Sophisticated Phishing attacks are increasingly bypassing smartphone protections. This analysis explores AI's potential role in defense and critical user safeguards.
Starbucks Employee Portal Phishing Leads to Data Breach
Starbucks confirms a data breach impacting hundreds of employees via targeted phishing attacks on an internal portal. Learn about the incident and prevention.
Phishing Credential Exfiltration via EmailJS and React Frameworks
Security analysis of a sophisticated React-based phishing kit that leverages the EmailJS service for stealthy exfiltration of user credentials.