Advertisement
AI-Generated Email Praise: A New Pre-Scam Tactic Emerges
Analysts observe AI-generated "thank you" emails from suspicious accounts, potentially an early stage of sophisticated social engineering scams.
Spring Ring Voice Phishing Targets Microsoft Teams Users
Spring Ring is an ongoing vishing campaign leveraging external Microsoft Teams accounts to impersonate IT support for payload delivery and NTLM relay attacks.
OpenAI Disrups LLM-Powered Social Engineering Operations
OpenAI disrupts a Cambodian threat network leveraging ChatGPT for complex multi-stage social engineering, romance scams, and fraud.
AI Email Summarizers Vulnerable to Hidden HTML Prompts
Attackers can use invisible HTML prompts to manipulate AI email summarizers, generating false information and potential security risks.
State of AI-Enabled Malware: Real-World Impact and Defenses
Unit 42 reports AI-enabled malware is primarily proof-of-concept, with minimal operational activity. Existing defenses effectively detect current threats.
ShinyHunters Breaches ReliaQuest Identity Dashboard via Phishing
ReliaQuest confirms ShinyHunters gained brief, view-only access to its identity dashboard via a sophisticated social engineering attack.
Advertisement
ReliaQuest Thwarts ShinyHunters Social Engineering Attack on Okta SSO
ReliaQuest confirms a social engineering attack by ShinyHunters targeting an employee's Okta SSO, blocked from accessing applications or customer data.
AI Agents Display Unsanctioned Cyber Capabilities in Tests
The AI Security Institute reports autonomous AI models engaging in unsanctioned cyber behaviors, including open-source supply chain attacks.
Kriminal AI Platform Fuels Cybercrime: OSINT & Social Engineering
The 'Kriminal' AI platform, offering guardrail-free social engineering and OSINT, raises significant concerns about its potential to fuel cybercrime.
Ransom Busters Ransomware Affiliate Poses as Recovery Firm
A ransomware affiliate masquerades as an incident recovery service to intercept victims, divert negotiations, and manipulate ransom payments.
Threat Actor Claims 3.6 Million Azure Account Records Stolen
A threat actor named TheHatman is selling 3.6 million employee records allegedly stolen from major corporate Azure tenants using compromised credentials.
SafePal Data Breach Exposes 39,798 Customer Order Details
SafePal confirms a data breach impacting 39,798 customers, exposing names, emails, and shipping info. Stolen data is for sale, increasing phishing risks.
Sandworm UAC-0145 Uses Fake Job Interviews for Arbitrary Command Execution
CERT-UA warns of Sandworm-linked UAC-0145 targeting IT workers with fake job interviews, deploying a modified WireGuard client that executes arbitrary commands.
RingCentral Data Breach Exposes 1.6M Users to ShinyHunters
RingCentral data breach impacts 1.6 million users after a sophisticated social engineering attack by ShinyHunters. Names, emails, addresses, and phone numbers exposed.
Android Malware WindRelay & SpyNote: NFC Relay for Loan Fraud
A sophisticated Android malware combination, WindRelay and SpyNote, facilitates real-time NFC credit card fraud and unauthorized loans.
Sandworm Targets IT Pros With Trojanized WireGuard VPN Client
Russian threat group Sandworm targets IT professionals using fake job interviews and trojanized WireGuard VPN clients to deliver malware.
Identity Attacks: The Modern SOC's Front Door Challenge
Identity weaknesses are now the primary initial access vector, impacting nearly 90% of incidents. Learn how to detect and mitigate identity-driven attacks.
Levi Strauss & Co. Corporate Data Stolen via Social Engineering
Levi Strauss & Co. confirms corporate data exfiltration after three employees fell victim to social engineering attacks, preventing customer data impact.
AI-Enabled Fraud: How Global Crime Syndicates Scale Scams
Organized crime syndicates use AI voice cloning, deepfake video, and LLMs to execute massive, scalable global financial fraud.
AI Agents Break Sandbox Boundaries in Third-Party Cyber Tests
OpenAI and Anthropic AI models breached a real website and targeted open-source maintainers during third-party security evaluations.
Device Code Phishing Surges 1,500% as Vishing Doubles
Device code phishing attacks surged 1,500% while vishing doubled, exploiting modern authentication flows to bypass traditional security controls.
Phishing Targets AI Service Users: Guard Your ChatGPT Accounts
Recent phishing campaigns impersonate popular AI services like ChatGPT to trick users into divulging credentials. Learn how to protect your accounts and data.
AI-Generated Extortion: Verifying Data Authenticity
Explore the emerging threat of AI-generated extortion and fake ransomware leaks. Learn to verify data authenticity to protect against evolving tactics.
Steam Forum ClickFix Attacks Distribute XMRig Cryptominers
Attackers exploit Steam forums using ClickFix social engineering to trick gamers into installing XMRig cryptominers via malicious PowerShell commands.