Advertisement
MuddyWater Exploits Microsoft Teams via Chaos Ransomware Decoy
Iranian APT MuddyWater utilizes Microsoft Teams social engineering and Chaos ransomware decoys to mask state-sponsored espionage operations.
MuddyWater Exploits Microsoft Teams for False Flag Ransomware
Iranian APT MuddyWater is leveraging Microsoft Teams social engineering to deploy false flag ransomware, obscuring state-sponsored espionage activities.
Legacy of the USB Drop: Evolution of Social Engineering TTPs
An analysis of the historical 2006 USB penetration test that shaped modern social engineering defense and the evolution of hardware-based attack vectors.
DigiCert Revokes Certificates After Support Portal Compromise
DigiCert is revoking TLS/SSL certificates following a breach where attackers used support chat to compromise an internal analyst's workstation and portal.
Bluekit Phishing Kit: AI Integration and Automated Deployment
The Bluekit phishing kit uses an AI assistant and automated domain registration to simplify credential harvesting against financial and logistics sectors.
Hugging Face and ClawHub Abused for Malware Distribution
Threat actors are exploiting the trust of AI and code-hosting platforms like Hugging Face and ClawHub to distribute malware via social engineering lures.
Advertisement
European Police Dismantle €50 Million Crypto Investment Fraud Ring
Authorities in Austria and Albania shut down a massive crypto investment scam involving fraudulent call centers and over €50 million in victim losses.
UNC6692 Leverages Teams, AWS S3 for Malware & Cloud Abuse
Newly discovered threat actor UNC6692 combines social engineering via Microsoft Teams with custom 'Snow' malware and AWS S3 cloud abuse in multi-pronged attacks.
Combating Romance Scams and Confidence Schemes: Institutional Response
Romance scams and confidence schemes represent a growing threat to personnel. Learn how cross-sector collaboration improves victim recovery and threat mitigation.
UNC6692 Targets Microsoft Teams to Deploy Snow Malware
UNC6692 is leveraging Microsoft Teams and social engineering to deliver the modular Snow malware suite, facilitating long-term persistence and data theft.
AI-Powered Phishing Surges: Defending Against Advanced Attacks
Explore the surge in AI-powered phishing, how threat actors are leveraging it for personalized attacks, and critical defensive strategies for organizations.
UNC6692 Social Engineering: Deploying the SNOW Custom Malware Suite
UNC6692 leverages Microsoft Teams and S3-hosted payloads to deploy the SNOW modular malware ecosystem, targeting enterprise Windows environments.
UNC6692 Impersonates IT Helpdesk to Deploy SNOW Malware via Teams
UNC6692 threat actors are impersonating IT helpdesk staff via Microsoft Teams to deliver custom SNOW malware, highlighting risks in SaaS messaging apps.
Defensive Strategies for Routine Workflow Weaponization
Attackers are pivoting from technical exploits to weaponizing trusted workflows. Learn how to detect and mitigate these behavioral identity-based threats.
DPRK's 'Contagious Interview' Spreads RATs via Dev Repositories
DPRK threat actors are employing a 'contagious interview' scam, weaponizing compromised developer repositories to propagate RATs and malware across the software supply…
Scattered Spider Member Tylerb Pleads Guilty: Smishing Analysis
Tyler Robert Buchanan's guilty plea exposes Scattered Spider smishing tactics that compromised 12+ tech firms and stole millions in cryptocurrency.
WhatsApp Metadata Leak: Exposure Risks and Mitigation Strategies
WhatsApp's metadata leakage allows strangers to infer limited user information without interaction, potentially aiding targeted social engineering or other malicious…
Scattered Spider Member Tyler Buchanan Pleads Guilty in US
Tyler Buchanan, a British national linked to the Scattered Spider cybercrime group, pleaded guilty in the US to charges of hacking, fraud, and cryptocurrency theft.
Microsoft Teams Abused in Helpdesk Impersonation Attacks: TTPs & Mitigations
Microsoft warns of helpdesk impersonation attacks via Teams external collaboration.
Apple ID Alerts Abused for Phishing via Legitimate Servers
Threat actors are exploiting Apple's account notification system to send authentic-looking phishing emails that bypass traditional spam filters and SPF checks.
Strategic Human-LLM Interaction: Research into AI Trust and Rationality
New research shows humans attribute higher rationality and cooperation to LLMs in strategic games, impacting trust in automated cybersecurity environments.
Kraken Extorted by Hackers Following Insider Account Breach
Kraken faces extortion after a social engineering attack on a support agent led to unauthorized internal system access and threatened customer data exposure.
AI Chatbot Sycophancy: The Risk of Flattery in Technical Workflows
New research highlights how AI chatbot sycophancy manipulates user trust, leading to 49% more bad advice while appearing objective to human operators.
APT37 Social Engineering via Facebook Delivers RokRAT Malware
North Korean threat actor APT37 leverages Facebook friend requests and trust-building to deploy the RokRAT trojan against high-value targets.