Tag: phishing
722 articles

MSPs Face Ransomware Onslaught, Seek Integrated Protection
MSPs are under siege from ransomware attacks, with 143 reported victims in 2025 alone, and it's clear that a robust defense requires more than just backup or endpoint detection - a comprehensive, integrated protection approach is needed. To stay safe, MSPs must bring together prevention, detection, response, and recovery into a cohesive, measurable service that delivers six critical outcomes.

AI-Generated Emails Flood Inbox in Apparent Scam
Beware of the sudden surge of brief, upbeat responses flooding your inbox - they might not be from genuine subscribers, but rather AI-generated emails trying to trick you. A recent flood of one-line replies to a newsletter confirmation email is raising red flags about a potential scam.

Russian Hacker Charged Over Excel Malware Campaign Targeting Freelancers
A massive malware campaign, involving around 255 fake accounts and 80,000 targeted users, has led to charges against a Russian national, Searzhudin Tamirlanovich Aktulaev, who has been extradited and charged by the U.S. Department of Justice. The campaign, which spread malware through infected Excel attachments, allegedly ran from June 2016 to November 2017, targeting freelancers and others.

Hackers Exploit Faronics Tool to Install ScreenConnect on Compromised Endpoints
Hackers are using clever phishing lures disguised as invoices and business files to trick victims into installing malicious software, with over 457 endpoints compromised in just a month. They exploited a legitimate endpoint-management tool to gain remote control and install additional remote-access software.

Microsoft Teams Targeted in Voice Phishing Campaigns
Beware of voice phishing scams on Microsoft Teams! A recent campaign, dubbed Spring Ring, used fake IT help desk accounts to trick over 150 employees across 10 organizations into granting remote access.

SVG Attachments Fuel Large-Scale Phishing with JavaScript Smuggling
A massive phishing campaign, detected in over 5,500 organizations, used sneaky JavaScript smuggling tactics to evade native defenses, with a whopping 26,589 messages sent over just two months. The attackers cleverly exploited SVG attachments and voicemail lures to spread executable code.

Phishing Service NovaCookies Targets Organizations with 365 Session Theft
Meet NovaCookies, a sneaky phishing service that's stealing Microsoft 365 sessions from hundreds of organizations - and it's available for a low monthly fee of just $320. This subscription-based threat packages real-time session theft, making it a potent and affordable tool for cybercriminals.

Hackers Exploit npm Mirrors to Host Phishing Pages
Hackers are exploiting npm mirrors to host phishing pages by uploading malicious HTML files to the npm registry, which are then mirrored and can be accessed directly in a browser. This clever tactic turns the trusted registry into a free web host for malware, allowing threat actors to spread phishing pages under the guise of legitimate content.

CISA Red Team Exposes Defense Gap Between Water, Government Sectors
In a recent test, CISA's red team uncovered a shocking vulnerability in a government organization, breaching its defenses with ease by sending phishing emails from an internal address, then moving undetected to sensitive systems and cloud resources. The team was able to gain elevated privileges and spread laterally, exposing a significant gap in the organization's security.

ZeroTokens Phishing Platform Enables Real-Time Attack Adaptation
Meet ZeroTokens, a sneaky phishing platform that's sending shockwaves with its real-time attack adaptation capabilities, allowing live operators to steer victims through a multi-stage scam. Over 45,000 phishing messages have already been sent to 24,000 recipients across 700 organizations, making it a threat that's hard to ignore.

Malware Campaigns Deliver Stealers via ClickFix and Phishing
Beware of the sneaky ClickFix trick: just a click on the 'I'm not a robot' checkbox can lead to a malware attack, putting your sensitive info at risk. This clever scam uses a malicious command to download WordlistLoader, ultimately unleashing the Amatera Stealer.

SynkLoader Malware Targets Microsoft Teams Users in Phishing Campaign
Beware of phishing messages on Microsoft Teams that claim to be from your IT help desk - they may be laced with SynkLoader malware, a newly discovered threat that's being spread through seemingly legitimate downloads hosted on Microsoft Azure. These attacks use a clever tactic to gain your trust, but don't be fooled!

Russian Hackers Exploit Google OAuth, WhatsApp to Hijack High-Value Accounts
Meet the sneaky Russian hackers who are hijacking high-value accounts using clever tricks and fake emails to get their hands on sensitive info. They're using Google OAuth and WhatsApp to pull off their phishing scams, and experts warn that no one is safe.

MSPs Face Evolving Phishing Threats from AI-Driven Attacks
AI-powered phishing attacks have transformed from a filtering issue to a detection challenge, with Kaseya warning that the numbers are stark. AI now turbocharges every stage of a phishing campaign, from lightning-fast reconnaissance to convincing content generation and evasive post-compromise activity.

Phishers Target Def Con Attendees with Persistent Campaign
Meet the sneaky phishing scam that hit Def Con attendees, using a clever Google Doc trick that looked legit - but led to a malicious web page instead. A security researcher got roped in by a scammer impersonating a CoinDesk executive, and things quickly escalated.

Hackers Exploit Dropcatch Domains to Redirect Traffic to Scams and Malware
Hackers are exploiting "dropcatch domains" - previously owned domains that are re-registered by new owners - to redirect traffic to scams and malware, taking advantage of the reputation and connections they inherit from their past life. With nearly one in five new domain registrations being a re-registration of an expired name, the threat is more widespread than you might think.

Kimsuky Bolsters Phishing Arsenal with Offline AI Infrastructure
North Korean hackers Kimsuky are taking phishing to the next level by leveraging offline AI infrastructure, a deliberate move to supercharge their espionage capabilities. Genians, a South Korean security firm, uncovered evidence of language-model tools like Ollama and GPT4All being installed and run on Kimsuky's servers.

Phisher Breaches US Defense Supplier's Microsoft 365 Account
A phishing scam led to a breach of a US defense supplier's Microsoft 365 account, exposing sensitive data including customer communications, engineering docs, and potentially export-controlled tech info. The intruder gained access to mailbox contents, but the company found no evidence that the data was copied or exfiltrated.

AI-Powered Phishing Outpaces Blocklist Defenses
Phishing campaigns are now a moving target, with 89% of domains disappearing within two days - and by the time they're blocked, the attackers have already packed up and moved on. AI-powered phishing has outsmarted traditional blocklist defenses, using disposable infrastructure and trusted platforms to stay one step ahead.

Cloud Platforms Expose Phishers to Easy MFA Bypass Tactics
Reputable cloud platforms have unwittingly become a phishing haven, with threat actors exploiting their trusted reputations, generous free tiers, and instant onboarding to launch attacks - all thanks to lenient security measures that rarely require verification. This has made it alarmingly easy for phishers to bypass multi-factor authentication and wreak havoc.

Malware Campaigns Exploit Software Updates for ScreenConnect Installation
Cyber attackers have launched a sneaky malware campaign, dubbed SMOKE#SCREEN, that uses fake software updates and social-engineering tricks to install ConnectWise ScreenConnect on victims' devices. The campaign relies on clever tactics like phishing emails and fake Adobe and Zoom updates to gain access to systems.

WhatsApp Scam Exploits Linked Devices Feature to Hijack Accounts
Beware of a sneaky WhatsApp scam that's hijacking accounts by tricking you into voting for a friend - but actually hands over control to attackers. One wrong click can let scammers take over your account, and you might not even get a password reset alert.

PNLD Breach Reveals U.K. Police and Government Contacts on Dark Web
A recent PNLD data breach has exposed sensitive contact information of U.K. police, government officials, and customers on the dark web, including names, work email addresses, and organisation details. The breach could make it easier for scammers to craft convincing phishing messages targeting law enforcement officers.

SilverFox Exploits New Drivers in BYOVD Attacks on Japanese Manufacturer
Meet the sneaky SilverFox hackers who've been exploiting new drivers to launch BYOVD attacks on a Japanese industrial manufacturer, using clever tactics like DLL sideloading and defense evasion to stay one step ahead. Their attack began with a simple yet effective invoice-themed phishing lure, delivered via popular Chinese services QQ and Tencent Cloud.