Skip to main content

Tag: phishing

722 articles

Brightly-lit IT support environment with a central computer workstation.

MSPs Face Ransomware Onslaught, Seek Integrated Protection

MSPs are under siege from ransomware attacks, with 143 reported victims in 2025 alone, and it's clear that a robust defense requires more than just backup or endpoint detection - a comprehensive, integrated protection approach is needed. To stay safe, MSPs must bring together prevention, detection, response, and recovery into a cohesive, measurable service that delivers six critical outcomes.

Analyst 207
Cluttered laptop inbox with papers, coffee cups, and sticky notes, with a hand poised over the keyboard.

AI-Generated Emails Flood Inbox in Apparent Scam

Beware of the sudden surge of brief, upbeat responses flooding your inbox - they might not be from genuine subscribers, but rather AI-generated emails trying to trick you. A recent flood of one-line replies to a newsletter confirmation email is raising red flags about a potential scam.

Analyst 207
Federal courthouse or government briefing room with podium and blank plaque.

Russian Hacker Charged Over Excel Malware Campaign Targeting Freelancers

A massive malware campaign, involving around 255 fake accounts and 80,000 targeted users, has led to charges against a Russian national, Searzhudin Tamirlanovich Aktulaev, who has been extradited and charged by the U.S. Department of Justice. The campaign, which spread malware through infected Excel attachments, allegedly ran from June 2016 to November 2017, targeting freelancers and others.

Analyst 207
Cluttered office cubicle with desktop computer and suspicious email nearby.

Hackers Exploit Faronics Tool to Install ScreenConnect on Compromised Endpoints

Hackers are using clever phishing lures disguised as invoices and business files to trick victims into installing malicious software, with over 457 endpoints compromised in just a month. They exploited a legitimate endpoint-management tool to gain remote control and install additional remote-access software.

Analyst 207
Person sits at cluttered desk, looking concerned while on video conference on computer with Microsoft Teams on screen.

Microsoft Teams Targeted in Voice Phishing Campaigns

Beware of voice phishing scams on Microsoft Teams! A recent campaign, dubbed Spring Ring, used fake IT help desk accounts to trick over 150 employees across 10 organizations into granting remote access.

Analyst 207
Office desk with papers and a nearby workstation showing a blurred email inbox, hinting at disruption.

SVG Attachments Fuel Large-Scale Phishing with JavaScript Smuggling

A massive phishing campaign, detected in over 5,500 organizations, used sneaky JavaScript smuggling tactics to evade native defenses, with a whopping 26,589 messages sent over just two months. The attackers cleverly exploited SVG attachments and voicemail lures to spread executable code.

Analyst 207
Empty office cubicle with laptop and smartphone on desk, surrounded by office supplies in a bright, daytime setting.

Phishing Service NovaCookies Targets Organizations with 365 Session Theft

Meet NovaCookies, a sneaky phishing service that's stealing Microsoft 365 sessions from hundreds of organizations - and it's available for a low monthly fee of just $320. This subscription-based threat packages real-time session theft, making it a potent and affordable tool for cybercriminals.

Analyst 207
Web developer's laptop open to npm registry page in coffee shop with notes and empty browser windows nearby.

Hackers Exploit npm Mirrors to Host Phishing Pages

Hackers are exploiting npm mirrors to host phishing pages by uploading malicious HTML files to the npm registry, which are then mirrored and can be accessed directly in a browser. This clever tactic turns the trusted registry into a free web host for malware, allowing threat actors to spread phishing pages under the guise of legitimate content.

Analyst 207
Dimly lit security operations center with empty workstations and monitors.

CISA Red Team Exposes Defense Gap Between Water, Government Sectors

In a recent test, CISA's red team uncovered a shocking vulnerability in a government organization, breaching its defenses with ease by sending phishing emails from an internal address, then moving undetected to sensitive systems and cloud resources. The team was able to gain elevated privileges and spread laterally, exposing a significant gap in the organization's security.

Analyst 207
A cluttered office cubicle with laptop, phone, and papers, with a blurred cityscape in the background and a person's hand…

ZeroTokens Phishing Platform Enables Real-Time Attack Adaptation

Meet ZeroTokens, a sneaky phishing platform that's sending shockwaves with its real-time attack adaptation capabilities, allowing live operators to steer victims through a multi-stage scam. Over 45,000 phishing messages have already been sent to 24,000 recipients across 700 organizations, making it a threat that's hard to ignore.

Analyst 207
Office worker sits at cluttered desk with laptop showing fake CAPTCHA and nearby paper with malicious command.

Malware Campaigns Deliver Stealers via ClickFix and Phishing

Beware of the sneaky ClickFix trick: just a click on the 'I'm not a robot' checkbox can lead to a malware attack, putting your sensitive info at risk. This clever scam uses a malicious command to download WordlistLoader, ultimately unleashing the Amatera Stealer.

Analyst 207
Office desk with laptop and smartphone, Microsoft Teams logo on blurred computer screen.

SynkLoader Malware Targets Microsoft Teams Users in Phishing Campaign

Beware of phishing messages on Microsoft Teams that claim to be from your IT help desk - they may be laced with SynkLoader malware, a newly discovered threat that's being spread through seemingly legitimate downloads hosted on Microsoft Azure. These attacks use a clever tactic to gain your trust, but don't be fooled!

Analyst 207
Person sitting at a coffee shop table looks concerned while holding a smartphone, surrounded by blurred cafe patrons and a…

Russian Hackers Exploit Google OAuth, WhatsApp to Hijack High-Value Accounts

Meet the sneaky Russian hackers who are hijacking high-value accounts using clever tricks and fake emails to get their hands on sensitive info. They're using Google OAuth and WhatsApp to pull off their phishing scams, and experts warn that no one is safe.

Analyst 207
Concerned office worker scrutinizes a paper at their cluttered desk.

MSPs Face Evolving Phishing Threats from AI-Driven Attacks

AI-powered phishing attacks have transformed from a filtering issue to a detection challenge, with Kaseya warning that the numbers are stark. AI now turbocharges every stage of a phishing campaign, from lightning-fast reconnaissance to convincing content generation and evasive post-compromise activity.

Analyst 207
A conference attendee sits at a laptop in a crowded hallway, surrounded by people looking at their own devices.

Phishers Target Def Con Attendees with Persistent Campaign

Meet the sneaky phishing scam that hit Def Con attendees, using a clever Google Doc trick that looked legit - but led to a malicious web page instead. A security researcher got roped in by a scammer impersonating a CoinDesk executive, and things quickly escalated.

Analyst 207
A cluttered computer workstation with a blank laptop screen sits unoccupied in a dimly lit server room with rows of…

Hackers Exploit Dropcatch Domains to Redirect Traffic to Scams and Malware

Hackers are exploiting "dropcatch domains" - previously owned domains that are re-registered by new owners - to redirect traffic to scams and malware, taking advantage of the reputation and connections they inherit from their past life. With nearly one in five new domain registrations being a re-registration of an expired name, the threat is more widespread than you might think.

Analyst 207
A cluttered server room with rows of computer servers and networking equipment, highlighting a single organized server.

Kimsuky Bolsters Phishing Arsenal with Offline AI Infrastructure

North Korean hackers Kimsuky are taking phishing to the next level by leveraging offline AI infrastructure, a deliberate move to supercharge their espionage capabilities. Genians, a South Korean security firm, uncovered evidence of language-model tools like Ollama and GPT4All being installed and run on Kimsuky's servers.

Analyst 207
Blurred office workstation with scattered papers and a small potted plant nearby.

Phisher Breaches US Defense Supplier's Microsoft 365 Account

A phishing scam led to a breach of a US defense supplier's Microsoft 365 account, exposing sensitive data including customer communications, engineering docs, and potentially export-controlled tech info. The intruder gained access to mailbox contents, but the company found no evidence that the data was copied or exfiltrated.

Analyst 207
Rows of server racks in a modern office background with a laptop screen in the foreground.

AI-Powered Phishing Outpaces Blocklist Defenses

Phishing campaigns are now a moving target, with 89% of domains disappearing within two days - and by the time they're blocked, the attackers have already packed up and moved on. AI-powered phishing has outsmarted traditional blocklist defenses, using disposable infrastructure and trusted platforms to stay one step ahead.

Analyst 207
Brightly-lit server rack with rows of out-of-focus servers and cables against a neutral background.

Cloud Platforms Expose Phishers to Easy MFA Bypass Tactics

Reputable cloud platforms have unwittingly become a phishing haven, with threat actors exploiting their trusted reputations, generous free tiers, and instant onboarding to launch attacks - all thanks to lenient security measures that rarely require verification. This has made it alarmingly easy for phishers to bypass multi-factor authentication and wreak havoc.

Analyst 207
Office setting with computers, papers, and a blurred monitor displaying a fake software update prompt.

Malware Campaigns Exploit Software Updates for ScreenConnect Installation

Cyber attackers have launched a sneaky malware campaign, dubbed SMOKE#SCREEN, that uses fake software updates and social-engineering tricks to install ConnectWise ScreenConnect on victims' devices. The campaign relies on clever tactics like phishing emails and fake Adobe and Zoom updates to gain access to systems.

Analyst 207
Person sitting at home holding smartphone with WhatsApp conversation on screen.

WhatsApp Scam Exploits Linked Devices Feature to Hijack Accounts

Beware of a sneaky WhatsApp scam that's hijacking accounts by tricking you into voting for a friend - but actually hands over control to attackers. One wrong click can let scammers take over your account, and you might not even get a password reset alert.

Analyst 207
Blurred police station lobby with out-of-focus interior details.

PNLD Breach Reveals U.K. Police and Government Contacts on Dark Web

A recent PNLD data breach has exposed sensitive contact information of U.K. police, government officials, and customers on the dark web, including names, work email addresses, and organisation details. The breach could make it easier for scammers to craft convincing phishing messages targeting law enforcement officers.

Analyst 207
Industrial control panel and laptop in a Japanese manufacturing facility.

SilverFox Exploits New Drivers in BYOVD Attacks on Japanese Manufacturer

Meet the sneaky SilverFox hackers who've been exploiting new drivers to launch BYOVD attacks on a Japanese industrial manufacturer, using clever tactics like DLL sideloading and defense evasion to stay one step ahead. Their attack began with a simple yet effective invoice-themed phishing lure, delivered via popular Chinese services QQ and Tencent Cloud.

Analyst 207