Skip to main content

Tag: phishing

692 articles

Microsoft Exchange servers: Must-Have Patch for Risky Flaws

Microsoft Exchange servers: Must-Have Patch for Risky Flaws

Over 29,000 Microsoft Exchange servers are still unpatched, leaving hybrid Active Directory–Azure environments vulnerable to attackers who could seize domain control. If you manage Exchange, now’s the time to inventory, patch, and tighten configurations before adversaries walk through this wide-open door.

Analyst 207
phishing campaign: Stunning Risk to UK Sponsors

phishing campaign: Stunning Risk to UK Sponsors

A slick phishing campaign is targeting Home Office sponsor licence holders, risking fraud, extortion and even licence revocation by stealing the credentials used to manage migrant sponsorships. If you manage a sponsor account, verify any Home Office contact, enable MFA, and treat unexpected emails with extreme caution to protect your organisation and the people you sponsor.

Analyst 207
APT28 LameHug: Exclusive Risky AI Threat Warning

APT28 LameHug: Exclusive Risky AI Threat Warning

MITRE’s take on APT28’s LameHug at Black Hat is a wake-up call: while crude now, this testbed shows how AI and automation could quickly turn basic tools into powerful cyber weapons. Defenders, policymakers, and everyday users should sharpen defenses and share intel now—before experiments like this graduate into routine attacks.

Analyst 207
ShinyHunters cybercrime group: Critical Exclusive Threat

ShinyHunters cybercrime group: Critical Exclusive Threat

When your bank calls about a transaction you didn’t make, it’s a stark reminder that the ShinyHunters cybercrime group is now homing in on banks, fintechs and their vendors to harvest credentials and personal data for large-scale fraud. Institutions must act fast—tightening credential defenses, shoring up vendor security, and boosting detection—to protect customers, reputation and regulatory standing.

Analyst 207
sextortion scams: Must-Have Best Survival Guide

sextortion scams: Must-Have Best Survival Guide

Most sextortion emails are bluffs—ask where’s the tape? and demand verifiable proof instead of paying. Secure your accounts with unique passwords and 2FA, scan devices, preserve evidence, and report the scam.

Analyst 207
NIST Cyber AI Profile: Must-Have Guide to Best Defenses

NIST Cyber AI Profile: Must-Have Guide to Best Defenses

NIST’s Cyber AI Profile brings technologists, policymakers, and everyday users together to build practical defenses against AI-enabled attacks—balancing strong security with the innovation that powers our digital lives.

Analyst 207
AI in Cybersecurity: Stunning Must-Have Defense

AI in Cybersecurity: Stunning Must-Have Defense

In a rapidly evolving digital landscape, the battle between AI-driven attacks and defenses is more intense than ever. Join us as we unpack the insights from the recent Black Hat conference, where experts discussed how AI can transform from a weapon for cybercriminals to a vital shield for defenders—reminding us that in cybersecurity, staying one step ahead is crucial!

Analyst 207
Romance fraud scheme: Stunning $100M Risky Scam

Romance fraud scheme: Stunning $100M Risky Scam

When online romance turns into a $100 million criminal scheme, four Ghana-based suspects have been extradited to the U.S., spotlighting how emotional manipulation fuels sprawling scams and why stronger international cooperation is urgently needed.

Analyst 207
Embargo ransomware Shocking $34.2M Haul Exposed

Embargo ransomware Shocking $34.2M Haul Exposed

TRM Labs revealed the Embargo ransomware gang has siphoned $34.2 million from victims—a stark reminder that our connected world can be exploited for huge profit. It’s time businesses, regulators, and users to boost defenses and work together to stop these crypto-enabled crimes.

Analyst 207
EncryptHub Exposes Fake AI Platforms Targeting Web3 Developers

EncryptHub Exposes Fake AI Platforms Targeting Web3 Developers

Beware, Web3 developers! As the digital landscape evolves, so do the threats lurking within it—like counterfeit AI platforms designed to ensnare the unsuspecting. Stay vigilant and informed to protect your innovations and integrity from these treacherous traps!

Analyst 207
Breached security perimeter with salt-encrusted debris and destroyed computer terminal on a stormy night.

Salt Typhoon Breach: How it Compromised National Guard Systems

The recent Salt Typhoon breach of the National Guard Systems serves as a stark reminder that our digital defenses are just as vital as the ones on the battlefield—highlighting urgent questions about our national security and the resilience of military operations. As experts call for enhanced cybersecurity measures, its clear that safeguarding our nation in the digital age is more crucial than ever!

Analyst 207
Identity-based attacks: Urgent Best Defense Guide

Identity-based attacks: Urgent Best Defense Guide

Identity-based attacks are surging—infostealers and off-the-shelf phishing kits are harvesting credentials and turning stolen identities into repeatable profit. Act now: use strong, unique passwords, enable phishing-resistant MFA, and stay alert to suspicious messages to keep your digital identity safe.

Analyst 207
Cybersecurity Threats: Must-Have Defenses for Risky Firms

Cybersecurity Threats: Must-Have Defenses for Risky Firms

A recent PureRAT campaign delivered via Ghost Crypt shows how quickly accounting firms’ trusted data can be undermined by stealthy malware and simple human mistakes—so now’s the time to treat cybersecurity as an everyday business priority. Strengthen controls, train staff with realistic phishing drills, and lock down access and backups to stop a single click from becoming a firm‑wide disaster.

Analyst 207
Cybersecurity vulnerabilities: Must-Have Best Practices

Cybersecurity vulnerabilities: Must-Have Best Practices

This week’s roundup uncovers alarming flaws—from a critical SharePoint bug that can expose entire orgs to a Chrome exploit that makes ordinary browsing risky—showing attackers now target overlooked misconfigurations as much as flashy zero-days. Stay ahead by prioritizing patching, hardening defaults, and boosting monitoring to keep your data safe.

Analyst 207
QR Phishing FIDO Keys: Exclusive Risky Threat Revealed

QR Phishing FIDO Keys: Exclusive Risky Threat Revealed

Think your FIDO key makes you untouchable? PoisonSeed’s QR‑phishing scam shows how a convincing QR scan and fake approval prompt can trick users into granting access—learn how these attacks work and what simple steps you can take to stay safe.

Analyst 207
PoisonSeed Hack: Must-Have Warning of Risky Breach

PoisonSeed Hack: Must-Have Warning of Risky Breach

The PoisonSeed Hack reveals how clever QR-based phishing can trick FIDO authenticators—meaning even “phishing-resistant” logins can be hijacked when users approve vague prompts. Learn how to spot fake QR flows, tighten approval UX, and train teams so attackers can’t exploit convenience and trust.

Analyst 207
fake AI schemes: Stunningly Risky Threats to Web3

fake AI schemes: Stunningly Risky Threats to Web3

Web3 developers are being targeted by a sophisticated scam—EncryptHub (aka LARVA-208/Water Gamayun) uses fake AI platforms like Norlax AI and Teampilot to deliver info-stealers disguised as job offers or portfolio reviews. Learn how to spot these impersonations and protect your projects, reputation, and community before it’s too late.

Analyst 207
Web3 cyber threats: Critical Must-Have Defense Guide

Web3 cyber threats: Critical Must-Have Defense Guide

EncryptHub is targeting Web3 developers with convincing fake AI platforms, so learn to spot spoofed sites, verify domains and social profiles, and never share private keys. Use hardware wallets, multisig, and secure development practices to keep your projects and funds safe.

Analyst 207
Microsoft malware threat: Stunning, Alarming Risks

Microsoft malware threat: Stunning, Alarming Risks

Imagine your inbox becoming a spying ground — UK officials warn Fancy Bear-linked hackers are using new malware to hijack Microsoft email accounts and siphon private messages and sensitive documents. Take it seriously: enable MFA, tighten access controls, and monitor for unusual logins to stay one step ahead.

Analyst 207
Microsoft malware: Stunning Critical Threats Exposed

Microsoft malware: Stunning Critical Threats Exposed

Russian state-backed hackers have unleashed stealthy Microsoft-targeted malware to hijack Outlook accounts—exposing how fragile our email defenses can be. Now’s the time to tighten security with phishing-resistant MFA, vigilant monitoring, and smarter user habits to stay one step ahead.

Analyst 207
npm package malware: Must-Have Best Defenses

npm package malware: Must-Have Best Defenses

Think a routine dependency update is harmless? The recent npm malware attack—where phishers stole maintainer tokens to publish malicious versions of five popular packages—proves supply-chain trust can be shattered and why maintainers, consumers, and registries must act now to enforce 2FA, rotate tokens, and verify publish provenance.

Analyst 207
npm package security: Must-Have Guide to Risky Breaches

npm package security: Must-Have Guide to Risky Breaches

A targeted phishing attack that slipped malicious code into five npm packages shows how easily supply chains can be weaponized. Treat publish tokens like private keys—enable 2FA, rotate credentials, and demand package signing and provenance to stop the next breach.

Analyst 207
Iran Cyber Threats: Stunning Risk to Global Security

Iran Cyber Threats: Stunning Risk to Global Security

Iran’s rapidly evolving cyber campaigns—mixing technical skill with sophisticated social engineering—now threaten critical infrastructure, economies, and public trust worldwide. Tackling this growing risk means investing in people, smarter technology, and stronger international cooperation before the next attack lands.

Analyst 207
UNG0002 cyber espionage Exclusive Critical Threat

UNG0002 cyber espionage Exclusive Critical Threat

UNG0002 is a stealthy cyber-espionage campaign using CV-themed phishing, LNK/VBScript exploits, and post-exploitation tools to target organizations in China, Hong Kong, and Pakistan—putting strategic data and finances at risk. Stay vigilant: harden email defenses, enforce MFA, patch systems, and train staff to spot realistic résumé and job-offer lures.

Analyst 207