Tagged: Social Engineering
Corporate video meetings are increasingly attracting attention not only from employees but from automated services as well, prompting Microsoft to roll out new protections within Teams. Administrators will now be able to fully block...
The notorious ShinyHunters group, meticulously tracked and scrutinized by ReliaQuest for months, audaciously decided to reverse roles. The malevolent actors launched a targeted assault against ReliaQuest personnel, successfully compromising a single employee account. Judging...
An ordinary-looking message from corporate IT support on Microsoft Teams can end in a stolen Windows password and full access to a company’s internal network. Researchers at Expel discovered a new malware family called...
uBlock Origin, the popular ad-blocking extension, has gained new capabilities to protect users. It now detects and blocks websites that display malicious ClickFix pop-ups. These sites try to trick visitors into running dangerous commands...
Attackers have begun creating fake ChatGPT workspaces dressed up as real companies. Then they invite employees through genuine OpenAI emails. The scheme is dangerous precisely because it does not look like ordinary phishing. The...
Generative AI as a Criminal Commodity Cybercriminals increasingly integrate artificial intelligence into traditional attack strategies. However, they frequently exploit this novel technology as a lucrative commodity. Recently, researchers investigated various illicit forums and dark...
Malicious actors are no longer exclusively targeting rare virtual items within the Roblox ecosystem. They have escalated their operations to expropriate entire developmental projects. Creators have invested years nurturing these digital environments, which often...
A new ClickFix malware campaign is turning Amazon’s trusted name against its own customers. Researchers at the Cofense Phishing Defense Center uncovered the scheme. Notably, the attack convinces victims to infect their own machines....
MITRE has unveiled ATT&CK v19, a monumental evolution of the framework utilized by security cohorts to delineate adversary tactics and techniques. This iteration fundamentally recalibrates the established architecture: developers have bifurcated the overly broad...
A seemingly innocuous file transmitted via a support chat escalated into a significant crisis for DigiCert. An adversary masquerading as a client presented a malicious archive as a “customer screenshot,” successfully infiltrating systems utilized...
Corporate correspondence has once again emerged as a convenient portal for adversaries. In this nascent campaign, the assailants eschew direct “forced entry,” choosing instead to orchestrate a familiar professional complication for employees and promptly...
The Harvester threat collective has re-emerged, wielding a sophisticated instrument designed to elude conventional defensive parameters. Security researchers have identified a nascent iteration of the GoGra backdoor for Linux, which surreptitiously camouflages its presence...