Security News

U.S. Sentences 31-Year-Old to 10 Years for Laundering $4.5M in Email Scams
2024-05-29 11:50

The U.S. Department of Justice (DoJ) has sentenced a 31-year-old to 10 years in prison for laundering more than $4.5 million through business email compromise (BEC) schemes and romance scams....

Product showcase: Alert – Data breach detector for your email, credit card, and ID
2024-05-24 05:30

With Alert, you can easily monitor your most important credentials, such as your email, credit card, and ID. Alert will instantly notify you if it appears in breached online databases. Real-time monitoring and email notifications: your details are scanned in real-time, and if there's a new breach, Alert promptly informs you via email.

CISOs pursuing AI readiness should start by updating the org’s email security policy
2024-05-23 05:00

Conduct regular security training, especially with staff members who work with sensitive data and with executives who are often the targets of BEC. This should include live instruction, security awareness training videos and testing, and phishing simulation testing that use current, real-world attacks as examples. Finally, gamifying the cyber-aware culture by rewarding the employee with "Most reported emails" or the "Fastest reporter" promotes contributing to the overall security posture of the organization while keeping reporting engaging and fun.

Microsoft shares temp fix for Outlook encrypted email reply issues
2024-05-16 17:28

Microsoft has shared a temporary fix for a known issue preventing Microsoft 365 customers from replying to encrypted emails using the Outlook Desktop client. Affected customers will receive error messages stating, "Microsoft Outlook was not able to create a message with restricted permission" when trying to reply to messages using Microsoft encryption.

Ongoing Campaign Bombards Enterprises with Spam Emails and Phone Calls
2024-05-14 10:44

Cybersecurity researchers have uncovered an ongoing social engineering campaign that bombards enterprises with spam emails with the goal of obtaining initial access to their environments for...

Botnet sent millions of emails in LockBit Black ransomware campaign
2024-05-13 19:08

Since April, millions of phishing emails have been sent through the Phorpiex botnet to conduct a large-scale LockBit Black ransomware campaign. The LockBit Black encryptor deployed in these attacks is likely built using the LockBit 3.0 builder leaked by a disgruntled developer on Twitter in September 2022.

AT&T delays Microsoft 365 email delivery due to spam wave
2024-05-09 17:58

AT&T's email servers are blocking connections from Microsoft 365 due to a "High volume" spam wave originating from Microsoft's service. Starting on Monday, AT&T customers began reporting they could no longer receive email from Microsoft 365 email addresses.

NSA warns of North Korean hackers exploiting weak DMARC email policies
2024-05-03 19:16

The NSA and FBI warned that the APT43 North Korea-linked hacking group exploits weak email Domain-based Message Authentication Reporting and Conformance policies to mask spearphishing attacks. Together with the U.S. State Department, the two agencies cautioned that the attackers abuse misconfigured DMARC policies to send spoofed emails which appear to come from credible sources such as journalists, academics, and other experts in East Asian affairs.

NSA, FBI Alert on N. Korean Hackers Spoofing Emails from Trusted Sources
2024-05-03 09:37

The U.S. government on Thursday published a new cybersecurity advisory warning of North Korean threat actors' attempts to send emails in a manner that makes them appear like they are from...

Why the automotive sector is a target for email-based cyber attacks
2024-04-30 04:00

While every organization across every vertical is at risk of advanced email attacks, certain industries periodically become the go-to target for threat actors. In this Help Net Security video, Mick Leach, Field CISO at Abnormal Security, discusses why the automotive industry is the new most popular target for business email compromise and vendor email compromise attacks.