Security News

Windows NTLM hash leak flaw exploited in phishing attacks on governments
2025-04-17 19:20

A Windows vulnerability that exposes NTLM hashes using .library-ms files is now actively exploited by hackers in phishing campaigns targeting government entities and private companies. [...]

Gamma AI Platform Abused in Phishing Chain to Spoof Microsoft SharePoint Logins
2025-04-16 11:44

Threat actors are leveraging an artificial intelligence (AI) powered presentation platform named Gamma in phishing attacks to direct unsuspecting users to spoofed Microsoft login pages. "Attackers...

Midnight Blizzard deploys new GrapeLoader malware in embassy phishing
2025-04-15 20:25

Russian state-sponsored espionage group Midnight Blizzard is behind a new spear-phishing campaign targeting diplomatic entities in Europe, including embassies. [...]

ResolverRAT Campaign Targets Healthcare, Pharma via Phishing and DLL Side-Loading
2025-04-14 16:09

Cybersecurity researchers have discovered a new, sophisticated remote access trojan called ResolverRAT that has been observed in attacks targeting healthcare and pharmaceutical sectors. "The...

Phishing Campaigns Use Real-Time Checks to Validate Victim Emails Before Credential Theft
2025-04-14 13:24

Cybersecurity researchers are calling attention to a new type of credential phishing scheme that ensures that the stolen information is associated with valid online accounts. The technique has...

Tycoon2FA phishing kit targets Microsoft 365 with new tricks
2025-04-12 15:16

Phishing-as-a-service (PhaaS) platform Tycoon2FA, known for bypassing multi-factor authentication on Microsoft 365 and Gmail accounts, has received updates that improve its stealth and evasion...

iOS devices face twice the phishing attacks of Android
2025-04-11 04:00

2024 brought about countless new cybersecurity challenges including significant growth of the mobile threat landscape, according to Lookout. Threat actors, ranging from nation-states to...

Phishing kits now vet victims in real-time before stealing credentials
2025-04-09 13:49

Phishing actors are employing a new evasion tactic called 'Precision-Validated Phishing' that only shows fake login forms when a user enters an email address that the threat actors specifically...

Phishing, fraud, and the financial sector’s crisis of trust
2025-04-08 05:00

The financial sector is under growing pressure from advanced phishing attacks and fraud, causing major financial losses and eroding customer trust. Escalation of phishing attacks While traditional...

CISA and FBI Warn Fast Flux is Powering Resilient Malware, C2, and Phishing Networks
2025-04-07 13:40

Cybersecurity agencies from Australia, Canada, New Zealand, and the United States have published a joint advisory about the risks associated with a technique called fast flux that has been adopted...