Security News

Say Goodbye to Phishing: Must-Haves to Eliminate Credential Theft
2024-09-13 11:17

Even as cyber threats become increasingly sophisticated, the number one attack vector for unauthorized access remains phished credentials (Verizon DBIR, 2024). Solving this problem resolves over...

Phishing in focus: Disinformation, election and identity fraud
2024-09-09 03:30

The frequency of phishing attacks is rising as attackers increasingly utilize AI to execute more scams than ever before. In this Help Net Security video, Abhilash Garimella, Head Of Research at...

Novel attack on Windows spotted in phishing campaign run from and targeting China
2024-09-02 03:06

Resources hosted at Tencent Cloud involved in Cobalt Strike campaign Chinese web champ Tencent's cloud is being used by unknown attackers as part of a phishing campaign that aims to achieve...

Threat Actors Exploit Microsoft Sway to Host QR Code Phishing Campaigns
2024-08-29 20:42

Threat actors are abusing Microsoft Sway to host QR Code phishing campaigns.

How AitM Phishing Attacks Bypass MFA and EDR—and How to Fight Back
2024-08-29 11:26

Attackers are increasingly using new phishing toolkits (open-source, commercial, and criminal) to execute adversary-in-the-middle (AitM) attacks. AitM enables attackers to not just harvest...

New QR Code Phishing Campaign Exploits Microsoft Sway to Steal Credentials
2024-08-28 06:49

Cybersecurity researchers are calling attention to a new QR code phishing (aka quishing) campaign that leverages Microsoft Sway infrastructure to host fake pages, once again highlighting the abuse...

Microsoft Sway abused in massive QR code phishing campaign
2024-08-27 14:00

​A massive QR code phishing campaign abused Microsoft Sway, a cloud-based tool for creating online presentations, to host landing pages to trick Microsoft 365 users into handing over their...

This uni thought it would be a good idea to do a phishing test with a fake Ebola scare
2024-08-22 10:32

Needless to say, it backfired in a big way University of California Santa Cruz (UCSC) students may be relieved to hear that an emailed warning about a staff member infected with the Ebola virus...

CERT-UA Warns of New Vermin-Linked Phishing Attacks with PoW Bait
2024-08-21 05:28

The Computer Emergency Response Team of Ukraine has warned of new phishing attacks that aim to infect devices with malware. The ZIP file contains a Microsoft Compiled HTML Help file that embeds JavaScript code responsible for launching an obfuscated PowerShell script.

New phishing method targets Android and iPhone users
2024-08-20 14:29

ESET researchers discovered an uncommon type of phishing campaign targeting Android and iPhone users. The phishing websites targeting iOS instruct victims to add a Progressive Web Application to their home screens, while on Android, the PWA is installed after confirming custom pop-ups in the browser.