Security News

DocuSign phishing campaign targets low-ranking employees
2021-10-14 15:33

Phishing actors are following a new trend of targeting non-executive employees but who still have access to valuable areas within an organization. As reported by Avanan researchers, half of all phishing emails they analyzed in recent months impersonated non-executives, and 77% of them targeted employees on the same level.

Phishing campaign uses math symbols to evade detection
2021-10-12 16:22

Phishing actors are now using mathematical symbols on impersonated company logos to evade detection from anti-phishing systems. All three spoofing types masquerade as voicemail notifications containing an embedded 'Play' button, that when clicked, take the user to a phishing portal that was crafted to look like a Verizon website.

Intuit warns QuickBooks customers of ongoing phishing attacks
2021-10-08 17:16

Intuit has warned QuickBooks customers that they are targeted by an ongoing phishing campaign impersonating the company and trying to lure potential victims with fake renewal charges. Intuit also provides information on how customers can protect themselves from phishing attempts on its support website.

State-sponsored Chinese crims targeted India with tax and COVID phishing
2021-10-07 06:58

Blackberry's Research and Intelligence Team has uncovered three phishing schemes targeting Indian nationals, and says a Chinese state-sponsored malware gang is the culprit. Blackberry identified the responsible party as APT41 - a prolific Chinese state-sponsored cyberthreat group that has carried out what Fireye called "Espionage activity in parallel with financially motivated operations" since at least 2012.

How a phishing attack thwarted MFA to steal money from Coinbase customers
2021-10-06 14:38

That lesson was hammered home through a recent phishing attack that stole money from Coinbase customers. The attackers were able to move funds from Coinbase to their own accounts, thus stealing a vast amount of money in the form of cryptocurrency.

Phishing campaigns against Chase Bank customers are on the rise
2021-10-05 14:24

One brand that's been getting a lot of exposure among phishing campaigns is Chase Bank as cybercriminals are increasingly targeting people who use the company's financial services. The American subsidiary of JP Morgan Chase, Chase Bank is now ranked as the sixth most spoofed brand seen in phishing URLs, according to Cyren.

3 tips to protect your users against credential phishing attacks
2021-09-28 16:21

A new phishing campaign spotted by Armorblox tried to steal user credentials by spoofing a message notification from a company that provides email encryption. A successful phishing email that obtains the right username and password can gain access to an entire network.

Credential Spear-Phishing Uses Spoofed Zix Encrypted Email
2021-09-28 10:00

Armorblox researchers have spotted an ongoing credential-phishing attack that spoofs an encrypted Zix email - one coming, weirdly enough, from what looks like a legitimate domain associated with the Baptist religion. God isn't sending encrypted Zix messages: If hapless users click on the spoofed email's link, it will try to download a presumably unholy HTML file onto their system.

How Does DMARC Prevent Phishing?
2021-09-27 04:21

DMARC is a global standard for email authentication. Recipients can detect phishing emails sent from a spoofed company domain by examining the email header information, such as the "From:" address and "Return-path" address, and verifying that they match.

How phishing-as-a-service operations pose a threat to organizations
2021-09-23 15:11

Attackers can easily buy, deploy and scale phishing campaigns to steal credentials and other sensitive data, says Microsoft. Cybercrime as a service has expanded to malware, ransomware and even phishing campaigns.