Security News

FBI warns of voice phishing attacks targeting employees at large companies
2021-01-19 19:20

The FBI is cautioning companies to beware of a slew of voice phishing attacks aimed at capturing the login credentials of employees. In an advisory released last Thursday, the FBI revealed that as of December 2019, cybercriminals have been working together on social engineering campaigns targeting employees at large firms both in the US and abroad. The criminals are taking advantage of VoIP platforms to launch voice phishing, or vishing, attacks.

FBI Warns of Employee Credential Phishing via Phone, Chat
2021-01-18 19:21

The Federal Bureau of Investigation has issued a Private Industry Notification to warn of attacks targeting enterprises, in which threat actors attempt to obtain employee credentials through vishing or chat rooms. An observed shift in tactics, the FBI says, is the targeting of all employee credentials, not exclusively of those individuals who might have higher access and privileges based on their corporate position.

Windows Finger command abused by phishing to download malware
2021-01-15 14:34

Attackers are using the normally harmless Windows Finger command to download and install a malicious backdoor on victims' devices. This week, security researcher Kirk Sayre found a phishing campaign utilizing the Finger command to download the MineBridge backdoor malware.

Hoplite Technology Anti-Phishing Bot: Protecting everyday users against phishing attacks
2021-01-15 03:00

With an inherent emphasis in "Privacy-by-default", Hoplite Technology announced the new launch of a free anti-phishing solution named Anti-Phishing Bot to protect everyday users against phishing attacks. Due to the lack of ways to verify the identity of the senders, everyday users without technical trainings will often find it difficult to distinguish a phishing attack as the red flags are hidden in different parts of an email.

Telegram-based phishing service Classiscam hits European marketplaces
2021-01-14 07:06

Some of the brands abused through this scam are extremely popular in Europe and include LeBonCoin, Allegro, OLX, Sbazar, FAN Courier, Lalafo, Kufar and DHL. Scam expanding to Europe. The scammers publish ads on popular marketplaces and classifieds claiming to offer various products at low prices.

Beware: PayPal phishing texts state your account is 'limited'
2021-01-03 12:58

A PayPal text message phishing campaign is underway that attempts to steal your account credentials and other sensitive information that can be used for identity theft. When PayPal detects suspicious or fraudulent activity on an account, the account will have its status set to "Limited," which will put temporary restrictions on withdrawing, sending, or receiving money.

PSA: Active Chase phishing scam pretends to be fraud alerts
2020-12-23 16:23

A large scale phishing scam is underway that pretends to be a security notice from Chase stating that fraudulent activity has been detected and caused the recipient's account to be blocked. One recipient said they fell for the scam after their card was denied in a purchase online and thought the email was a legitimate Chase fraud alert.

U.S. Government Warns of Phishing, Fraud Schemes Using COVID-19 Vaccine Lures
2020-12-23 04:56

Several U.S. government organizations have issued warnings regarding various types of fraud and phishing schemes that use COVID-19 vaccine-related topics to lure potential victims. The alert from the FBI, HHS-OIG, and CMS reads, could take the form of ads that claim to offer early access to vaccines in exchange for a deposit or fee, requests to pay for the vaccine or enter personal information on a so-called waiting list, or offers to undergo medical testing to obtain the vaccine.

How to Defend Against Malware, Phishing, and Scams During COVID-19 Crisis
2020-12-23 00:41

As if the exponential rise in phishing scams and malware attacks in the last five years wasn't enough, the COVID-19 crisis has worsened it further. Many scammers have rolled out campaigns offering COVID-19 vaccines, free medical tests and testing kits, tax rebates for donation to pandemic relief funds, information on COVID-19 cases, and new job opportunities due to the economic downturn.

US seizes domains used for COVID-19 vaccine phishing attacks
2020-12-21 12:28

The US Department of Justice has seized two domain names used to impersonate the official websites of biotechnology companies Moderna and Regeneron involved in the development of COVID-19 vaccines. While almost perfectly cloning the contents of the real sites, the website seized by the federal government were instead used for various malicious purposes including running scams, infecting visitors with malware, and collecting sensitive info in phishing attacks.