Security News

Twitter says spear-phishing attack hooked its staff and led to celebrity account hijack
2020-07-31 05:27

Twitter has offered further explanation of the celebrity account hijack hack that saw 130 users' timelines polluted with a Bitcoin scam. "The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack," says a July 30 update to Twitter's incident report.

BitDam releases scanner that detects phishing at first encounter
2020-07-28 23:00

BitDam announced the availability of its new phishing scanner. Phishing attacks are also becoming increasingly sophisticated, making it harder for traditional phishing detection solutions based on reputation and threat intelligence to identify them.

U.S. Election Administrators Failed to Implement Phishing Protections: Study
2020-07-28 16:00

A majority of election administrators in the United States have yet to implement cybersecurity controls designed to provide protection against phishing attacks, a new Area 1 Security report reveals. The U.S. elections have been targeted by phishing as well, with examples including attacks against election-sensitive organizations in 2016 and 2018, and phishing attempts targeting the current 2020 election cycle.

27% of consumers hit with pandemic-themed phishing scams
2020-07-24 03:30

Among consumers reporting being targeted with digital COVID-19 schemes globally, 27% said they were hit with pandemic-themed phishing scams. "From the impacts of phishing and other well documented COVID-19 scams like unemployment fraud, it's clear that fraudsters have the data and increasing opportunities to create synthetic identities and utilize stolen identities," said Shai Cohen, senior vice president of Global Fraud & Identity Solutions at TransUnion.

Phishing attacks and ransomware are the most challenging threats for many organizations
2020-07-22 18:45

In a new report released on Wednesday, enterprise security provider Balbix looks at the top threats cited in a survey of security professionals. For many organizations, limited visibility into their security holes and an inability to prioritize security issues are creating greater risk.

Phishing is the leading type of COVID-19 fraud
2020-07-22 15:06

TransUnion surveyed consumers in six countries and found that phishing was the preferred method of attack 27% of the time. Credit agency TransUnion has found that COVID-19 related scams have targeted 32% of people around the world, and phishing is the method of choice, accounting for 27% of those attacks.

Phishing attacks hiding in Google Cloud to steal Microsoft account credentials
2020-07-21 13:08

By hosting phishing pages at a legitimate cloud service, cybercriminals try to avoid arousing suspicion, says Check Point Research. The idea is that such phishing pages will better elude detection by security products and more easily ensnare unsuspecting victims.

Phishing attacks aim to steal sensitive data by prompting people to renew Microsoft subscription
2020-07-20 17:25

The initial scam emails claim that the recipient must renew their Microsoft Office 365 subscription, says Abnormal Security. In a Friday blog post, Abnormal Security described two separate phishing campaigns, both of which impersonate actual notices from Microsoft.

Phishing: Email fraudsters are impersonating colleagues, customers, and vendors, report says
2020-07-17 16:30

The latest form of business email phishing attacks involve impersonating familiar senders, a GreatHorn report found. GreatHorn also acknowledged this uptick the report noted that this view isn't fully adequate in understanding how phishing email attacks are evolving, and how security teams are responding to those threats.

Zoom's Vanity URLs Could Have Been Abused for Phishing Attacks
2020-07-17 08:25

An issue related to the Zoom feature that allows for the customization of meeting URLs could have been exploited for phishing attacks, Check Point reveals. The recently identified security issue, Check Point says, is related to the Zoom Vanity URL, a custom URL that organizations are required to use when looking to enable single sign-on.