‘Dubai Police’ Lures Anchor Wave of UAE Mobile Attacks

December 13, 2024 at 02:06AM Dubai Police are being impersonated by fraudsters in a phishing campaign targeting mobile users in the UAE. The attackers send messages with fake URLs, aiming to harvest personal and financial information. Cybercriminals exploit the UAE’s digital vulnerabilities, urging organizations to enhance cybersecurity measures and cooperate with law enforcement against evolving … Read more

Phishing: The Silent Precursor to Data Breaches

December 12, 2024 at 02:20PM Phishing is a leading cyber threat that often initiates data breaches, as seen in the 2021 Colonial Pipeline attack. This social engineering tactic manipulates victims into revealing sensitive information through various methods, including email and SMS. Mitigating risks requires user education, technical controls, and robust incident response strategies. ### Meeting … Read more

Inside the incident: Uncovering an advanced phishing attack

December 10, 2024 at 10:11AM The article by Varonis Security Specialist Tom Barnea discusses the evolution of sophisticated phishing attacks that exploit AI and legitimate platforms. A specific case involving a U.K. insurance company illustrates how attackers used a trusted sender’s email and created deceptive links. Recommendations emphasize user awareness and technical measures for prevention. … Read more

Fake Recruiters Distribute Banking Trojan via Malicious Apps in Phishing Scam

December 10, 2024 at 09:48AM Cybersecurity researchers have uncovered a mobile phishing campaign distributing an updated Antidot banking trojan, luring victims through fake job offers. Attackers prompt downloads of malicious apps, enabling extensive device control and data theft. Targeting multilingual users, the advanced malware requires robust protection measures to prevent significant data loss and financial … Read more

Blue Yonder ransomware termites claim credit

December 8, 2024 at 10:10PM The Termite ransomware gang claimed responsibility for a ransomware attack on Blue Yonder, stealing 680GB of data. Blue Yonder’s operations were disrupted, affecting clients like Starbucks and UK grocery chains. Additionally, a Nigerian scammer received eight years in prison for a business email compromise scheme that stole over $6 million. … Read more

US arrests Scattered Spider suspect linked to telecom hacks

December 5, 2024 at 03:35PM U.S. authorities arrested 19-year-old Remington Goy Ogletree, connected to the Scattered Spider cybercrime gang, for breaching a financial institution and telecoms. He exploited phishing tactics, targeting employee credentials, and sent millions of phishing texts to steal cryptocurrency. Investigations reveal his extensive criminal activities and ties to other notorious hackers. ### … Read more

Latrodectus malware and how to defend against it with Wazuh

December 5, 2024 at 10:41AM Latrodectus is a sophisticated malware family targeting corporate networks and financial institutions, leveraging advanced tactics like phishing and dynamic API resolution for data theft while evading detection. It utilizes a modular design for adaptability and persistence. Effective defenses include employee training, endpoint security, network segmentation, and regular updates. ### Meeting … Read more

North Korean Kimsuky Hackers Use Russian Email Addresses for Credential Theft Attacks

December 3, 2024 at 04:52AM North Korea-aligned Kimsuky is linked to phishing attacks using Russian sender addresses to steal credentials. These attacks, primarily targeting South Korean users, exploit email services and impersonate institutions like Naver. Kimsuky utilizes compromised servers and tools for spoofing to evade security, aiming for account hijacking and further attacks. ### Meeting … Read more

Novel phising campaign uses corrupted Word documents to evade security

December 2, 2024 at 05:49AM A new phishing attack exploits Microsoft Word’s file recovery feature by distributing corrupted documents as email attachments. These files bypass security software due to their damaged condition while remaining recoverable by users, posing a significant security risk. ### Meeting Takeaways: – **Phishing Attack Overview**: A new phishing attack leverages a … Read more

The only thing worse than being fired is scammers fooling you into thinking you’re fired

November 28, 2024 at 02:38AM A phishing campaign targets individuals by falsely claiming their employment has been terminated, using a legal-sounding email to induce panic. The scam preys on economic fears, spreading malware disguised as legal documents. Attackers aim to steal sensitive information, using tactics that may evolve across different platforms. ### Meeting Takeaways 1. … Read more