#phishing

[ follow ]
Information security
fromIT Pro
11 hours ago

Foreign states ramp up cyber attacks on EU with AI-driven phishing and DDoS campaigns

EU public administration faces intense state-aligned cyberespionage; phishing drives initial intrusions, hacktivist DDoS dominates incident counts, and vulnerability exploitation remains significant.
Information security
fromTalentLMS Blog
14 hours ago

10 Essential Cybersecurity Topics for Employee Training

Comprehensive cybersecurity training for all employees prevents breaches, protects data, preserves customer trust, and reduces financial, legal, and reputational damage.
Information security
fromSecuritymagazine
1 day ago

Cybersecurity Awareness Month Is a Reminder: Phishing Prevention Is Year-Round

Generative AI significantly increases phishing effectiveness by lowering skill barriers and creating highly authentic, hard-to-detect malicious messages, worsening global phishing prevalence.
#cybersecurity
fromZDNET
2 days ago
Information security

4 better ways to protect your business than dreaded (and useless) anti-phishing training

fromBusiness Insider
2 weeks ago
Information security

I'm a principal security engineer at Microsoft. Here are 5 things you should know if you're interested in working in cybersecurity.

fromIT Pro
1 month ago
Privacy professionals

Malicious URLs overtake email attachments as the biggest malware threat

Privacy professionals
fromDataBreaches.Net
1 month ago

NYDFS Secures $2 Million Cybersecurity Settlement with Healthplex, Inc. - DataBreaches.Net

Healthplex will pay a $2 million penalty for cybersecurity violations related to a 2021 phishing incident affecting over 89,000 people.
Canada news
fromIT Pro
1 month ago

Everything we know so far about the Canadian House of Commons data breach

Canada's House of Commons experienced a cyber attack linked to a Microsoft SharePoint zero-day, affecting employee data security.
fromZDNET
2 days ago
Information security

4 better ways to protect your business than dreaded (and useless) anti-phishing training

fromBusiness Insider
2 weeks ago
Information security

I'm a principal security engineer at Microsoft. Here are 5 things you should know if you're interested in working in cybersecurity.

fromIT Pro
1 month ago
Privacy professionals

Malicious URLs overtake email attachments as the biggest malware threat

fromIT Pro
1 month ago
Canada news

Everything we know so far about the Canadian House of Commons data breach

#security-training
fromZDNET
3 days ago
Information security

Phishing training doesn't stop your employees from clicking scam links - here's why

fromZDNET
1 week ago
Privacy professionals

Employees learn close to nothing from phishing training, and this is why

fromZDNET
3 days ago
Information security

Phishing training doesn't stop your employees from clicking scam links - here's why

fromZDNET
1 week ago
Privacy professionals

Employees learn close to nothing from phishing training, and this is why

Information security
fromThe Hacker News
3 days ago

Microsoft Flags AI-Driven Phishing: LLM-Crafted SVG Files Outsmart Email Security

Threat actors used LLM-generated code to obfuscate SVG-based phishing payloads targeting U.S. organizations, enabling credential theft while evading security defenses.
Information security
fromThe Hacker News
6 days ago

Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and Vietnam

Phishing campaign impersonating Ukrainian agencies uses SVG-based emails to deliver CountLoader that installs Amatera Stealer and PureMiner (fileless .NET, process hollowing).
fromZDNET
1 week ago

Employees learn nothing from phishing security training, and this is why

The , conducted by UC San Diego Health and Censys researchers, found that phishing-related cybersecurity training programs had no effect on whether or not employees were duped by phishing emails. After analyzing the results of 10 different phishing email campaigns sent to over 19,500 employees at UC San Diego Health over eight months, the researchers found "no significant relationship between whether users had recently completed an annual, mandated cybersecurity training and the likelihood of falling for phishing emails."
Tech industry
#pypi
Toronto
fromwww.cbc.ca
1 week ago

Phishing scam targeting U of T students, demanding payment for outstanding fees, police warn | CBC News

Students are being targeted by phishing emails impersonating the University of Toronto demanding immediate e-transfer payments for alleged outstanding tuition.
Information security
fromTheregister
1 week ago

Kaspersky: RevengeHotels returns with AI-coded malware

RevengeHotels uses AI-generated malware to enhance hotel phishing attacks, producing variants that evade detection and increase risk of guest card and personal data theft.
Information security
fromZDNET
1 week ago

FBI warns its scam reporting site is being spoofed - how to avoid getting tricked

Scammers are creating spoofed websites impersonating the FBI’s IC3 to steal personal and financial information and facilitate monetary scams.
Information security
fromThe Hacker News
1 week ago

ComicForm and SectorJ149 Hackers Deploy Formbook Malware in Eurasian Cyberattacks

ComicForm conducted phishing since April 2025 targeting Belarus, Kazakhstan, and Russia to deploy Formbook via multi-stage .NET malware.
Information security
fromSecurityWeek
1 week ago

FBI Warns of Spoofed IC3 Website

Threat actors are spoofing the FBI IC3 website to steal personal and financial information; users should access www.ic3.gov directly and avoid suspicious links.
Information security
fromInfoWorld
1 week ago

NPM attacks and the security of software supply chains

Process improvements and sustainable funding provide far more protection for open-source software supply chains than isolated technical guardrails.
#cybercrime
fromDataBreaches.Net
2 weeks ago
Information security

Microsoft seizes 338 websites to disrupt rapidly growing 'RaccoonO365' phishing service - DataBreaches.Net

fromDataBreaches.Net
2 weeks ago
Information security

Microsoft seizes 338 websites to disrupt rapidly growing 'RaccoonO365' phishing service - DataBreaches.Net

#revengehotels
#ta415
Information security
fromBusiness Matters
2 weeks ago

The Role of IT Support in Cyber Security Awareness Training

Effective cyber security awareness training led by IT support teams reduces human error, prevents breaches, and makes cyber safety second nature across organizations.
Information security
fromPCWorld
2 weeks ago

Protect your small business from remote working's biggest security nightmares

Small businesses must secure remote and hybrid work to protect employees, data, finances, and reputation from threats such as man-in-the-middle and phishing attacks.
fromComputerWeekly.com
2 weeks ago

Microsoft scores win against Office 365 credential thieves | Computer Weekly

Investigators from Microsoft's Digital Crimes Unit (DCU) have disrupted the network behind the dangerous RaccoonO365 infostealer malware that targeted the usernames and credentials of Office 365 users after being granted a court order in the Southern District of New York. The operation saw a total of 338 websites linked to the popular malware seized and its technical infrastructure disrupted, severing RaccoonO365 users' access to their victims.
Information security
Information security
fromwww.dw.com
2 weeks ago

Microsoft seizes websites linked to Nigeria-based phishing DW 09/17/2025

Microsoft seized 338 websites tied to Raccoon0365, a Nigerian phishing service that stole at least 5,000 Microsoft credentials and generated over $100,000.
Information security
fromSecuritymagazine
2 weeks ago

When Employees Help Hackers: How Threat Actors Bypass MFA

Criminals increasingly bypass MFA by tricking employees with sophisticated phishing, driving business email compromise and largely irretrievable wire fraud losses.
Information security
fromTheregister
2 weeks ago

Microsoft, Cloudflare shut down RaccoonO365 phishing domains

Microsoft seized 338 RaccoonO365 websites and identified leader Joshua Ogundipe, disrupting a subscription-based phishing service that stole Microsoft 365 credentials.
Information security
fromThe Hacker News
2 weeks ago

New FileFix Variant Delivers StealC Malware Through Multilingual Phishing Site

A FileFix variant is being used to deliver StealC malware via phishing pages that trick users into executing commands and downloading malicious images from Bitbucket.
Information security
fromBusiness Insider
2 weeks ago

Fake military IDs, bogus resumes: How North Korean and Chinese hackers use AI tools to infiltrate companies and other targets

North Korean and Chinese hackers use AI tools like ChatGPT and Claude to create fake IDs, résumés, and phishing materials to enable espionage and unauthorized access.
Information security
fromFortune
2 weeks ago

North Korean hackers used ChatGPT to help forge deepfake ID | Fortune

A suspected North Korean hacking group used ChatGPT to create a deepfake military ID image to support a phishing attack on a South Korean target.
Information security
fromBusiness Insider
3 weeks ago

Holiday shopping is just around the corner, and so are the shipping scams

Ending the de minimis exemption means low-value international packages now face duties, creating confusion that scammers exploit with fake customs and delivery notices.
#data-breach
fromIT Pro
3 weeks ago
Information security

LNER warns customers to remain vigilant after personal data exposed in cyber attack

fromIT Pro
3 weeks ago
Information security

LNER warns customers to remain vigilant after personal data exposed in cyber attack

#npm
fromZDNET
3 weeks ago
Information security

This 2FA phishing scam pwned a developer - and endangered billions of npm downloads

fromZDNET
3 weeks ago
Information security

This 2FA phishing scam pwned a developer - and endangered billions of npm downloads

#email-security
fromTechCrunch
3 weeks ago
Information security

Google's former security leads raise $13M to fight email threats before they reach you | TechCrunch

fromBuzzFeed
1 month ago
Privacy professionals

A New Email Scam Is Shockingly Realistic, Here's Everything You Need To Know About Protecting Yourself

fromTechCrunch
3 weeks ago
Information security

Google's former security leads raise $13M to fight email threats before they reach you | TechCrunch

fromBuzzFeed
1 month ago
Privacy professionals

A New Email Scam Is Shockingly Realistic, Here's Everything You Need To Know About Protecting Yourself

#scams
Information security
fromThe Hacker News
3 weeks ago

Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks

Threat actors exploit Axios and Microsoft Direct Send to spoof trusted senders, bypass gateways, and drive highly successful phishing and account takeover campaigns across industries.
Information security
fromThe Hacker News
3 weeks ago

From MostereRAT to ClickFix: New Malware Campaigns Highlight Rising AI and Phishing Risks

MostereRAT uses EPL-developed staged payloads, mTLS-protected C2, security-tool disabling, and plugin deployment to gain full control and stealthily persist on infected systems.
#icloud-calendar
#stealerium
Information security
fromTechzine Global
3 weeks ago

Varonis acquires SlashNext for email security

SlashNext's multi-channel phishing detection combined with Varonis' AI-driven data security enables earlier detection and prevention of AI-powered social-engineering attacks before data breaches occur.
Information security
fromThe Hacker News
3 weeks ago

VirusTotal Finds 44 Undetected SVG Files Used to Deploy Base64-Encoded Phishing Pages

Attackers use obfuscated SVG files with embedded JavaScript to deliver Base64-encoded phishing pages impersonating Colombia's judiciary and trigger hidden ZIP malware downloads.
Information security
fromChannelPro
4 weeks ago

Varonis snaps up AI email security specialist SlashNext

Varonis will acquire SlashNext to integrate AI-native multi-channel phishing detection into its platform, enhancing protection against AI-generated threats across email and messaging.
#gmail
#upcrypter
fromwww.theguardian.com
1 month ago

The good news is, you're owed a tax refund. The bad news? It's a scam

Tax calculations can be, well, taxing, so a message from HMRC saying that there's been a mistake may not ring too many alarm bells. Some bring good news: you have overpaid and are owed a refund, but others claim you owe money. In both cases there's an imminent deadline to act sometimes with the threat of legal action, or penalties if you don't. Scammers are taking advantage of people's fears over bills to steal personal and banking information.
Information security
fromWIRED
1 month ago

Scammers Will Try to Trick You Into Filling Out Google Forms. Don't Fall for It

These forms can be created in minutes, with clean and clear formatting, official-looking images and video, and-most importantly of all-a genuine Google Docs URL that your web browser will see no problem with. Scammers can then use these authentic-looking forms to ask for payment details or login information. It's a type of scam that continues to spread, with Google itself issuing a warning about the issue in February.
Information security
Artificial intelligence
fromTechzine Global
1 month ago

Anthropic blocks misuse of Claude for cybercrime

Anthropic blocked attempts to misuse Claude for phishing, malware development, filter circumvention, and influence campaigns, banning accounts and tightening filters to mitigate risks.
#identity-security
fromTheregister
1 month ago
Information security

Report declares 'identity crisis' amid rising login attacks

Security leaders increasingly distrust identity providers due to complexity, poor visibility, inadequate MFA coverage, and rising credential-focused attacks.
fromSecuritymagazine
1 month ago
Privacy professionals

Survey Reveals Top Challenges of Implementing Identity Security

A significant gap exists between the need for identity security and its implementation across organizations.
Information security
fromEntrepreneur
1 month ago

AI-Driven Scams Are Draining Retirement Funds | Entrepreneur

The Phantom Hacker Scam uses AI-driven, three-pronged phishing to steal seniors' retirement funds through tech support, bank, and government impersonation.
Information security
fromTechzine Global
1 month ago

Phishing campaign targets Teams and Zoom with RMM tool

Attackers hijack ConnectWise ScreenConnect via AI-driven phishing that impersonates Zoom/Teams, using cloud obfuscation to gain administrator access and enable lateral movement and credential theft.
Science
fromSecuritymagazine
1 month ago

Agentic AI Browsers Exploited by "PromptFix" Trick Technique

A new prompt injection technique uses fake CAPTCHA pages to trick generative AI agents into executing malicious actions and visiting lookalike storefronts.
Information security
fromIT Pro
1 month ago

Employee distraction is now your biggest cybersecurity risk

Distracted and undertrained staff, not sophisticated threats, cause the majority of cyber incidents, with phishing as the primary attack vector.
fromAbc
1 month ago

How a request for a video of a dress led to the seller losing $950

"Usually, I am pretty onto it and I have helped other friends avoid scams," she said. "For it to happen to me ... this situation got me off guard."
E-Commerce
Information security
fromThe Hacker News
1 month ago

Linux Malware Delivered via Malicious RAR Filenames Evades Antivirus Detection

Phishing emails deliver RAR archives whose filenames contain Base64-encoded Bash commands that execute VShell via shell command injection when file names are parsed.
#tax-scams
Information security
fromLifehacker
1 month ago

This Creative Phishing Scam Uses Netflix Job Offers to Steal Facebook Credentials

Scammers impersonate Netflix recruiters to phish jobseekers, steal Facebook credentials, and compromise business accounts to run malicious ads or demand ransoms.
Information security
fromABC7 Los Angeles
1 month ago

Don't click on that text claiming to be from Amazon. Here's what to know about the scam

Scammers send fake Amazon texts claiming refunds or recalls to phish for personal information and money; verify via the Amazon app/website and report spam to 7726.
Privacy professionals
fromTechCrunch
1 month ago

After researchers unmasked a prolific SMS scammer, a new operation has emerged in its wake | TechCrunch

A prolific SMS scam operation has targeted victims by impersonating delivery and toll notifications to steal credit card information.
#malware
Privacy technologies
fromArs Technica
1 month ago

Here's how deepfake vishing attacks work, and why they can be hard to detect

AI voice cloning poses significant risks through fraudulent calls mimicking known individuals, increasing the efficiency of phishing schemes.
fromThe Hacker News
1 month ago

ClickFix Malware Campaign Exploits CAPTCHAs to Spread Cross-Platform Infections

"Like a real-world virus variant, this new 'ClickFix' strain quickly outpaced and ultimately wiped out the infamous fake browser update scam that plagued the web just last year."
Privacy professionals
Marketing tech
fromOCCRP
2 months ago

Behind the Scam: How Fraudsters Use Social Media, Software, and Shell Companies to Steal Millions

Affiliate marketers use phishing ads to collect victim data for call centers offering fake investment opportunities.
fromCSO Online
2 months ago

Supply chain attack compromises npm packages to spread backdoor malware

In a newly discovered supply chain attack, attackers last week targeted a range of npm-hosted JavaScript type testing utilities, several of which were successfully compromised to distribute malware.
JavaScript
fromwww.bbc.com
2 months ago

University student who sold fraud kits jailed

Holman created and sold 1,052 kits which provided fraudulent webpages with built-in scripts to enable the harvesting of information entered, including account log-in details and bank details.
Privacy technologies
[ Load more ]