Security Bot her emails: most modern phishing campaigns are AI-enabled KnowBe4 says 86% of phishing it tracked used AI, and inboxes are only the start
Cyber-crime Hundreds of orgs compromised daily in Microsoft device code phishing attacks Who needs MFA when you've got EvilTokens?
Cyber-crime Ericsson blames vendor vishing slip-up for breach exposing thousands of records Crooks used simple phone scam to compromise vendor account, spilling personal and financial data belonging to more than 15,000 people
Cyber-crime Crims hit the easy button for Scattered-Spider style helpdesk scams Teach a crook to phish…
Cyber-crime Crims compromised energy firms' Microsoft accounts, sent 600 phishing emails Logging in, not breaking in
Cyber-crime Don't click on the LastPass 'create backup' link - it's a scam Phishing campaign tries to reel in master passwords
Cyber-crime Chinese spies used Maduro's capture as a lure to phish US govt agencies What's next for Venezuela? Click on the file and see
Cyber-crime Microsoft taps UK courts to dismantle cybercrime host RedVDS Redmond says cheap virtual desktops powered a global wave of phishing and fraud
Cyber-crime Google sues 25 China-based scammers behind Lighthouse 'phishing for dummies' kit 600+ phishing websites and 116 of these use a Google logo
Security Phishers try to lure 5K Facebook advertisers with fake business pages One company alone was hit with more than 4,200 emails
Security Attackers targeting unpatched Cisco kit notice malware implant removal, install it again PLUS: Cyber-exec admits selling secrets to Russia; LastPass isn't checking to see if you're dead; Nation-state backed Windows malware; and more
Security Iran's MuddyWater wades into 100+ government networks in latest spying spree Group-IB says Tehran-linked crew used hijacked mailbox and VPN to sling phishing emails across Middle East
Cybersecurity Month AI makes phishing 4.5x more effective, Microsoft says And potentially 50 times more profitable
Cybersecurity Month Chinese phishing kit helps scammers who send fake texts impersonate TikTok, Coinbase, others Researchers tracking 2,158 domains hosting YYlaiyu phishing pages
Cyber-crime New string of phishing attacks targets Python developers If you recently got an email asking you to verify your credentials to a PyPI site, better change that password
Cyber-crime Microsoft blocks bait for ‘fastest-growing’ 365 phish kit, seizes 338 domains Redmond names alleged ringleader, claims 5K+ creds stolen and $100k pocketed
Cyber-crime Hijacker helper VoidProxy boosts Google, Microsoft accounts on demand Okta uncovers new phishing-as-a-service operation with 'multiple entities' falling victim
Cyber-crime ZipLine attack uses 'Contact Us' forms, White House butler pic to invade sensitive industries 'Many dozens' targeted in ongoing campaign, CheckPoint researcher tells The Reg
Cyber-crime 'Impersonation as a service' the next big thing in cybercrime Underground forums now recruiting English-speaking social engineers
Cyber-crime Mozilla flags phishing wave aimed at hijacking trusted Firefox add-ons Devs told to exercise 'extreme caution' with emails disguised as account update prompts
Security Massive spike in use of .es domains for phishing abuse ¡Cuidado! Time to double-check before entering your Microsoft creds
Research ChatGPT creates phisher’s paradise by recommending the wrong URLs for major companies Crims have cottoned on to a new way to lead you astray
Cyber-crime That WhatsApp from an Israeli infosec expert could be a Iranian phish Charming Kitten unsheathes its claws and tries to catch credentials
Cyber-crime DeepSeek installer or just malware in disguise? Click around and find out 'BrowserVenom' is pure poison
Cyber-crime Hire me! To drop malware on your computer FIN6 moves from point-of-sale compromise to phishing recruiters
Cyber-crime Darcula adds AI to its DIY phishing kits to help would-be vampires bleed victims dry Because coding phishing sites from scratch is a real pain in the neck
Research Scattered Spider stops the Rickrolls, starts the RAT race Despite arrests, eight-legged menace targeted more victims this year
Cyber-crime Infosec pro Troy Hunt HasBeenPwned in Mailchimp phish 16,000 stolen records pertain to former and active mail subscribers
Research That 'angry guest' email from Booking.com? It's a scam, not a 1-star review Phishers check in, your credentials check out, Microsoft warns
Security Rather than add a backdoor, Apple decides to kill iCloud encryption for UK peeps Plus: SEC launches new crypto crime unit; Phishing toolkit upgraded; and more
CSO If you dread a Microsoft Teams invite, just wait until it turns out to be a Russian phish Roses aren't cheap, violets are dear, now all your access token are belong to Vladimir
Security India's banking on the bank.in domain cleaning up its financial services sector With over 2,000 banks in operation, a domain only they can use has potential to make life harder for fraudsters
Security DeepSeek's iOS app is a security nightmare, and that's before you consider its TikTok links PLUS: Spanish cops think they've bagged NATO hacker; HPE warns staff of data breach; Lazy Facebook phishing, and more!
Cyber-crime Google takes action after coder reports 'most sophisticated attack I've ever seen' Latest trope is tricky enough to fool even the technical crowd… almost
Security Europe coughs up €400 to punter after breaking its own GDPR data protection rules PLUS: Data broker leak reveals extent of info trading; Hot new ransomware gang might be all AI, no bark; and more
Security It's only a matter of time before LLMs jump start supply-chain attacks 'The greatest concern is with spear phishing and social engineering'
Cyber-crime Don't fall for a mail asking for rapid Docusign action – it may be an Azure account hijack phish Recent campaign targeted 20,000 folk across UK and Europe with this tactic, Unit 42 warns
Cyber-crime Phishers cast wide net with spoofed Google Calendar invites Not that you needed another reason to enable the 'known senders' setting
Cyber-crime Solana blockchain's popular web3.js npm package backdoored to steal keys, funds Damage likely limited to those running bots with private PKI access
Security Russian spies may have moved in next door to target your network Plus: Microsoft seizes phishing domains; Helldown finds new targets; Illegal streaming with Jupyter, and more
Security Helpline for Yakuza victims fears it leaked their personal info Organized crime types tend not to be kind to those who go against them, so this is nasty
Research Don't open that 'copyright infringement' email attachment – it's an infostealer Curiosity gives crims access to wallets and passwords
Cyber-crime Russian spies use remote desktop protocol files in unusual mass phishing drive The prolific Midnight Blizzard crew cast a much wider net in search of scrummy intel
Security ESET denies it was compromised as Israeli orgs targeted with 'ESET-branded' wipers Says 'limited' incident isolated to 'partner company'
Cyber-crime Microsoft says more ransomware stopped before reaching encryption Volume of attacks still surging though, according to Digital Defense Report
Security US and UK govts warn: Russia scanning for your unpatched vulnerabilities Also, phishing's easier over the phone, and your F5 cookies might be unencrypted, and more
Cybersecurity Month OpenAI says Chinese gang tried to phish its staff Claims its models aren't making threat actors more sophisticated - but is helping debug their code
Cyber-crime If you're holding important data, Iran is probably trying spearphish it It's election year for more than 50 countries and the Islamic Republic threatens a bunch of them
Research Mind your header! There's nothing refreshing about phishers' latest tactic It could lead to a costly BEC situation
Security Kremlin-linked COLDRIVER crooks take pro-democracy NGOs for phishy ride The latest of many attempts to stifle perceived threats to Putin's regime
Research Novel attack on Windows spotted in phishing campaign run from and targeting China Resources hosted at Tencent Cloud involved in Cobalt Strike campaign
CSO This uni thought it would be a good idea to do a phishing test with a fake Ebola scare Needless to say, it backfired in a big way
Security Iran named as source of Trump campaign phish, leaks Political stirrer Roger Stone may have been a weak link after personal emails cracked
Research Google raps Iran's APT42 for raining down spear-phishing attacks US politicians and Israeli officials among the top targets for the IRGC’s cyber unit
Cyber-crime Orion SA says scammers conned company out of $60 million Incident sounds like a BEC fraud targeting an unwitting staffer
Research Small CSS tweaks can help nasty emails slip through Outlook's anti-phishing net A simple HTML change and the warning is gone!
Security Users call on Microsoft to update Outlook's friendly name feature That one weird thing in Outlook that gives phishers and scammers an in to an inbox
Malware Month 'LockBit of phishing' EvilProxy used in more than a million attacks every month Leaves a trail of ransomware infections, data theft, business email compromise in its wake
Cyber-crime Cybercrooks spell trouble with typosquatting domains amid CrowdStrike crisis Latest trend follows various malware campaigns that began just hours after IT calamity
Security Singapore's banks to ditch texted one-time passwords Accessibility be damned, preventing phishing is the priority
Cyber-crime Cops cuff 22-year-old Brit suspected of being Scattered Spider leader Spanish plod make arrest at airport before he jetted off to Italy
Cyber-crime Two cuffed over suspected smishing campaign using 'text message blaster' Thousands of dodgy SMSes bypassed network filters in UK-first case, it is claimed
Security Google guru roasts useless phishing tests, calls for fire drill-style overhaul Current approaches aren't working and demonize security teams
Cyber-crime US charges Iranians with cyber snooping on government, companies Their holiday options are now far more restricted
Cyber-crime Fraudsters abused Apple Stores' third-party pickup policy to phish for profits Scam prevalent across Korea and Japan actually had some winners
Security Prolific phishing-made-easy emporium LabHost knocked offline in cyber-cop op Police emit Spotify Wrapped-style videos to let crims know they're being hunted
CSO X fixes URL blunder that could enable convincing social media phishing campaigns Poorly implemented rule allowed miscreants to deceive users with trusted URLs
Cyber-crime China encouraged armed offensive against Myanmar government to protest proliferation of online scams Report claims Beijing is most displeased by junta's failure to address slave labor scam settlements
Research As if working at Helldesk weren't bad enough, IT helpers now targeted by cybercrims Wave of Okta attacks mark what researchers are calling the biggest security trend of the year
Security Iranian charged over attacks against US defense contractors, government agencies $10M bounty for anyone with info leading to Alireza Shafie Nasab's identification or location
Cyber-crime Crooks hook hundreds of exec accounts after phishing in Azure C-suite pond Plenty of successful attacks observed with dangerous follow-on activity
AI + ML Deepfake CFO tricks Hong Kong biz out of $25 million Recordings of past vidchats suspected as source of fakery – so there's another class of data you need to lock down
Security BreachForums admin 'Pompourin' sentenced to 20 years of supervised release Also: Another UEFI flaw found; Kaspersky discovers iOS log files actually work; and a few critical vulnerabilities
Cyber-crime ShinyHunters chief phisherman gets 3 years, must cough up $5M Sebastien Raoult developed various credential-harvesting websites over more than 2 years
Cyber-crime Cybercrooks book a stay in hotel email inboxes to trick staff into spilling credentials Research highlights how major attacks like those exploiting Booking.com are executed
Security Hershey phishes! Crooks snarf chocolate lovers' creds Stealing Kit Kat maker's data?! Give me a break
Research Microsoft unveils shady shenanigans of Octo Tempest and their cyber-trickery toolkit Gang thought to be behind attack on MGM Resorts has a skillset larger than most cybercrime groups in existence
Security Telcos should compensate phished subscribers, suggests Singapore Regulator reckons letting scam texts through is a culpable act
Cyber-crime Pro-Russia group exploits Roundcube zero-day in attacks on European government emails With this zero-day, researchers say the 'scrappy' group is stepping up its operations
Cyber-crime D-Link clears up 'exaggerations' around data breach Who knew 3 million actually means 700 in cybercrime forum lingo?
Cyber-crime South Korea accuses North of Phish and Ships attack Kim Jong-un looks at industry's progress with green eyes, says South Korea's spy agency
Cyber-crime Singapore may split liability for phishing losses between banks and victims Won't someone please think of the banks?
Cyber-crime More Okta customers trapped in Scattered Spider's web Oktapus phishing campaign criminals are back in action
Security US government to investigate China's Microsoft email breach PLUS: Phishing campaign targets the C-suite; Cybercrime arrests in EU and Africa; and more
Security INTERPOL shutters '16shop' phishing-as-a-service outfit Alleged administrator cuffed in Indonesia, associate arrested in Japan, accused of selling fake Amazons for $60
Cyber-crime American and Southwest Airlines pilot candidate data exposed Time to start practising identity protection
Security North Korea created very phishy evil twin of Naver, South Korea's top portal Think of it as a fake Google tuned for credential capture and you'll understand why authorities want to kill it
Cyber-crime Posing as journalists, Pink Drainer pilfers $3.3M in crypto First the interview, then the phishing attack
Security You might have been phished by the gang that stole North Korea’s lousy rocket tech US, South Korea, warn 'Kimsuky' is a very sophisticated social engineer
Cyber-crime Ads for lucrative jobs in Asia fail to mention chance of slavery as crypto-scammer FBI warns jobseekers to be very skeptical of working holidays in Cambodia
Cyber-crime Russia's APT28 targets Ukraine government with bogus Windows updates Nasty emails designed to infect systems with info-stealing malware
AI + ML ChatGPT fans need 'defensive mindset' to avoid scammers and malware Palo Alto Networks spots suspicious activity spikes such as naughty domains, phishing, and worse
Cyber-crime UK Cyber Security Centre's scary new story: One phish, two phish, Russia phish, Iran phish
Security Mafia works remotely, too, it seems: 100+ people suspected of phishing, SIM swapping, email fraud cuffed
Security Russian gang behind SolarWinds hack returns with phishing attack disguised as mail from US aid agency
Security Scammers tried slurping folks' login details through 70,000 coronavirus-themed phishing URLs during 2020
Security You have to be very on-trend as a cybercrook – hence why coronavirus-themed phishing is this year's must-have look
Security Things are getting back to normal: Chinese hackers revert to bugging Tibetans after brief Euro campaign
Security Doctor, doctor, got some sad news, there's been a bad case of hacking you: UK govt investigates email fail
Security UK intel committee on Russia: Social media firms should remove state disinformation. What was that, MI5? ████████?
Software Southern Water to splash £50m on IT services to purify systems of planning, governance and internal controls
Security Microsoft sues coronavirus phishing spammers to seize their domains amid web app attacks against Office 354.5
Security Hundreds of forgotten corners of mega-corp websites fall into the hands of spammers and malware slingers
Security Your 2.3m Instagram fans won't stop the FBI... Web star accused of plotting to launder millions from cyber-crime
Security Honeypot behind sold-off IP subnet shows Cyberbunker biz hosted all kinds of filth, says SANS Institute
Security Australian PM says nation under serious state-run 'cyber attack' – Microsoft, Citrix, Telerik UI bugs 'exploited'
Security Anatomy of a business email scam: FBI dossier details how fraudster pocketed $500k+ by redirecting payments
Security There's Norway you're going to believe this: Government investment fund conned out of $10m in cyber-attack
Security Something a bit phishy in your inbox? You can now email suspected frauds straight to Blighty's web takedown cops
Security Weeks before US oil contract prices went negative, a spear-phishing crew went after oil firms. What did they get?
Security You know all those stories of leaky cloud buckets taken offline? Well, some may still be there, just badly hidden
Security No, the head of the World Health Organization has not emailed you – it's a message laced with malware
Security Online face mask sales scams, 400% uptick of coronavirus phishing reports: Brit cops' workload shifts online along with the nation's
Security Like a Virgin, hacked for the very first time... UK broadband ISP spills 900,000 punters' records into wrong hands from insecure database