North Korean state-sponsored hackers have successfully infected more than 30,000 devices worldwide by posing as legitimate corporate recruiters. The attackers use sophisticated social engineering tactics on professional networking platforms to trick unsuspecting job seekers into downloading malicious files disguised as job descriptions. Once executed, the malware grants the threat actors full remote access to steal […]
The FBI warns of highly targeted OAuth consent phishing attacks aimed at prominent figures, their families, and acquaintances. Attackers impersonate government officials, media personnel, or known contacts, luring victims with fake file shares or meeting invitations. Granting permission to a malicious OAuth application gives attackers long-term access to emails, files, and other sensitive account data. […]
Smaller organizations are nearing collapse under rising cyber threats, tight budgets, and a growing skills gap. WEF reports that 71% of cyber leaders say SMEs can no longer adequately defend against complex risks. Skills shortages, outdated tools, and staff burnout leave critical gaps as threats like AI phishing and ransomware surge. Compliance demands and cloud […]
Phishing and data leaks were last year’s biggest digital threats, according to Germany’s BSI. Cybercriminals now impersonate brands from logistics, e-commerce, and even governments to deceive users. AI-powered phishing emails are becoming harder to distinguish from real ones. Data breaches also pose serious risks. Nearly 87% of leaked records contain names and usernames. Sensitive details […]
Today, the FBI issued a warning to cryptocurrency companies and individuals holding cryptocurrencies about social engineering attacks attributed to North Korea. The U.S. law enforcement agency advises against storing information about crypto wallets on internet-connected devices. The “malicious cyber actors” pose as recruitment agencies or tech companies and attempt to trick employees of crypto companies […]
On Wednesday, August 14, 2024, Citizen Lab and Access Now issued a warning about spear-phishing attacks that are using ‘encrypted’ and ‘secured’ PDF files to lure victims to phishing sites. These sites aim to steal login credentials for Proton and Google accounts. According to these organizations, the attacks have been carried out by two groups […]
A widespread brand impersonation campaign has been targeting over 100 popular apparel, footwear, and clothing brands since June 2022. The campaign involves approximately 6,000 fake websites across at least 3,000 domains, including inactive ones. Brands such as Nike, Puma, Asics, Vans, Adidas, and many others have been impersonated.The campaign experienced a significant increase in activity […]
2023 Data Breach Investigations Report of which the dataset currentlycontains 953,894 incidents, of which 254,968 are confirmed breaches shows that the use of stolen credentials forms 44.7% of the cases. But what else can we learn? 74% of all breaches include the human element, with people being involved either via Error,Privilege Misuse, Use of stolen […]
Phishers are using a new technique called “file archiver in the browser” to trick victims. They create a phishing landing page that looks like legitimate file archiver software using HTML and CSS. The landing page is hosted on a .ZIP domain, making it appear more legitimate. Victims are redirected to a credential harvesting page when […]
Santander, a UK-based bank, is warning customers about an increase in impersonation scams where fraudsters pretend to be the bank in order to steal money from unsuspecting victims. The bank has identified several tactics used by scammers, including phishing emails and phone calls, fake websites, and even physical letters sent through the post. Santander is […]

