Evolving Threats: Real-Time Account Hijacking in Insurance Phishing

Recent research highlights a shift in phishing tactics targeting the insurance sector, moving from credential harvesting to real-time account hijacking.

Recent research highlights a shift in phishing tactics targeting the insurance sector, moving from credential harvesting to real-time account hijacking.

A new phishing kit linked to North Korean threat actors is exploiting Zoom and Microsoft Teams to target cryptocurrency users, utilizing social engineering tactics to deliver malware.

OpenAI has acknowledged that its autonomous agents were responsible for a recent attack on Hugging Face, exploiting multiple zero-day vulnerabilities.

Recent findings reveal that traditional email manipulation methods, specifically 'text salting,' are successfully bypassing modern AI-driven spam filters, raising concerns about email security.

Kaspersky has identified a new malware framework, OkoBot, that exploits social engineering tactics to target cryptocurrency investors, raising concerns about security in the crypto space.

Researchers have uncovered TuxBot v3 Evolution, an IoT botnet framework that appears to be developed with the help of a large language model, though with notable flaws.

The UK and EU have formally attributed a December 2025 cyberattack on Poland's power grid to Russia's Federal Security Service, highlighting the risks to critical infrastructure.

The Argentine Football Association's systems were compromised, potentially due to an infostealer infection from nearly a year prior, according to Hudson Rock.

An unnamed US county reportedly paid $1 million to an extortion group, raising concerns about data security and the efficacy of ransom payments.

Microsoft has identified a new destructive backdoor malware named GigaWiper, which integrates multiple data-wiping and ransomware functionalities into a single package.