Evolving Threats: Real-Time Account Hijacking in Insurance Phishing

Recent research highlights a shift in phishing tactics targeting the insurance sector, moving from credential harvesting to real-time account hijacking.

Recent research highlights a shift in phishing tactics targeting the insurance sector, moving from credential harvesting to real-time account hijacking.

A new phishing kit linked to North Korean threat actors is exploiting Zoom and Microsoft Teams to target cryptocurrency users, utilizing social engineering tactics to deliver malware.

Danish e-commerce platform Miinto has disclosed a data breach affecting customer order information, prompting warnings about potential phishing attacks.

This week’s cybersecurity landscape reveals multiple vulnerabilities affecting various systems, including a significant flaw in Apple's Hide My Email service and a new ransomware phishing campaign targeting small businesses.

The EvilTokens phishing kit has evolved, enabling attackers to bypass multi-factor authentication and gain unauthorized access to Microsoft 365 applications, according to Cisco Talos.

The Security Service of Ukraine, in collaboration with the FBI, has revealed a phishing campaign by Russian intelligence aimed at stealing messaging credentials from officials and civilians alike.

The FBI and CISA have issued an updated warning regarding Russian intelligence phishing campaigns aimed at Signal users, specifically focusing on the theft of Backup Recovery Keys.

A phishing campaign linked to North Korea has targeted developers with over 250 fraudulent job offers, aiming to steal credentials and cryptocurrency.

A newly disclosed vulnerability in OpenAI's ChatGPT could allow attackers to exploit the AI's handling of Markdown links and images, creating a potential phishing surface.

Recent findings reveal two distinct malware campaigns, Grandoreiro and BTMOB, targeting Windows and Android users in various regions, including Latin America and Europe.