phishing

Attackers conceal phishing lures using invisible Unicode characters News

Attackers conceal phishing lures using invisible Unicode characters

Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to ev...
39 New Methods That Compromise Passkey Authentication News

39 New Methods That Compromise Passkey Authentication

Passkeys were introduced with a strong security proposition. Replace passwords with public key cryptography, bind the cr...
US charges Russian for infecting 80,000 freelancers with malware News

US charges Russian for infecting 80,000 freelancers with malware

A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousa...
Hackers abuse Faronics Deploy admin tool to install ScreenConnect News

Hackers abuse Faronics Deploy admin tool to install ScreenConnect

Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative co...
Hackers abuse npm mirrors to host phishing redirect pages News

Hackers abuse npm mirrors to host phishing redirect pages

Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redir...
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes News

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to un...
ReliaQuest、ShinyHuntersへの侵入事件を受け、データ窃取攻撃の未遂を確認 News

ReliaQuest、ShinyHuntersへの侵入事件を受け、データ窃取攻撃の未遂を確認

サイバーセキュリティ企業のReliaQuestは、ハッカーがセキュリティチームのメンバーを装った結果、同社の従業員1名がソーシャルエンジニアリング攻撃の標的となったことを確認した。 週末に発表された声明の中で、ReliaQuestは、攻撃者...
Microsoft Teamsを標的としたフィッシングキャンペーンで、新たな「SynkLoader」マルウェアが拡散されている News

Microsoft Teamsを標的としたフィッシングキャンペーンで、新たな「SynkLoader」マルウェアが拡散されている

「SynkLoader」と呼ばれる、これまで知られていなかったマルウェアファミリーが、Microsoft Teamsを標的としたフィッシング攻撃を通じて拡散されており、偽のロック画面を利用して認証情報を盗み出そうとしています。 攻撃者は標的...
MSPが、メールフィルターで見逃されたフィッシング攻撃をどのように検知できるか News

MSPが、メールフィルターで見逃されたフィッシング攻撃をどのように検知できるか

顧客は毎日何千通ものメールを受け取っていますが、たった1通の説得力のあるメッセージがあれば、一見無害に見えるメールが、あなたが後始末を迫られるセキュリティインシデントへと変貌してしまうのです。 AIはフィッシングの手法を根本的に変え、攻撃の...
現代の攻撃チェーン:AI時代のGoogle Workspaceセキュリティの再考 News

現代の攻撃チェーン:AI時代のGoogle Workspaceセキュリティの再考

Material Security セキュリティ担当副社長、ラジャン・カプール この2ヶ月間、私はVercelの侵害事件とComposioの侵害事件について、それぞれ別々に記事を書いてきました。どちらの事例も、それ自体で学ぶべき教訓がありま...