< ciso
brief />
Tag Banner

All news with #phishing tag

746 articles · page 20 of 38

Watch for Winter Olympics Scams and Cyberthreats in 2026

⚠️ Cybercriminals commonly exploit major sporting events like the Milano‑Cortina 2026 Winter Olympics, using phishing, fake ticketing and streaming sites, rogue apps, SEO poisoning, QR-code scams and AI-driven deepfakes to steal data or money. Fans should purchase only from official ticket and merchandise channels, use the official Olympics app, and avoid pirated streams and unsolicited offers. Protect devices with reputable anti‑malware, avoid public Wi‑Fi or use a VPN, and be cautious with links, QR codes and marketplace listings.
read more →

Large-scale cloud storage payment scam floods inboxes

⚠️ Over recent months a global scam campaign has bombarded users with fraudulent cloud-storage renewal notices claiming payment failures and imminent deletion of photos and backups. The emails use auto-generated sender domains and links hosted on Google Cloud Storage that redirect to phishing pages impersonating cloud portals. Those pages run fake storage scans, promote unrelated affiliate products, and lead to checkout forms that collect credit card details. Delete these messages and verify billing only through official apps or websites.
read more →

January 2026 security roundup with Tony Anscombe — Lessons

🛡️ January brought several high-impact incidents that underline persistent enterprise risks. ServiceNow patched a critical AI-driven vulnerability (CVE-2025-12420) that could let unauthenticated actors impersonate admins on its AI platform. Unsecured Zendesk systems were abused for a large spam campaign, while the World Economic Forum reports cyber-fraud has overtaken ransomware as CEOs' top worry. Nike is also probing an alleged theft of 1.4 TB of data.
read more →

NCA and NatWest Warn Businesses of Invoice Fraud Risks

⚠️ NatWest and the UK's National Crime Agency (NCA) have launched a joint awareness campaign to highlight rising invoice fraud affecting businesses, including BEC and payment redirection. The initiative warns that fraudsters impersonate suppliers, intercept emails and pressure victims into urgent payments that are then diverted. Guidance urges businesses to Check, Verify, Never transfer funds until payment details are independently confirmed. The campaign also stresses that Accounts Payable and Finance teams are frequent targets of these schemes.
read more →

Threat Source: Resilience, trends, and hard truths

📰 Hazel Burton opens this Threat Source newsletter by acknowledging how difficult it can be to stay engaged with the news and suggests small, human respites—like the U.K. show Taskmaster—to remind readers creativity and levity persist under pressure. On the technical side, Cisco Talos Incident Response’s Q4 2025 report shows exploitation of public-facing applications remains the leading initial access vector (down from 62% to ~40%), while phishing and credential harvesting rose and ransomware incidents fell to 13% with Qilin still common. The newsletter urges rapid patching, correct MFA configuration and monitoring, and comprehensive logging to detect suspicious activity.
read more →

Microsoft Teams to add report feature for suspicious calls

📞 Microsoft will add a Report a Call feature in Teams that lets users flag suspicious or unwanted one-to-one calls as potential scams or phishing. The option appears in call history on Windows, Mac and the web and is enabled by default; administrators can disable it in the Teams Admin Center under Calling settings. Limited metadata — timestamps, duration, caller ID and participant Teams IDs — is shared with the organization and Microsoft, and reports are viewable in the Microsoft Defender portal or Teams Admin Center. Targeted Release begins mid-March, with worldwide general availability planned by late April.
read more →

Four Arrested in Discord SWATting and Doxing Crackdown

🚨 Hungarian and Romanian police arrested four young men accused of orchestrating Discord-based SWATting and doxing campaigns that triggered hoax bomb threats and endangered targeted individuals. Law enforcement released video of coordinated raids in which computers, phones and other digital evidence were seized as investigators traced anonymous calls to spoofed numbers. Suspects, aged 16 to 20, face investigations and charges including misuse of personal data and public endangerment; authorities stress these actions are serious crimes with potentially life‑threatening consequences.
read more →

AI-Powered Polymorphic Attacks Enable Runtime Phishing

🔒 Researchers at Unit 42 demonstrated how attackers can convert benign webpages into bespoke phishing pages by calling LLMs from client-side code to generate malicious JavaScript in real time. This polymorphic technique assembles malware inside the victim’s browser, leaving no static payload and evading many traditional network and signature controls. Defenders are advised to prioritize message-layer protections, secure web gateways, and secure enterprise browsers to block the initial lure and the last mile reassembling of malicious code.
read more →

ClickFix Uses Signed App-V Scripts to Deploy Amatera

🔒 Blackpoint researchers describe a campaign that chains ClickFix-style fake CAPTCHA prompts with a signed Microsoft App-V script to proxy PowerShell and deliver the Amatera information stealer. Victims are tricked into pasting a command into the Windows Run dialog that abuses SyncAppvPublishingServer.vbs to load an in-memory loader, which pulls configuration from a public Google Calendar and retrieves a PNG containing an encrypted PowerShell payload. The attack targets systems with App-V enabled (Enterprise/Education), relies on manual user interaction, and uses living-off-the-land techniques and trusted services to frustrate detection and automated analysis.
read more →

Drowning in Spam? Ten Reasons and How to Stop It Now

📧 Inboxes can be overwhelmed by spam and scams for many reasons, from large-scale data breaches and web scraping to updated scam kits and AI-assisted phishing that evade filters. Attackers use these feeds to deliver malspam, impersonate trusted brands, or bury critical alerts through email bombing. Reduce exposure by keeping profiles private, using email-masking services, avoiding replies or unsubscribe links, and deploying reputable security software with layered anti-phishing and anti-spam protections.
read more →

New MaaS 'Stanley' enables phishing Chrome extensions

⚠️Researchers at Varonis warn of a new malware‑as‑a‑service named Stanley that sells malicious browser extensions engineered to pass review and appear on the Chrome Web Store. The extensions overlay a full‑screen iframe with attacker-controlled phishing content while leaving the address bar intact, and claim silent auto‑installation on Chromium browsers. Stanley offers subscription tiers, including a Luxe Plan that assists with publishing extensions, and provides operator controls for targeting, notifications, and session correlation.
read more →

Tax Phishing Targets Indian Users to Deliver Blackmoon

🧾 Cybersecurity researchers uncovered a phishing campaign impersonating India's Income Tax Department that delivers a multi-stage backdoor to targeted users. The attackers distribute a ZIP containing an executable that sideloads a malicious DLL, performs anti-analysis checks, and fetches further payloads, ultimately deploying a Blackmoon variant alongside a repurposed SyncFuture TSM RMM tool. The operation employs UAC bypass, process masquerading, antivirus exclusion manipulation, and numerous helper scripts to establish persistent, covert access for long-term monitoring and data exfiltration.
read more →

Researchers Expose HaxorSEO Backlink Marketplace Abuse

🔎 Security researchers at Fortra’s Intelligence and Research Experts (FIRE) uncovered a Telegram and WhatsApp marketplace called HaxorSEO offering over 1,000 backlinks on pre-compromised, legitimate domains. Operators install webshells and inject backlinks that point to phishing or malware sites, advertising SEO metrics like PA, DA and DR to sell effectiveness. Listings cost as little as $6 each and can help fraudulent pages outrank genuine services. Users are advised to bookmark sensitive login pages and verify domains before entering credentials.
read more →

1Password Adds Pop-up Warnings for Suspected Phishing

⚠️ 1Password has added a browser pop-up that warns users when a visited URL appears to be a phishing or typosquatted site, aiming to prevent manual credential entry on deceptive pages. The feature will be enabled automatically for individual and family plans, while enterprise admins can turn it on via Authentication Policies in the admin console. 1Password cites rising AI-assisted phishing and internal survey data on click-through and credential reuse as motivating factors.
read more →

1Password Adds Pop-Up Alerts for Suspected Phishing

🔔 1Password has added an in-product pop-up that warns users when a visited URL looks like a potential phishing or typosquatted site, aiming to prevent manual credential entry. The feature is enabled by default for individual and family plan users; admins can activate it for employees via Authentication Policies. 1Password says the alerts are intended to make users pause and inspect URLs more closely, addressing cases where autofill protections alone are insufficient.
read more →

Multi-Stage Phishing Targets Russia with Amnesia RAT

🔒 Fortinet researchers detailed a multi-stage phishing campaign targeting Russian organizations that delivers the Amnesia RAT and Hakuna Matata ransomware. Attackers use business-themed decoy documents and malicious LNK files that fetch staged PowerShell loaders from GitHub while binary payloads are hosted on Dropbox. The chain abuses defendnot to disable Microsoft Defender, leverages Telegram bots for telemetry and exfiltration, and assembles payloads in memory to minimize disk artifacts. Targeted recipients include HR and payroll staff, enabling credential theft, surveillance, and destructive encryption.
read more →

Building Cyber Readiness Early: Youth Education Imperative

🔐 Cyber security should begin in childhood, not only as a late-stage workforce specialization. The piece argues that threat actors target schools, hospitals, municipalities and small businesses as aggressively as large enterprises, and that waiting for workforce pipelines to mature leaves communities exposed. Early, practical education—covering ransomware awareness, phishing resistance, hands-on skills and teacher training—reduces immediate risk and strengthens future talent pools.
read more →

Phishing Leads to LogMeIn RMM Deployment for Persistence

🔒 Cybersecurity researchers describe a two-wave phishing campaign that uses fake Greenvelope invitations to harvest Microsoft Outlook, Yahoo! and AOL credentials, then leverages those stolen logins to register and deploy legitimate LogMeIn RMM tools. Attackers deliver a signed executable, GreenVelopeCard.exe, containing a JSON configuration that silently installs LogMeIn Resolve and connects to an attacker-controlled URL. The RMM is configured for persistent, elevated access and hidden scheduled tasks to ensure survival and ongoing remote control.
read more →

Microsoft Flags Multi-Stage AitM Phishing in Energy Sector

🔒 Microsoft warns of a multi-stage adversary-in-the-middle (AitM) phishing and BEC campaign targeting the energy sector. The attackers abused SharePoint file-sharing and legitimate trusted addresses (a living-off-trusted-sites, LOTS, technique) to deliver credential-harvesting links, then used stolen session cookies and inbox rules to persist and hide activity. Microsoft says simple password resets are insufficient; organizations must revoke sessions, remove malicious rules, and enforce phishing-resistant controls.
read more →

Microsoft Teams adds brand impersonation call warnings

🔔 Microsoft is introducing Brand Impersonation Protection for Teams Calling, rolling out to the targeted release ring in mid‑February and enabled by default. The feature inspects incoming VoIP calls from first‑time external contacts for signs of brand impersonation and displays high‑risk call warnings before suspicious calls are answered. Users can accept, block, or end flagged calls, and alerts may persist during a conversation if suspicious signals continue. IT teams are advised to update support materials and brief helpdesks ahead of the rollout.
read more →