Email Security News Feed

With Retail Cyberattacks on the Rise, Customers Find Orders Blocked and Shelves Empty

Beyond potentially halting sales of physical goods, breaches can expose customers’ personal data to future phishing or fraud attempts. The post With Retail Cyberattacks on the Rise, Customers Find Orders Blocked and Shelves Empty appeared first on SecurityWeek .

Read Original
FIN6 hackers pose as job seekers to backdoor recruiters’ devices

In a twist on typical hiring-related social engineering attacks, the FIN6 hacking group impersonates job seekers to target recruiters, using convincing resumes and phishing sites to deliver malware. [...]

Read Original
20 Top-Level Domain Names Abused by Hackers in Phishing Attacks

Disclosure: This article was provided by ANY.RUN. The information and analysis presented are based on their research and findings.

Read Original
Google patched bug leaking phone numbers tied to accounts

A vulnerability allowed researchers to brute-force any Google account's recovery phone number simply by knowing a their profile name and an easily retrieved partial phone number, creating a massive risk for phishing and SIM-swapping attacks. [...]

Read Original
Weekly Update 455

Presently sponsored by: Malwarebytes Browser Guard blocks phishing, ads, scams, and trackers for safer, faster browsing The bot-fighting is a non-stop battle. In this week's video, I discuss how we're tweaking Cloudflare Turnstile and combining more attributes around how bot-like requests are, and... it almost worked. Just as I was preparing to write this intro, I found a small spike of anomalous

Read Original
Phishing e-mail that hides malicious link from Outlook users, (Wed, Jun 4th)

A phishing email impersonating a Czech bank was recently observed targeting Outlook users.

Read Original
Trustifi Raises $25 Million for AI-Powered Email Security

Trustifi has raised $25 million in Series A funding to accelerate its product roadmap and go-to-market initiatives. The post Trustifi Raises $25 Million for AI-Powered Email Security appeared first on SecurityWeek .

Read Original
Scattered Spider: Three things the news doesn’t tell you

Scattered Spider is described as an evolving, identity-first threat model rather than a single group. They utilize techniques like v

Read Original
Bling slinger Cartier tells customers to be wary of phishing attacks after intrusion

Luxury jeweler Cartier experienced a data breach that exposed customer data to cybercriminals. As a result, Cartier is warning customers to be vigilant against potential phishing attacks, as the compromised information could be used to craft more convincing fraudulent emails. This incident highlights how data breaches can directly increase the risk of targeted email-based threats like phishing.

Read Original
Weekly Update 454

Presently sponsored by: Malwarebytes Browser Guard blocks phishing, ads, scams, and trackers for safer, faster browsing We're two weeks in from the launch of the new HIBP, and I'm still recovering. Like literally still recovering from the cold I had last week and the consequent backlog. A major launch like this isn't just something you fire and forget; instead, it

Read Original
Firebase, Google Apps Script Abused in Fresh Phishing Campaigns

Security researchers have identified recent phishing campaigns exploiting Google's Firebase and Google Apps Script. Attackers are using these legitimate services to host malicious content, including malware and fake login pages. This abuse facilitates phishing attacks, often initiated via email,

Read Original
Chinese Phishing Service Haozi Resurfaces, Fueling Criminal Profits

A Chinese-language PhaaS platform Haozi is making cybercrime easy with no tech skills needed. Discover how this plug-and-play service facilitated over $280,000 in illicit transactions.

Read Original
Threat actors abuse Google Apps Script in evasive phishing attacks

Threat actors are exploiting Google Apps Script to host phishing pages, making these attacks highly evasive and difficult for traditional security tools to detect. This technique leverages a trusted platform to bypass email security defenses and deliver malicious content, posing a significant challenge for preventing phishing and potential data breaches.

Read Original
Pakistan Arrests 21 in ‘Heartsender’ Malware Service

Authorities in Pakistan have arrested 21 individuals accused of operating "Heartsender," a once popular spam and malware dissemination service that operated for more than a decade. The main clientele for HeartSender were organized crime groups that tried to trick victim companies into making payments to a third party, and its alleged proprietors were publicly identified by KrebsOnSecurity in 2021 after they inadvertently infected their computers with malware.

Read Original
New Phishing Campaign Uses DBatLoader to Drop Remcos RAT: What Analysts Need to Know

Disclosure: This article was provided by ANY.RUN. The information and analysis presented are based on their research and findings.

Read Original