No, you’re not fired – but beware of job termination scams

Some employment scams are shifting focus from “hiring” to “firing” staff, creating a new type of scam known as job termination scams. These scams exploit individuals who are currently employed or searching for jobs.

Phishing Attack Hides JavaScript Using Invisible Unicode Trick

A new JavaScript obfuscation method utilizing invisible Unicode characters to represent binary values is being actively abused in phishing attacks targeting affiliates of an American political action committee (PAC).

Black-Hat SEO Campaign Lures Indian Users Into Visiting Potential Phishing Schemes

In a recent development, analysts at CloudSEK have discovered the much maligned use of black hat Search Engine Poisoning by threat actors, to push Rummy and Investment focused websites to unsuspecting users.

Astaroth Phishing Kit Bypasses 2FA to Hijack Gmail and Microsoft Accounts

According to SlashNext’s research, the Astaroth phishing kit is designed to bypass two-factor authentication (2FA) through a combination of session hijacking and real-time credential interception.

Russian-Linked Hackers Found Using 'Device Code Phishing' to Hijack Accounts

The Storm-2372 actors use a phishing technique called 'device code phishing.' Users are lured to log in to productivity apps while the actors capture the information from the authentication codes to hijack their accounts.

Hackers Use CAPTCHA Trick on Webflow CDN PDFs to Bypass Security Scanners

A widespread phishing campaign has been observed leveraging bogus PDF documents hosted on the Webflow content delivery network (CDN) with an aim to steal credit card information and commit financial fraud.

Scammers Use Fake Facebook Copyright Notices to Hijack Accounts

This campaign, which began around December 20th, 2024, primarily focuses on companies within the EU, the US, and Australia. Still, some instances have also been detected in Chinese and Arabic languages, indicating a global reach.

Scalable Vector Graphics Files Pose a Novel Phishing Threat

Attackers have been observed using the graphics file format scalable vector graphics (SVG) for this purpose. SVGs contain Extensible Markup Language (XML)-like text instructions to draw resizable, vector-based images on a computer.

Sophisticated Phishing Campaign Targets Ukraine’s Largest Bank

A new phishing campaign orchestrated by the financially motivated threat group UAC-0006 has been discovered targeting customers of PrivatBank, Ukraine’s largest state-owned financial institution.

Hackers Spoof Microsoft ADFS Login Pages to Steal Credentials

A help desk phishing campaign targets an organization's Microsoft Active Directory Federation Services (ADFS) using spoofed login pages to steal credentials and bypass multi-factor authentication (MFA) protections.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags