New 'Sneaky 2FA' Phishing Kit Targets Microsoft 365 Accounts with 2FA Code Bypass

Cybersecurity researchers have detailed a new adversary-in-the-middle (AitM) phishing kit that's capable of Microsoft 365 accounts with an aim to steal credentials and two-factor authentication (2FA) codes since at least October 2024.

Hackers Use Google Search Ads to Steal Google Ads Accounts

The attackers are running ads on Google Search impersonating Google Ads, showing as sponsored results that redirect potential victims to fake login pages hosted on Google Sites but looking like the official Google Ads homepage.

North Korean IT Worker Fraud Linked to 2016 Crowdfunding Scam and Fake Domains

The new evidence suggests that Pyongyang-based threat groups may have pulled off illicit money-making scams that predate the use of IT workers, SecureWorks Counter Threat Unit (CTU) said in a report shared with The Hacker News.

Phishing Trend Exploiting YouTube URLs Through Microsoft Office 365 Expiry Themes

Researchers at Cyderes warned of a recent wave of phishing campaigns leveraging cleverly disguised URLs and Microsoft 365 password expiry lures to trick users into divulging sensitive credentials.

Phishing Texts Trick Apple iMessage Users Into Disabling Protection

Apple iMessage automatically disables links in messages from unknown senders for protection. However, if users reply to these messages or save the sender's contact information, the links get re-enabled, which can be abused by scammers.

New Web3 attack exploits transaction simulations to steal crypto

The attack, spotted by ScamSniffer, highlights a flaw in transaction simulation mechanisms used in modern Web3 wallets, meant to safeguard users from fraudulent and malicious transactions.

Phishing Scam Targets Job Seekers with XMRig Cryptominer

CrowdStrike researchers warned of a phishing campaign that exploits its own branding to distribute a cryptocurrency miner that's disguised as an employee CRM application as part of a supposed recruitment process.

“Butcher Shop” Phishing Campaign Targets Legal, Government and Construction Firms

Obsidian uncovered a new phishing campaign targeting Microsoft 365 accounts. The campaign uses a mix of email redirects and open redirect vulnerabilities, which makes it hard for traditional phishing solutions to detect and block.

Fake Government Officials Use Remote Access Tools for Card Fraud

Researchers at Group-IB uncovered a sophisticated, multi-stage fraud campaign designed to trick consumers into sharing their card details. The fraudsters purchase logins to government accounts, originally obtained via infostealers, from the dark web.

Scammers Exploit Microsoft 365 to Target PayPal Users

Fortinet researchers identified a new phishing technique exploiting PayPal’s money request feature, using a legitimate PayPal money request that may appear genuine to recipients.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags