255 Fake Accounts Used to Send Malicious Excel Files to 80,000 Freelancers
A Russian national has been extradited to the United States to face charges over an alleged phishing operation that used 255 fake accounts on a freelance emp...
20 articles
A Russian national has been extradited to the United States to face charges over an alleged phishing operation that used 255 fake accounts on a freelance emp...
The campaign uses DLL sideloading and PNG steganography to evade detection.
Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. [.
Google has released a new update for the Chrome Stable Channel on desktop platforms, addressing 26 security vulnerabilities. This includes two critical use-a...
An active malware campaign that abuses counterfeit download pages for trusted software brands including Microsoft Edge, Kaspersky and Razer to compromise Win...
Sift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: loc...
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Micr...
Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response.
A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malwa...
Iran-linked threat actor Mirage Kitten is targeting software developers with fake recruitment assessments that hide two newly identified cross-platform remot...
Project Watershed 250, a six-month pilot program, will test cybersecurity and artificial intelligence tools provided by private companies like Microsoft, Ref...
Infostealer malware, including families such as Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer on macOS, is stealing active Claud...
A coordinated social-engineering campaign dubbed Spring Ring used external Microsoft Teams accounts to impersonate corporate IT help desk staff and target mo...
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to...
A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stea...
The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot.
Attackers are using fake CAPTCHA prompts to trick victims into running malicious PowerShell commands as part of a multi-stage intrusion campaign that can est...
The Windows infostealer uses several evasion measures to remain mostly invisible to security systems.
BraZetsu, a Python-based Windows malware framework allegedly operated by the Brazilian threat actor Exilware to identify, profile, and monetize compromised c...
A newly analyzed Windows backdoor named SLEEPWALKER uses a passive command-and-control model designed to evade conventional beaconing-based detections. Raw-p...