Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 5 / 8
142 résultats taggé phishing  ✕
D-Link confirms data breach after employee phishing attack https://www.bleepingcomputer.com/news/security/d-link-confirms-data-breach-after-employee-phishing-attack/
21/10/2023 12:40:05
QRCode
archive.org
thumbnail

Taiwanese networking equipment manufacturer D-Link confirmed a data breach linked to information stolen from its network and put up for sale on BreachForums earlier this month.

bleepingcomputer EN 2023 D-Link Data-Breach Phishing BreachForums
LinkedIn Smart Links Fuel Credential Phishing Campaign https://cofense.com/blog/linkedin-smart-links-credential-phishing-campaign/
13/10/2023 09:21:57
QRCode
archive.org
thumbnail

Learn what LinkedIn Smart Links are and how they're being used to bypass email security gateways. Get up-to-date information on this credential phishing threat

cofense EN 2023 LinkedIn Smart Links Phishing Campaign
When MFA isn't actually MFA https://retool.com/blog/mfa-isnt-mfa/
16/09/2023 12:22:57
QRCode
archive.org
thumbnail

Due to a recent Google change, MFA isn't truly MFA.

retool EN 2023 incident retool MFA SMS-based phishing attack GoogleAuthenticator
Attacker combines phone, email lures into believable, complex attack chain https://news.sophos.com/en-us/2023/08/10/image-spam-attack/
13/09/2023 21:44:02
QRCode
archive.org
thumbnail

A social engineering phone call lends authenticity to the attacker’s malicious email

sophos EN 2023 switzerland phone email lures phishing
“MrTonyScam” — Botnet of Facebook Users Launch High-Intent Messenger Phishing Attack on Business Accounts https://labs.guard.io/mrtonyscam-botnet-of-facebook-users-launch-high-intent-messenger-phishing-attack-on-business-3182cfb12f4d
12/09/2023 07:25:33
QRCode
archive.org

Facebook’s Messenger platform has been heavily abused in the past month to spread endless messages with malicious attachments from a swarm of fake and hijacked personal accounts. These threat actors are targeting millions of business accounts on Facebook’s platform — from highly-rated marketplace sellers to large corporations, with fake business inquiries, achieving a staggering “success rate” with approximately 1 out of 70 infected!

labs.guard.io EN 2023 Messenger Facebook Phishing Attack Botnet
W3LL oiled machine: Group-IB uncovers covert BEC phishing empire targeting Microsoft 365 https://www.group-ib.com/media-center/press-releases/w3ll-phishing-report/
07/09/2023 21:07:01
QRCode
archive.org

The report details the operations of W3LL, a threat actor behind a phishing empire that has remained largely unknown until now. Group-IB’s Threat Intelligence and Cyber Investigations teams have tracked the evolution of W3LL and uncovered that they played a major role in compromising Microsoft 365 business email accounts over the past 6 years. The threat actor created a hidden underground market, named W3LL Store, that served a closed community of at least 500 threat actors who could purchase a custom phishing kit called W3LL Panel, designed to bypass MFA, as well as 16 other fully customized tools for business email compromise (BEC) attacks. Group-IB investigators identified that W3LL’s phishing tools were used to target over 56,000 corporate Microsoft 365 accounts in the USA, Australia and Europe between October 2022 and July 2023. According to Group-IB’s rough estimates, W3LL’s Store’s turnover for the last 10 months may have reached $500,000. All the information collected by Group-IB’s cyber investigators about W3LL has been shared with relevant law enforcement organizations.

PDF Document

group-ib EN 2023 BEC phishing W3LL Microsoft365
Okta customers targeted in social engineering scam https://www.scmagazine.com/news/okta-customers-targeted-in-social-engineering-scam
06/09/2023 14:23:10
QRCode
archive.org
thumbnail

Help desk staff duped into resetting MFA on Okta super admin accounts, allowing threat actors to move laterally across targeted organizations.

scmagazine EN 2023 Okta phishing MFA scam
Adversary On The Defense: ANTIBOT.PW https://inquest.net/blog/adversary-on-the-defense-antibot-pw/
28/08/2023 20:55:37
QRCode
archive.org
thumbnail

Discover the lifecycle of a commercial web traffic filtering service originating from a GitHub project and how it found success within phishing operations, including how it evolved into a commercial platform offering under new branding.

inquest EN 2023 analysis ANTIBOT.PW phishing
Phishing pages placed on hacked websites https://securelist.com/phishing-with-hacked-sites/110334/
18/08/2023 14:23:35
QRCode
archive.org
thumbnail

Scammers are hacking websites powered by WordPress and placing phishing pages inside hidden directories. We share some statistics and tips on recognizing a hacked site.

securelist EN 2023 Data-theft Phishing websites Website-Hacks Wordpress
Threat Actors Add .zip Domains to Their Phishing Arsenals https://www.fortinet.com/blog/industry-trends/threat-actors-add-zip-domains-to-phishing-arsenals
20/07/2023 23:11:25
QRCode
archive.org
thumbnail

In the evolving cybersecurity landscape, understanding the phishing threat has become more critical than ever. Read into a new threat resulting from the addition of a new Top-Level Domain (TLD), '.ZIP'.

fortinet EN 2023 Threat-Trends phishing TLD
WormGPT: New AI Tool Allows Cybercriminals to Launch Sophisticated Cyber Attacks https://thehackernews.com/2023/07/wormgpt-new-ai-tool-allows.html
15/07/2023 14:11:42
QRCode
archive.org
thumbnail

A new generative AI cybercrime tool called WormGPT is making waves in underground forums. It empowers cybercriminals to automate phishing attacks.

thehackernews EN 2023 WormGPT AI ChatGPT cybercrime automate phishing attacks
Cybercriminalité : sept suspects identifiés pour du « phishing / hameçonnage » https://www.vd.ch/toutes-les-actualites/actualite/news/i-cybercriminalite-sept-suspects-identifies-pour-du-phishing-hameconnage
15/07/2023 13:38:32
QRCode
archive.org
thumbnail

Entre avril 2022 et juin 2023, une quarantaine de plaintes relatives à des cas de « phishing / hameçonnage », pour un montant de plus de 170'000…

vd CH FR 2023 Cybercriminalité SMS Smishing phishing suspects identifiés
Storm-0978 attacks reveal financial and espionage motives https://www.microsoft.com/en-us/security/blog/2023/07/11/storm-0978-attacks-reveal-financial-and-espionage-motives/
11/07/2023 20:52:20
QRCode
archive.org
thumbnail

Microsoft has identified a phishing campaign conducted by the threat actor tracked as Storm-0978 targeting defense and government entities in Europe and North America. The campaign involved the abuse of CVE-2023-36884, which included a zero-day remote code execution vulnerability exploited via Microsoft Word documents.

microsoft EN 2023 Storm-0978 Follina CVE-2023-36884 ero-day remote phishing
Microsoft Encrypted Restricted Permission Messages Deliver Phishing | Trustwave https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-encrypted-restricted-permission-messages-deliver-phishing/
15/06/2023 08:21:00
QRCode
archive.org
thumbnail

Over the past few days, we have seen phishing attacks that use a combination of compromised Microsoft 365 accounts and .rpmsg encrypted emails to deliver the phishing message.

trustwave EN 2023 Phishing Microsoft Email Microsoft-365 rpmsg encrypted M365
File Archiver In The Browser https://mrd0x.com/file-archiver-in-the-browser/?no-cache=1
23/05/2023 22:05:36
QRCode
archive.org

This article explores a phishing technique that emulates a file archiver software in the browser while using a .zip domain.

mrd0x EN 2023 tld domain phishing technique
Securonix Threat Labs Security Advisory: Latest Update: Ongoing MEME#4CHAN Attack/Phishing Campaign uses Meme-Filled Code to Drop XWorm Payloads https://www.securonix.com/blog/securonix-threat-labs-security-meme4chan-advisory/
15/05/2023 21:16:07
QRCode
archive.org
thumbnail

An unusual attack/phishing campaign delivering malware while using meme-filled code and complex obfuscation methods continues dropping Xworm payloads for the last few months and is still ongoing today.

securonix EN 2023 XWorm Payloads MEME#4CHAN Phishing Meme-Filled
New phishing-as-a-service tool “Greatness” already seen in the wild https://blog.talosintelligence.com/new-phishing-as-a-service-tool-greatness-already-seen-in-the-wild/
11/05/2023 22:01:18
QRCode
archive.org
thumbnail
  • A previously unreported phishing-as-a-service (PaaS) offering named “Greatness” has been used in several phishing campaigns since at least mid-2022. Greatness incorporates features seen in some of the most advanced PaaS offerings, such as multi-factor authentication (MFA) bypass, IP filtering and integration with Telegram bots.
  • Greatness, for now, is only focused on Microsoft 365 phishing pages, providing its affiliates with an attachment and link builder that creates highly convincing decoy and login pages. It contains features such as having the victim’s email address pre-filled and displaying their appropriate company logo and background image, extracted from the target organization’s real Microsoft 365 login page. This makes Greatness particularly well-suited for phishing business users.
  • An analysis of the domains targeted in several ongoing and past campaigns revealed the victims were almost exclusively companies in the U.S., U.K., Australia, South Africa, and Canada, and the most commonly targeted sectors were manufacturing, health care and technology. The exact distribution of victims in each country and sector varies slightly between campaigns.
  • To use Greatness, affiliates must deploy and configure a provided phishing kit with an API key that allows even unskilled threat actors to easily take advantage of the service’s more advanced features. The phishing kit and API work as a proxy to the Microsoft 365 authentication system, performing a “man-in-the-middle” attack and stealing the victim’s authentication credentials or cookies.
talosintelligence EN 2023 Greatness Phishing phishing-kits analysis
Can Better Training Reduce the Success Rate of Phishing Attacks? https://www.lawfareblog.com/can-better-training-reduce-success-rate-phishing-attacks
06/05/2023 14:40:33
QRCode
archive.org
thumbnail

A review of Arun Vishwanath, “The Weakest Link: How to Diagnose, Detect, and Defend Users From Phishing Attacks” (MIT Press, 2022)

Many elements of the cyber threat landscape have changed significantly over the past two decades. For one, the number of attackers has grown dramatically, aided by the increasing availability of hacking tools and services as commodities for purchase in online marketplaces. The value of the losses cyber criminals have been able to inflict on their victims has also grown, though the dollar estimates vary widely in absolute terms. In recent years, the popularity of ransomware has increased substantially, prompting the Biden administration to initiate an ongoing diplomatic effort to foster cross-border efforts to curb this dangerous form of cyber-enabled extortion.

lawfareblog EN 2023 Phishing Training
Investigating ChatGPT phishing detection capabilities https://securelist.com/chatgpt-anti-phishing/109590/
01/05/2023 15:57:52
QRCode
archive.org
thumbnail

Kaspersky research on ChatGPT capabilities to tell a phishing link from a legitimate one by analyzing the URL, as well as extract target organization name.

securelist 2023 EN Machine-learning Phishing Phishing-websites phishing detection capabilities
Alerte sur des tentatives de piratage de comptes bancaires en Suisse https://www.letemps.ch/economie/alerte-tentatives-piratage-comptes-bancaires-suisse
09/03/2023 16:41:35
QRCode
archive.org
thumbnail

Le Centre national pour la cybersécurité lance un avertissement: les cybercriminels ont accès à des comptes bancaires, malgré des mesures de protection élevées, en incitant les victimes à leur fournir des informations. Raiffeisen est notamment concernée

letemps CH 2023 phishing tempsréel
page 5 / 8
4522 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio