Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 6 / 8
146 résultats taggé phishing  ✕
New phishing-as-a-service tool “Greatness” already seen in the wild https://blog.talosintelligence.com/new-phishing-as-a-service-tool-greatness-already-seen-in-the-wild/
11/05/2023 22:01:18
QRCode
archive.org
thumbnail
  • A previously unreported phishing-as-a-service (PaaS) offering named “Greatness” has been used in several phishing campaigns since at least mid-2022. Greatness incorporates features seen in some of the most advanced PaaS offerings, such as multi-factor authentication (MFA) bypass, IP filtering and integration with Telegram bots.
  • Greatness, for now, is only focused on Microsoft 365 phishing pages, providing its affiliates with an attachment and link builder that creates highly convincing decoy and login pages. It contains features such as having the victim’s email address pre-filled and displaying their appropriate company logo and background image, extracted from the target organization’s real Microsoft 365 login page. This makes Greatness particularly well-suited for phishing business users.
  • An analysis of the domains targeted in several ongoing and past campaigns revealed the victims were almost exclusively companies in the U.S., U.K., Australia, South Africa, and Canada, and the most commonly targeted sectors were manufacturing, health care and technology. The exact distribution of victims in each country and sector varies slightly between campaigns.
  • To use Greatness, affiliates must deploy and configure a provided phishing kit with an API key that allows even unskilled threat actors to easily take advantage of the service’s more advanced features. The phishing kit and API work as a proxy to the Microsoft 365 authentication system, performing a “man-in-the-middle” attack and stealing the victim’s authentication credentials or cookies.
talosintelligence EN 2023 Greatness Phishing phishing-kits analysis
Can Better Training Reduce the Success Rate of Phishing Attacks? https://www.lawfareblog.com/can-better-training-reduce-success-rate-phishing-attacks
06/05/2023 14:40:33
QRCode
archive.org
thumbnail

A review of Arun Vishwanath, “The Weakest Link: How to Diagnose, Detect, and Defend Users From Phishing Attacks” (MIT Press, 2022)

Many elements of the cyber threat landscape have changed significantly over the past two decades. For one, the number of attackers has grown dramatically, aided by the increasing availability of hacking tools and services as commodities for purchase in online marketplaces. The value of the losses cyber criminals have been able to inflict on their victims has also grown, though the dollar estimates vary widely in absolute terms. In recent years, the popularity of ransomware has increased substantially, prompting the Biden administration to initiate an ongoing diplomatic effort to foster cross-border efforts to curb this dangerous form of cyber-enabled extortion.

lawfareblog EN 2023 Phishing Training
Investigating ChatGPT phishing detection capabilities https://securelist.com/chatgpt-anti-phishing/109590/
01/05/2023 15:57:52
QRCode
archive.org
thumbnail

Kaspersky research on ChatGPT capabilities to tell a phishing link from a legitimate one by analyzing the URL, as well as extract target organization name.

securelist 2023 EN Machine-learning Phishing Phishing-websites phishing detection capabilities
Alerte sur des tentatives de piratage de comptes bancaires en Suisse https://www.letemps.ch/economie/alerte-tentatives-piratage-comptes-bancaires-suisse
09/03/2023 16:41:35
QRCode
archive.org
thumbnail

Le Centre national pour la cybersécurité lance un avertissement: les cybercriminels ont accès à des comptes bancaires, malgré des mesures de protection élevées, en incitant les victimes à leur fournir des informations. Raiffeisen est notamment concernée

letemps CH 2023 phishing tempsréel
A Noteworthy Threat: How Cybercriminals are Abusing OneNote https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/a-noteworthy-threat-how-cybercriminals-are-abusing-onenote-part-1/
08/03/2023 21:34:33
QRCode
archive.org
thumbnail

Threat actors are taking advantage of Microsoft OneNote's ability to embed files and use social engineering techniques, such as phishing emails and lures inside the OneNote document, to get unsuspecting users to download and open malicious files.

trustwave EN 2023 Microsoft OneNote phishing malicious analysis
The Growing Threat of ChatGPT-Based Phishing Attacks https://blog.cyble.com/2023/02/22/the-growing-threat-of-chatgpt-based-phishing-attacks/
23/02/2023 08:53:07
QRCode
archive.org
thumbnail

Cyble analyzes how Threat Actors are using the recent buzz around ChatGPT to launch Phishing attacks using various methods.

Cyble 2023 EN ChatGPT ChatGPT-Based Phishing Attacks
HTML Smuggling: The Hidden Threat in Your Inbox https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/html-smuggling-the-hidden-threat-in-your-inbox/
09/02/2023 18:21:15
QRCode
archive.org
thumbnail

Last October, Trustwave SpiderLabs blogged about the use and prevalence of HTML email attachments to deliver malware and phishing for credentials.

trustwave EN 2023 HTML Threat SpiderLabs email phishing malware
Bitwarden password vaults targeted in Google ads phishing attack https://www.bleepingcomputer.com/news/security/bitwarden-password-vaults-targeted-in-google-ads-phishing-attack/
08/02/2023 17:03:24
QRCode
archive.org
thumbnail

Bitwarden and other password managers are being targeted in Google ads phishing campaigns to steal users' password vault credentials.

bleepingcomputer EN 2023 1Password Bitwarden GoogleAds googleads MFA Multi-Factor-Authentication Password-Manager Passwords Phishing
Cost of data breaches to surpass US$5mn per incident in 2023 https://technologymagazine.com/articles/cost-of-data-breaches-to-surpass-us-5mn-per-incident-in-2023
28/12/2022 11:31:16
QRCode
archive.org
thumbnail

Acronis’ end-of-year cyberthreats report found that the proportion of phishing attacks has risen by 1.3x, accounting for 76% of all cyber attacks

technologymagazine 2022 EN Acronis end-of-year report phishing
An infostealer comes to town: Dissecting a highly evasive malware targeting Italy https://blog.cluster25.duskrise.com/2022/12/22/an-infostealer-comes-to-town
23/12/2022 22:35:26
QRCode
archive.org
thumbnail

Cluster25 researchers analyzed several campaigns (also publicly reported by CERT-AGID) that used phishing emails to spread an InfoStealer malware written in .NET through an infection chain that involves Windows Shortcut (LNK) files and Batch Scripts (BAT). Taking into account the used TTPs and extracted evidence, the attacks seem perpetrated by the same adversary (internally named AUI001).

cluster25 EN 2022 infostealer Italy phishing Campaigns analysis Alibaba2044 IoCs
Meddler-in-the-Middle Phishing Attacks Explained MitM https://unit42.paloaltonetworks.com/meddler-phishing-attacks/
22/12/2022 22:47:44
QRCode
archive.org
thumbnail

Meddler-in-the-Middle (MitM) phishing attacks show how threat actors find ways to get around traditional defenses and advice.

unit42 EN 2022 MitM phishing Meddler-in-the-Middle explanation analysis
Using OpenAI Chat to Generate Phishing Campaigns https://www.richardosgood.com/posts/using-openai-chat-for-phishing/
16/12/2022 09:18:03
QRCode
archive.org

OpenAI chat has exploded in popularity over the last couple of weeks. People are using it to do all sorts of interesting things. If you are unfamiliar with OpenAI Chat and GPT-3, you can find a primer here. The gist is that it’s an artificial intelligence model that you can chat with as if it were a person. It can do all kinds of things like answer questions, write code, find bugs in code, and more. It also remembers context, so you can refer to something you already mentioned at it is able to follow along. I thought maybe this could be a useful tool for building email phishing campaigns for my pentesting work, so I thought I’d try it out and see what I could get it to do.

richardosgood ChatGPT Phishing Campaigns
Threat Spotlight: Cyber Criminal Adoption of IPFS for Phishing, Malware Campaigns https://blog.talosintelligence.com/ipfs-abuse/
12/11/2022 22:26:19
QRCode
archive.org
thumbnail
  • The InterPlanetary File System (IPFS) is an emerging Web3 technology that is currently seeing widespread abuse by threat actors.
    • Cisco Talos has observed multiple ongoing campaigns that leverage the IPFS network to host their malware payloads and phishing kit infrastructure while facilitating other attacks.
    • IPFS is often used for legitimate
talosintelligence EN 2022 IPFS Phishing Malware Campaigns
How we handled a recent phishing incident that targeted Dropbox https://dropbox.tech/security/a-recent-phishing-campaign-targeting-dropbox
02/11/2022 07:00:10
QRCode
archive.org
thumbnail

We were recently the target of a phishing campaign that successfully accessed some of the code we store in GitHub. No one’s content, passwords, or payment information was accessed, and the issue was quickly resolved. Our core apps and infrastructure were also unaffected, as access to this code is even more limited and strictly controlled. We believe the risk to customers is minimal. Because we take our commitment to security, privacy, and transparency seriously, we have notified those affected and are sharing more here.

dropbox EN 2022 incident phishing GitHub
Cyble Phishing ERMAC Android Malware Increasingly Active https://blog.cyble.com/2022/10/18/ermac-android-malware-increasingly-active/
18/10/2022 10:45:03
QRCode
archive.org
thumbnail

CRIL Investigates the resurgence of ERMAC Android Malware as an increasing number of users are falling prey to their phishing attacks.

cyble EN 2022 ERMAC Android Malware phishing Analysis
Void Balaur | The Sprawling Infrastructure of a Careless Mercenary https://www.sentinelone.com/labs/the-sprawling-infrastructure-of-a-careless-mercenary/
23/09/2022 23:03:15
QRCode
archive.org
thumbnail

The Void Balaur cyber mercenary group has thrived throughout 2022, attacking targets on a global scale with new phishing campaigns.

sentinelone EN 2022 mercenary Void-Balaur phishing hack-for-hire
Revolut hack exposes data of 50,000 users, fuels new phishing wave https://www.bleepingcomputer.com/news/security/revolut-hack-exposes-data-of-50-000-users-fuels-new-phishing-wave/
19/09/2022 23:52:34
QRCode
archive.org
thumbnail

Revolut is sending out notices of a data breach to a small percentage of impacted users, informing them of a security incident where an unauthorized third party accessed internal data.

bleepingcomputer EN 2022 Data-Breach Phishing Revolut Smishing
Charming Kitten: “Can We Have A Meeting?” https://blog.certfa.com/posts/charming-kitten-can-we-wave-a-meeting/
14/09/2022 14:37:07
QRCode
archive.org
thumbnail

Our recent investigation at Certfa Lab, the APT42 has been running multiple phishing campaigns since late 2021 and some of them are ongoing and still active.

certfa EN 2022 Charming-Kitten APT Iran Phishing Espionage-Operations Sophisticated-Attacks investigation
Lampion Trojan Utilizes New Delivery through Cloud-Based Sharing https://cofense.com/blog/lampion-trojan-utilizes-new-delivery-through-cloud-based-sharing
12/09/2022 14:05:35
QRCode
archive.org
thumbnail

Analysts at the Cofense Phishing Defense Center (PDC) have recently analyzed an email asking users to download a “Proof of Payment” as well as other documents. While it is important to never click on the link(s) or download the attachment(s) of any suspicious email, if the recipient interacts with the link, it downloaded the malware Lampion.

cofense EN 2022 Phishing Lampion malware IoCs
Corte dei conti e l'hacker che ha violato account WhatsApp https://www.giornalettismo.com/corte-dei-conti-e-lhacker-whatsapp-violato/
10/09/2022 11:40:14
QRCode
archive.org
thumbnail

La violazione dell'account WhatsApp di un magistrato della Corte dei Conti ha un effetto domino: hacker hanno accesso a diverse informazioni

giornalettismo IT 2022 Corte-dei-conti WhatsApp Phishing
page 6 / 8
4720 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio