-
Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishing attacks.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Compromised hotel Wi-Fi gateways redirect business travelers to fake Microsoft 365 login pages allowing attackers to steal credentials and authorization tokens.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fake FBI agents are using deepfake videos, spoofed IC3 websites and false recovery claims to steal money and personal information from people who were scammed before, the FBI warns.
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An email that appears to contain a shipping document, payment request, or business proposal can infect a Windows…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Group-IB says scammers are targeting Céline Dion fans through Facebook, duplicate digital tickets and fake websites impersonating Ticketmaster, AXS and the venue site.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Dr.Web details Siggen Windows backdoor that uses Steam for C2, steals credentials and crypto data and infects Visual Studio projects to spread among developers.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Kaspersky details how the newly named Armored Likho APT uses BusySnake Stealer, AI-generated loaders, and phishing to target government and energy organizations.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Generative AI is making document fraud faster and harder to spot, pushing security teams to verify provenance, signatures and file integrity at intake securely.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
McAfee says a Google Notes browser extension is replacing copied crypto payment details, putting wallet transfers at risk for Chrome, Brave, and Microsoft Edge users.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


