SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
A new banking fraud operation tracked as REF6045 by Elastic Security Labs is targeting customers of Mexican banks, fintech platforms, payment processors,…
A new banking fraud operation tracked as REF6045 by Elastic Security Labs is targeting customers of Mexican banks, fintech platforms, payment processors,…
A recent EvilTokens campaign is exploiting a new 'ghost phishing' technique that hides malicious content until it decrypts inside the victim's browser,…
A critical vulnerability in Google's Dialogflow CX, dubbed 'Rogue Agent' by security firm Varonis, could have allowed an attacker with edit permissions…
A new Android malware operation called RedWing is being offered as a ready-made bank-fraud service on Telegram, allowing low-skill criminals to take…
RedWing is a new Android malware operation offered as a subscription-based service on Telegram, enabling criminals to steal banking credentials and intercept…
ZeroBEC is a cybersecurity firm that analyzed the Greatness PhaaS kit, detailing its new device code phishing and AiTM capabilities. The report…
Microsoft 365 is a productivity and collaboration suite that is a primary target for NovaCookies and other phishing kits. The AitM relay…
Microsoft Entra is Microsoft's cloud-based identity and access management service. Attackers are using fake passkey enrollment pages that mimic Entra's passkey registration…
Trustifi is an email security platform whose click-tracking URLs were used in Tycoon 2FA device code phishing campaigns to initiate attack chains.
A suspected China-nexus threat activity cluster, codenamed Operation DragonReturn by Seqrite Labs, has been targeting Indian taxpayers, tax professionals, and corporate finance…