Critical

Attackers Combo Up Evasion Tactics for BEC Phishing

darkreading
Actively Exploited

Overview

A new phishing campaign, dubbed 'The TFF Trap', employs sophisticated evasion tactics to execute business email compromise (BEC) attacks. This method utilizes fileless techniques and low-detection loaders to deploy various remote access trojans (RATs) and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger. The attackers aim to infiltrate corporate networks and steal sensitive information. Organizations should be on high alert, as these tactics make it challenging for traditional security measures to detect the malicious activities. Companies must bolster their email security practices and educate employees on recognizing phishing attempts to mitigate the risks associated with this evolving threat.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Agent Tesla, Remcos, XWorm, Best Private Logger
  • Action Required: Organizations should enhance email security protocols, implement multi-factor authentication, and conduct regular employee training on phishing awareness.
  • Timeline: Newly disclosed

Original Article Summary

"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.

Impact

Agent Tesla, Remcos, XWorm, Best Private Logger

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations should enhance email security protocols, implement multi-factor authentication, and conduct regular employee training on phishing awareness.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Phishing, Tesla.

Related Coverage

Nobody was checking the drives that encrypt your laptop

Help Net Security

A recent investigation by Milan Brož and his colleagues found that many solid-state drives (SSDs) labeled as having hardware encryption may not be secure. They tested 38 drives compliant with the TCG Opal2 standard, commonly used in millions of laptops and workstations. The researchers discovered that the drives failed to adequately protect data, raising concerns about the reliability of hardware encryption. This affects users and organizations relying on these drives for data security, as they may be under the false impression that their sensitive information is safe. With the increasing use of SSDs in computing, this issue highlights a significant gap in security practices and the need for more rigorous checks on encryption technologies.

Jul 21, 2026

AI agents are still logging in as humans

Help Net Security

Recent analysis shows that many large organizations are using multiple AI platforms simultaneously, which raises potential security concerns. Developers and marketing teams often mix sanctioned tools with personal accounts, leading to a complex environment where AI agents may log in as human users. This situation increases the risk of unauthorized access and data breaches, as the boundaries between professional and personal use of AI tools blur. The data, gathered from over 20,000 organizations, indicates that this trend has been growing since June 2022. Companies need to be aware of these risks and implement stricter security measures to protect sensitive information.

Jul 21, 2026

AI-generated reports push GNOME to shorten its disclosure window

Help Net Security

The GNOME project is responding to a surge in AI-generated security vulnerability reports that are being submitted to its maintainers. Many of these reports do not disclose that they were created using language models, leading to an overwhelming volume of submissions. As a result, GNOME is changing its policies regarding how it tracks and discloses vulnerabilities. Michael Catanzaro, who has been overseeing GNOME's security issue tracking since late 2020, is at the forefront of these changes. This shift is significant because it aims to improve the efficiency of handling security issues in open source projects, ensuring that genuine vulnerabilities are prioritized amidst the noise created by automated reports.

Jul 21, 2026

Estée Lauder discloses data breach via Oracle E-Business flaw

BleepingComputer

Estée Lauder has informed customers about a data breach that occurred due to a vulnerability in Oracle's E-Business Suite, which the company uses for its human resources operations. Hackers exploited this flaw, potentially compromising the personal data of affected individuals. While the specific details about the type of data accessed have not been disclosed, this incident raises concerns about the security of sensitive information within large organizations. Customers are advised to monitor their accounts for any unusual activity as the company works to address the breach. This incident serves as a reminder for businesses to ensure their software systems are regularly updated and secure against known vulnerabilities.

Jul 20, 2026

JadePuffer agentic attacks now target AI model data with ransomware

BleepingComputer

A new strain of malware, named EncForge, has been developed by the JadePuffer autonomous AI agent. This malware specifically targets AI-related assets, including training datasets, vector databases, and model checkpoints, by encrypting them and holding them for ransom. This shift in focus to AI model data represents a concerning trend, as organizations increasingly rely on these assets for their operations. If attackers succeed, they can disrupt AI development and implementation, potentially causing significant financial and operational damage to affected companies. As AI technology continues to evolve, the need for robust security measures to protect these critical assets becomes ever more urgent.

Jul 20, 2026

Hugging Face uses GLM 5.2 to investigate AI agent-driven cyberattack

SCM feed for Latest

Hugging Face, a company known for its work in AI and machine learning, has recently turned to an open-weight model named GLM 5.2 to investigate a cyberattack driven by AI agents. The shift to this model comes after they encountered limitations with their previous frontier model guardrails, which restricted their capabilities. This situation illustrates the evolving challenges in cybersecurity, particularly as AI technologies become more integrated into both offensive and defensive strategies. The use of AI in cyberattacks raises significant concerns about the potential for more sophisticated and automated threats. Companies in the tech sector should take note of these developments as they may need to adjust their security measures to counteract AI-driven vulnerabilities.

Jul 20, 2026