Articles tagged "Phishing"

Found 415 articles

Critical
Bendix EC80 Brake ECU

All CISA Advisories

Bendix has identified critical vulnerabilities in its EC80 Brake ECU, which could allow attackers to disrupt essential vehicle functions like ABS, steering assist, and traction control. The affected versions include multiple models such as EC80ESP+ and EC80ESP PLC across various configurations. These vulnerabilities stem from issues like stack-based buffer overflows, out-of-bounds writes, and the use of hard-coded credentials. Users of the affected products are urged to update their firmware to the latest versions to mitigate these risks. This situation is particularly concerning as it affects vehicle safety systems, making prompt action crucial for those using the impacted equipment.

Read Original

Researchers have uncovered a cybersecurity campaign involving 24 npm packages that serve as phishing tools. These packages redirect users to fake CAPTCHA pages that mimic legitimate Cloudflare prompts, tricking users into providing sensitive information. While the packages themselves contain harmless HTML, the intent is to exploit npm's infrastructure to deceive unsuspecting users. This tactic raises concerns about the safety of open-source package repositories and how they can be misused for malicious purposes. Developers and users of npm should be cautious and ensure they verify the packages they download to avoid falling victim to such schemes.

Read Original
Actively Exploited

A group known as ShinyHunters claims to have executed a social engineering attack against ReliaQuest. The attackers targeted employees by calling them and attempting to deceive them into visiting a fraudulent single sign-on (SSO) page. This fake page was hosted on a lookalike domain, reliaquest[.]claims, designed to mimic the legitimate ReliaQuest site. Such tactics can lead to credential theft and unauthorized access to sensitive company data. This incident raises concerns about the effectiveness of security training and awareness among employees, as social engineering remains a prevalent threat in cybersecurity.

Read Original

ReliaQuest has confirmed a security incident involving a phishing attack that targeted one of its employees. As a result of this attack, hackers gained access to a dashboard, which could have potentially exposed sensitive information. However, the company has stated that the overall impact of the breach was limited. This incident raises concerns about the vulnerability of employee accounts to phishing attempts and the need for companies to reinforce security training. It serves as a reminder that even established firms can fall victim to such tactics, highlighting the importance of ongoing vigilance in cybersecurity practices.

Read Original

ReliaQuest, a cybersecurity company, has confirmed that an employee was targeted in a social engineering attack by hackers impersonating a member of their security team. This incident follows a previous breach involving the hacker group ShinyHunters, known for stealing and leaking data from various organizations. Although ReliaQuest has stated that no data was successfully stolen in this attempt, the incident raises concerns about the effectiveness of internal security protocols and employee training regarding social engineering tactics. It serves as a reminder of the ongoing risks that companies face from sophisticated phishing schemes and the need for vigilant security practices. The implications of such attacks can be significant, leading to potential data breaches and loss of trust among clients and partners.

Read Original
Actively Exploited

A new phishing technique called Chameleon SEO Poisoning has been identified by Fortra's threat intelligence team. This method involves creating fake banking websites that are optimized to appear in search results for terms like 'Bank Name Customer Portal'. These deceptive sites can evade security scanners by disguising themselves, making it difficult for users to recognize them as fraudulent. Fortra reported a significant increase in these phishing attempts, with a 40% rise noted in the second quarter of 2026. This situation poses a serious risk to individuals seeking to access their banking information online, as attackers aim to steal credentials through these disguised sites.

Read Original

Researchers have identified a new phishing toolkit known as iAuthFlow V2 that allows attackers to register a passkey they control. This capability enables them to maintain access to user accounts even after victims change their passwords or revoke active sessions. The toolkit poses a significant risk as it undermines traditional security measures that rely on passwords. Users of affected services need to be vigilant about phishing attempts that aim to exploit this vulnerability. This development raises concerns about the effectiveness of password-based security and the potential for ongoing unauthorized access to personal accounts.

Read Original
Actively Exploited

A new variant of the Agent Tesla malware, known as version 4, has emerged with enhanced evasion techniques that utilize emoji-based code obfuscation. This innovative method helps the malware avoid detection by traditional security systems, making it more effective in attacking targets. Agent Tesla is known for stealing sensitive information such as login credentials and other personal data, and this latest variant poses a risk to individuals and organizations alike. Researchers from KnowBe4 have analyzed the campaign, indicating that users and companies need to remain vigilant against such evolving threats. The use of unconventional tactics like emoji in malware coding signifies a shift in how cybercriminals are attempting to bypass security measures.

Read Original
Actively Exploited

Attackers are posing as well-known AI brands, including Perplexity, Claude, ChatGPT, and Copilot, to distribute various types of malware, such as information stealers and malicious browser extensions. This tactic was highlighted in a report by Sophos, which analyzed managed detection and response cases over the past year. Out of 86 incidents flagged for AI involvement, 34 were confirmed to be linked to malicious activities. This trend raises significant concerns as it exploits the popularity of AI tools to trick users into downloading harmful software. Users need to be cautious and verify the authenticity of any AI-related applications to avoid falling victim to these scams.

Read Original

Adversa AI has revealed a new attack method called 'Cryptographic Context Injection' that enables attackers to extract sensitive data from users of xAI's Grok chatbot. When users request a summary of a regular web page, the chatbot could inadvertently send their name, approximate location, subscription tier, and ongoing conversation prompts to a server controlled by the attacker. This vulnerability raises concerns about user privacy and data security, particularly as chatbots become more integrated into everyday online interactions. Users of Grok should be cautious about the information they share, especially when interacting with web pages that may trigger this exploit. The potential for misuse of this data could lead to targeted phishing attempts or other malicious activities.

Read Original

A vulnerability in Johnson Controls' Simplex Incident Manager could allow local attackers to extract user credentials stored in cleartext in system memory. This issue affects versions of the software up to and including V2.01 (CVE-2026-27875). Organizations using this application, which is deployed in critical sectors like manufacturing, government, and energy, face risks of unauthorized access to their systems. Johnson Controls has released a patched version (v2.01.01) to address this issue and recommends that users restrict local access to authorized personnel, implement endpoint protection, and enforce strong access controls. While no public exploitation has been reported, the potential for abuse remains a concern for users of the affected software.

Read Original
Actively Exploited

After attending the Def Con hacking conference, participants found themselves at the center of a sophisticated phishing campaign. Researchers from Huntress reported receiving targeted emails that attempted to deceive them into revealing sensitive information. These phishing attempts were not just random; they were persistent and tailored to exploit the knowledge and skills of conference attendees. This incident serves as a reminder of the ongoing risks faced by cybersecurity professionals, especially after major events where attackers may leverage the excitement and connections made during the conference. The implications are significant, as such attacks can lead to data breaches or identity theft if successful.

Read Original

A spear-phishing campaign linked to a China-based group known as FamousSparrow is targeting organizations in Central Asia with various remote access trojans (RATs). These attacks are part of a broader strategy that reflects the geopolitical tensions in the region and the ongoing activities of advanced persistent threat (APT) groups. The campaign uses deceptive emails to trick recipients into installing malware, which can give attackers control over compromised systems. This poses significant risks for the affected organizations, as it could lead to data breaches, espionage, and further exploitation of sensitive information. Security experts are urging organizations in Central Asia to strengthen their defenses against such targeted attacks, especially as the threat landscape continues to evolve with geopolitical developments.

Read Original

The article discusses the evolution of phishing attacks, noting that traditional email defenses are becoming less effective. Initially, phishing threats focused on harmful content like malicious links or attachments. However, as attackers have shifted their strategies, the real danger now lies in the intent behind messages, often manipulated by AI. This change means that even sophisticated defenses may struggle to identify threats that are less about the content and more about misleading users through deceptive interactions. As AI technology improves on both sides, companies and users need to adapt their defenses to recognize these new tactics and protect against them.

Read Original
Critical
CISA Malcolm

All CISA Advisories

CISA Malcolm, a network traffic analysis tool, has several vulnerabilities that could allow attackers to execute arbitrary code or cause denial-of-service conditions. Versions prior to 26.07.0 are particularly affected by issues related to file extraction and role-based access control, allowing unauthorized access to sensitive areas and the potential execution of malicious code. Specifically, CVEs 2026-55676, 2026-63133, 2026-63134, 2026-63177, and 2026-19670 highlight problems with file upload handling and directory traversal protections. Users of Malcolm are urged to update to the latest versions—26.07.0 or 26.06.1—to mitigate these risks. These vulnerabilities are significant as they could compromise the integrity and availability of systems utilizing CISA Malcolm worldwide.

Read Original
PreviousPage 2 of 28Next