Articles tagged "Phishing"

Found 415 articles

A recent study by Proofpoint reveals that 65% of organizations impacted by ransomware believe that artificial intelligence has made these attacks more effective. This finding indicates that cybercriminals are increasingly using AI to enhance their tactics, making it harder for companies to defend against such threats. The research suggests that AI technology can help attackers automate tasks, analyze data quickly, and create more convincing phishing attempts. As a result, organizations must be more vigilant and proactive in their cybersecurity measures to counteract these evolving threats. The implications of this trend are significant, as companies may need to invest in advanced security solutions and training to protect themselves from increasingly sophisticated ransomware attacks.

Read Original

Authorities in Germany and the U.S. have taken significant action against a phishing-as-a-service platform known as Kratos, which has been linked to phishing attacks worldwide. The platform's infrastructure was dismantled, and its developer was arrested in Indonesia, marking a notable step in the fight against online fraud. Kratos allowed criminals to easily launch phishing campaigns, making it a considerable threat to individuals and businesses alike. With its removal, users should see a reduction in phishing attempts that leveraged this service. This incident underscores the ongoing efforts by law enforcement to combat cybercrime on a global scale.

Read Original

Ernst & Young (EY) recently experienced a data breach where attackers accessed a third-party support ticket system for two weeks. This system contained sensitive customer tax information, potentially affecting numerous clients. The breach raises significant concerns about the security of client data, particularly as tax season approaches. Clients are urged to monitor their accounts for unusual activity and to remain vigilant about potential phishing attempts that could arise from this incident. EY has not disclosed how many clients are impacted or the specific nature of the exposed data, but the incident highlights the risks associated with third-party services in handling sensitive information.

Read Original
Critical
Rockwell Automation 1734 POINT I/O

All CISA Advisories

Rockwell Automation has identified a vulnerability in its 1734 POINT I/O module that could lead to a denial-of-service condition. Specifically, attackers can exploit this issue by sending specially crafted CIP messages, causing the module to fail and requiring a restart for recovery. The affected version is 3.023 of the 1734 POINT I/O module, which is used in critical manufacturing sectors worldwide. While there are no reports of active exploitation at this time, organizations using this equipment are urged to take precautions. Rockwell recommends migrating to a newer version, specifically 5034-OB8, or following their security best practices to mitigate risks.

Read Original

Rockwell Automation has reported a vulnerability affecting their 1718-AENTR and 1719-AENTR products, specifically version 3.011 of the Ex I/O series. This flaw can lead to a denial-of-service condition, where the device becomes overloaded due to improper handling of a UDP unicast network storm, resulting in loss of communication. Recovery from this issue requires a power cycle. Users worldwide are advised to upgrade to version 3.012 or later to mitigate this risk. For those unable to upgrade, Rockwell Automation recommends following their security best practices to minimize exposure. This vulnerability is significant as it impacts devices used in critical manufacturing sectors, raising concerns about operational stability and security.

Read Original

Rockwell Automation's Studio 5000 Logix Designer has several vulnerabilities that could allow local attackers to execute arbitrary files and alter configurations. Versions affected include Studio 5000 Logix Designer V36.00 and various iterations of V35.00, V35.01, and earlier versions down to V32.00. The vulnerabilities, identified as CVE-2026-9108, CVE-2026-9127, and CVE-2026-9128, have been assigned high severity scores, indicating they could pose significant risks to users. Rockwell Automation has released updates to address these issues, and users unable to upgrade should follow the company's security best practices to mitigate risks. The potential for exploitation of these vulnerabilities highlights the need for organizations to maintain robust cybersecurity defenses.

Read Original

Rockwell Automation has disclosed a significant vulnerability in its FactoryTalk Services Platform (FTSP) version 6.60, which could allow attackers to impersonate authorized users. This flaw arises from weak authentication practices, specifically the inability of the application to properly validate JSON Web Tokens (JWT). As a result, low-privilege users could exploit this vulnerability to gain unauthorized access to critical system configurations and permissions. Organizations using FTSP are urged to apply a specific patch (RAID 1158263) or the February 2026 Patch Roll-up to mitigate this risk. As of now, there have been no reports of active exploitation in the wild, but users are advised to follow best security practices to protect their systems.

+1 more
Read Original
Actively Exploited

A new phishing campaign, dubbed 'The TFF Trap', employs sophisticated evasion tactics to execute business email compromise (BEC) attacks. This method utilizes fileless techniques and low-detection loaders to deploy various remote access trojans (RATs) and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger. The attackers aim to infiltrate corporate networks and steal sensitive information. Organizations should be on high alert, as these tactics make it challenging for traditional security measures to detect the malicious activities. Companies must bolster their email security practices and educate employees on recognizing phishing attempts to mitigate the risks associated with this evolving threat.

Read Original
Actively Exploited

Researchers have discovered that over one million phishing emails are using a technique called text salting to bypass AI security filters. This method involves hiding malicious text within seemingly harmless content, making it difficult for AI systems to detect the phishing attempts. As a result, many users may unknowingly receive these threats in their inboxes, putting their personal information at risk. This situation raises concerns about the effectiveness of current AI security measures and the need for improved detection strategies. Organizations and email service providers must address this vulnerability to better protect their users from sophisticated phishing attacks.

Read Original
Actively Exploited

A global phishing campaign has been detected that disguises a Lua loader as a TrueType font file to deploy remote access Trojans (RATs) and information stealers. Attackers are using this method to bypass security measures by making the malicious files appear innocuous. This tactic affects users who may inadvertently open these disguised files, leading to potential data breaches or unauthorized access to systems. The presence of such sophisticated phishing techniques raises concerns about the effectiveness of traditional email security measures. Users need to be vigilant about unexpected email attachments, even if they seem harmless, to avoid falling victim to these types of attacks.

Read Original

Rockwell Automation has identified several vulnerabilities in its CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix products that could allow attackers to cause a denial-of-service (DoS) condition. The affected versions include various models of CompactLogix and ControlLogix controllers, specifically those running versions V35.015 or lower for the 5370 and 5570 series, and V34.012 or V35.011 for the 5380, 5480, and 5580 series. If exploited, these vulnerabilities could lead to the devices entering a non-recoverable fault state, disrupting operations in critical manufacturing sectors. Users are urged to update their systems to the latest versions to mitigate these risks, as the vulnerabilities have a high severity rating (CVSS score of 8.6).

Read Original
Critical
Rockwell Automation Flex 5000 Adapter

All CISA Advisories

Rockwell Automation has reported a vulnerability in its Flex 5000 Adapter, specifically version 6.011, that could lead to a denial-of-service (DoS) condition. This issue arises from improper handling of specific CIP packets, which can cause the adapter to become unresponsive, necessitating a power cycle to restore functionality. The vulnerability is classified as CVE-2026-12659 and has a CVSS score of 7.5, indicating a high severity level. Users are advised to upgrade to version 6.012 to mitigate this risk. For those unable to update, Rockwell Automation recommends following its security best practices to safeguard their systems. This vulnerability is particularly concerning for sectors involved in critical manufacturing and information technology, affecting organizations globally.

Read Original

A serious vulnerability has been identified in Rockwell Automation's FactoryTalk DataMosaix Private Cloud software, affecting versions up to 8.02. This flaw, classified as CVE-2026-9292, allows authenticated attackers to inject malicious scripts into the server due to improper handling of user input. If exploited, this could lead to account takeovers, credential theft, or redirection to harmful websites when other users access the compromised pages. Rockwell Automation recommends that users upgrade to version 8.03 or later to mitigate the risk. For those unable to upgrade, following security best practices outlined by Rockwell is advised. Although there have been no reports of active exploitation of this vulnerability, organizations are urged to enhance their security measures to protect against potential threats.

Read Original

Rockwell Automation has reported a vulnerability affecting their 1756-EN2, 1756-EN3, and 1756-ENBT communication modules. Specifically, versions 1756-EN3 and 1756-EN2 up to V12.001, and 1756-ENBT V6.006 are susceptible to a denial-of-service attack due to improper validation of connection packets. An attacker on the same network could exploit this issue by sending malicious packets that disrupt device connections, although these connections can recover immediately. This vulnerability is particularly concerning for industries relying on critical manufacturing infrastructure, as it could lead to significant operational disruptions. Users are advised to update their devices to version 12.002 to mitigate this risk.

Read Original
Critical
Rockwell Automation Arena

All CISA Advisories

Rockwell Automation's Arena software has several critical vulnerabilities that could allow attackers to execute arbitrary code. These vulnerabilities affect versions up to V17.00.00 and include issues in components like model.exe, expmt.exe, linker.exe, and siman.exe. The problems arise from improper validation of user-supplied data, leading to out-of-bounds writes. Users are urged to update to version V17.00.01 to mitigate the risks. This situation is particularly concerning for sectors involved in critical manufacturing, as the software is used worldwide. No active exploitation of these vulnerabilities has been reported yet, but organizations should remain vigilant.

Read Original
PreviousPage 8 of 28Next