Articles tagged "Phishing"

Found 415 articles

Critical
AutomationDirect Productivity Suite

All CISA Advisories

AutomationDirect's Productivity Suite has several critical vulnerabilities that could be exploited by attackers with local or physical access. These vulnerabilities, affecting versions up to 4.6.2.2, include out-of-bounds writes and reads, which could lead to memory corruption, information disclosure, and system instability. Users are strongly advised to update to version 4.7.0.47 or later to mitigate these risks. In the meantime, AutomationDirect recommends several compensating controls, such as disconnecting affected workstations from external networks and restricting access to authorized personnel only. The vulnerabilities affect critical manufacturing sectors worldwide, emphasizing the need for immediate attention from users of the software.

Read Original

A vulnerability has been identified in NASA's Core Flight System (cFS) Health & Safety (HS) Application, specifically affecting versions prior to 7.0.1. This flaw allows attackers to cause the application to crash when processing certain telemetry requests, resulting in a denial-of-service condition. The vulnerability, categorized as CVE-2026-15352, poses a risk to critical infrastructure, particularly in the transportation sector, as the application is used globally. Users are urged to update to version 7.0.1 to mitigate this risk. While there have been no reports of the vulnerability being actively exploited in the wild, organizations are advised to take precautionary measures to secure their systems against potential attacks.

Read Original
Actively Exploited

A recent survey of 2,158 IT and security leaders reveals that email, particularly through phishing attacks, is the primary method for cyber attackers to gain access to networks. In many cases, employees unknowingly open malicious emails and provide their login credentials, allowing attackers to infiltrate deeper into the system. This chain of events often leads to ransomware incidents, where files become inaccessible. Notably, while ransom demands have decreased, the reliance on email as an attack vector remains significant, accounting for half of all reported incidents. This trend emphasizes the need for organizations to bolster their email security and educate employees about the risks of phishing.

Read Original
Actively Exploited

Phishing attacks targeting finance departments are becoming increasingly sophisticated and effective. According to research from Cofense, attackers are crafting phishing emails that mimic legitimate business communications, making them harder to detect. These emails often bypass advanced email security tools, such as AI-based secure email gateways, because they lack the typical urgency cues that would raise alarms. This tactic poses a significant risk to organizations in the financial sector, as employees might unknowingly engage with these deceptive messages, potentially leading to data breaches or financial loss. Companies need to enhance employee training and awareness to combat these subtle phishing efforts.

Read Original

A recent analysis shows that email attacks have surpassed software exploits as the leading cause of ransomware incidents. Last year, attackers increasingly targeted credentials via phishing and other identity-based tactics. Despite the widespread use of multifactor authentication (MFA)—implemented in 97% of these credential-based attacks—many organizations still faced compromises. This shift highlights a significant vulnerability in how companies defend against identity theft, emphasizing the need for improved security measures beyond just MFA. As cybercriminals adapt their strategies, businesses must rethink their security protocols to better protect sensitive information.

Read Original
Actively Exploited

A phishing campaign that lasted six months used seasonal eCards to trick victims into downloading legitimate Remote Monitoring and Management (RMM) tools. Attackers crafted emails that appeared to be friendly holiday greetings, leading individuals to believe they were receiving festive messages. Instead, these emails contained links that, when clicked, installed RMM software on the victims' devices without their knowledge. This tactic poses a significant risk as it allows attackers to gain remote access to the systems of unsuspecting users, potentially leading to data breaches and further exploitation. Companies and individuals need to be vigilant about unexpected emails, especially those that seem too good to be true, to avoid falling victim to similar attacks.

Read Original

Recent research by Sophos reveals that compromised logins are now the leading method for ransomware delivery, surpassing traditional software vulnerabilities. This shift means that attackers are increasingly using phishing, brute force attacks, and other identity-based threats to gain access to networks. As a result, organizations may be at greater risk if they do not enhance their security measures around user credentials. Companies should prioritize employee training on recognizing phishing attempts and implement multi-factor authentication to bolster defenses. This change in attack vectors highlights the need for a more proactive approach to cybersecurity, particularly in safeguarding login credentials.

Read Original

Lidl has informed its online shop customers in Germany, Belgium, and the Netherlands about a data breach that involved the theft of personal data. This incident occurred due to a compromise of an external IT service provider, although payment information was not affected. The company reached out to customers last week to notify them of the breach and the potential risks associated with their stolen information. Customers should remain vigilant for any suspicious activity related to their personal data, as it could be used for identity theft or phishing attempts. This breach highlights the vulnerabilities associated with third-party service providers and the importance of robust security measures.

Read Original
Actively Exploited

A misconfigured server has exposed the operations of three phishing groups using Evilginx forks, which are tools designed to bypass multi-factor authentication (MFA). This incident shows how attackers can exploit configuration errors to facilitate phishing attacks that are more sophisticated and harder to detect. The exposed data could potentially allow these operators to target unsuspecting users, putting sensitive information at risk. As more organizations adopt MFA as a security measure, attackers are finding ways to circumvent these protections, making it essential for companies to ensure their server configurations are secure. This incident serves as a reminder of the importance of proper server management and security practices.

Read Original

A new open-source tool called 'ScamBuster' is designed to combat email scammers by using artificial intelligence to imitate victim personas. This system engages with phishing attackers to collect valuable data on their operations, which can be useful for organizations and law enforcement agencies. By turning the tables on scammers, ScamBuster aims to enhance the understanding of cybercriminal tactics and improve defenses against phishing attacks. This initiative is significant as phishing remains one of the most common and effective cyber threats, targeting individuals and businesses alike. The tool could potentially help reduce the number of successful scams and improve overall cybersecurity awareness.

Read Original

Dutch police are investigating a cyberattack on telecom provider Odido that occurred in February 2026, which led to the theft of data belonging to over six million customers. Authorities believe that local hackers, possibly Dutch nationals, were behind the phishing attack that initiated the breach. The police are currently seeking public assistance to identify these suspects. This incident raises serious concerns about the security of customer data in the telecommunications sector and highlights the ongoing risks posed by phishing schemes. As the investigation unfolds, affected customers should be vigilant about potential misuse of their personal information.

Read Original

A misconfigured Python web server used in a phishing operation targeting Microsoft 365 was discovered by Lexfo, a French cybersecurity firm. The server was left publicly accessible with directory listing enabled, allowing researchers to access a log file that contained the command used to run the server. This oversight led them to uncover not only the phishing toolkit but also two additional related operations. The exposed setup raises concerns about the security practices of attackers, as it can lead to further exploitation of users unaware of these phishing attempts. Organizations using Microsoft 365 should be vigilant and ensure their security measures are robust against such phishing schemes.

Read Original

On February 7, 2023, a data breach at Odido compromised the personal information of 6.2 million customers. The breach was made public on February 12, and Dutch police are currently investigating the incident, with suspicions pointing towards local hackers. This breach raises concerns about the security of personal data, especially given the scale of the impact. Affected customers may face risks such as identity theft and fraud. The investigation is ongoing, and it remains crucial for users to monitor their accounts and be aware of potential phishing attempts in the aftermath.

Read Original

Anastasia Tikhonova from Group-IB emphasizes the importance of integrating software supply chain security into daily operations rather than treating it as a one-time compliance task. In a recent video, she advocates for the active use of Software Bill of Materials (SBOM) for various security processes, including vulnerability assessments and incident responses. Drawing insights from Group-IB’s High-Tech Crime Trend Report 2026, she warns that supply chain attacks are becoming more sophisticated, often linking phishing, ransomware, and data breaches through the trust companies place in their suppliers. This shift means organizations need to be proactive in managing their software supply chain risks to protect against these evolving threats. Acknowledging that these vulnerabilities can have widespread implications, Tikhonova encourages teams to make security a daily habit.

Read Original

A recent report by Secret Double Octopus reveals that only 28% of the financial workforce is using phishing-resistant multi-factor authentication (MFA). Many banks and financial organizations still rely on traditional passwords, which leaves them vulnerable to phishing attacks and credential theft. The combination of phishing-resistant technologies with less secure methods, like passwords plus one-time passwords (OTPs), is common but insufficient to protect against identity security risks. This situation raises concerns about the overall security posture of financial institutions, as attackers can exploit weaknesses in authentication processes. As phishing attacks continue to rise, the need for stronger authentication measures becomes more critical for protecting sensitive financial data.

Read Original
PreviousPage 9 of 28Next