Articles tagged "Proofpoint"

Found 6 articles

Researchers from Proofpoint have uncovered a campaign by a suspected Chinese espionage group targeting universities, specifically focusing on physics and engineering departments. The attackers are using an exploit chain involving Roundcube, an open-source webmail software, to gain access to sensitive information. This campaign is believed to still be active, which raises concerns for institutions that may be vulnerable to further intrusions. The implications of this breach could be significant, as universities often hold valuable research data and intellectual property. It's crucial for educational institutions to bolster their cybersecurity measures to protect against these types of targeted attacks.

Read Original

Researchers at Proofpoint have identified two phishing campaigns linked to a North Korean hacking group known as Contagious Interview, also referred to as Famous Chollima. These campaigns are cleverly disguised as recruitment efforts for developer roles or as requests for code reviews. The tactics used by these attackers demonstrate a sophisticated approach to lure potential victims into providing sensitive information. This is particularly concerning for software developers and companies in the tech sector, who may be targeted due to their access to valuable intellectual property and sensitive data. The rise in these types of campaigns serves as a reminder for organizations to remain vigilant about phishing threats and to educate employees about identifying suspicious communications.

Read Original

A recent study by Proofpoint revealed that half of global organizations have experienced incidents involving artificial intelligence, even with AI security measures in place. This suggests that existing safeguards are not sufficient to prevent misuse or attacks related to AI technologies. The research highlights a growing concern among businesses about the vulnerabilities associated with AI, particularly as adoption rates increase. Security professionals need to reassess their strategies to better protect against AI-related threats, as the technology continues to evolve. This finding serves as a wake-up call for organizations to enhance their defenses and stay ahead of potential risks.

Read Original

Recent research from Proofpoint reveals that hackers are increasingly targeting logistics firms, aiming to steal cargo and divert payments. These cyberattacks are reportedly connected to organized crime, leading to significant losses in the industry. Attackers employ coordinated remote access campaigns to infiltrate trucking and logistics companies, which raises concerns about the security of supply chains. This trend poses a serious risk not only to the affected companies but also to the broader economy, as disruptions in logistics can impact the availability of goods. Companies in the logistics sector need to enhance their cybersecurity measures to protect against these rising threats.

Read Original

Proofpoint has acquired Acuvity, a move aimed at addressing the security risks associated with agentic AI. This acquisition focuses on enhancing cybersecurity measures as organizations increasingly use AI technologies that can operate autonomously. The integration of Acuvity's capabilities is expected to bolster Proofpoint's existing security solutions, making them more resilient against potential AI-driven threats. This development is significant as it reflects the growing concern among cybersecurity firms about the challenges posed by advanced AI systems that could be exploited by attackers. Companies using AI technologies should stay informed about these advancements to better prepare for potential security vulnerabilities.

Read Original
Actively Exploited

A recent report from Proofpoint reveals a rise in phishing attacks that take advantage of Microsoft's OAuth device code flow. These campaigns target Microsoft 365 users, tricking them into providing access to their accounts through fake sign-in prompts. The attacks exploit the trust users place in the OAuth process, which is designed to facilitate secure authentication. As a result, individuals and organizations using Microsoft 365 could be at risk of unauthorized access to sensitive information. This surge in phishing attempts underscores the need for heightened awareness and vigilance among users to avoid falling victim to these scams.

Read Original