A phishing campaign has been detected that uses fake voicemail SVG attachments to trick recipients into clicking on malicious links. This attack targeted 5,527 organizations and sent out over 26,000 harmful emails. The SVG format allowed attackers to bypass traditional email security measures, making it easier for their messages to reach inboxes undetected. This incident is significant because it shows how attackers are continuously evolving their tactics to exploit vulnerabilities in email systems. Organizations need to be vigilant and educate their employees about the risks associated with unexpected voicemail notifications or attachments.
Articles tagged "Phishing"
Found 415 articles
BleepingComputer
Hasbro, the well-known toy and game manufacturer, has reported a data breach that has compromised the personal and financial information of some of its employees. While the company has not disclosed the exact number of individuals affected, this incident raises concerns about the security of sensitive employee data. The breach could lead to identity theft or financial fraud for those impacted. Hasbro has not provided specific details about how the attackers gained access to this information or what steps they are taking to address the issue. This incident serves as a reminder for companies to prioritize data protection and for employees to remain vigilant about potential phishing attempts or other security threats in light of the breach.
Rockwell Automation's OTTO Fleet Manager has a vulnerability (CVE-2026-75112) that could make it easier for attackers to conduct offline brute-force attacks on stored password hashes. The affected versions include all versions up to and including 2.36.2. This weakness arises from an insufficient work factor in the bcrypt hashing method, which could expose weakly hashed credentials if an attacker gains access to system backups. Users need to upgrade to version 2.36.3 to fix this issue. The vulnerability is particularly concerning for sectors like critical manufacturing and transportation, as it could lead to unauthorized access to sensitive systems.
Recent vulnerabilities have been discovered in the Xiiaozet LK100W device, affecting versions below 2.1.240. These vulnerabilities could allow attackers to take control of the device through OS command injection, missing authentication for critical functions, and authentication bypass methods. The most severe of these issues has a CVSS score of 9.8, indicating a critical risk of unauthorized access. Users worldwide are urged to update their devices to version 2.1.240 as a primary remediation step. The vulnerabilities expose sensitive information and could potentially lead to complete device compromise, making it crucial for organizations to address these security gaps promptly.
Ebyte's NA111-M device firmware version 9013-2-17 has multiple serious vulnerabilities that can allow attackers to take full control of the device. These vulnerabilities include issues with authentication, improper request handling, and lack of encryption for sensitive information. Attackers could exploit these flaws to access sensitive configurations, impersonate users, and disrupt device operations. Ebyte has acknowledged the vulnerabilities and is reportedly working on a patch, but there has been no further communication regarding its status. Users of the affected devices are advised to reach out to Ebyte for updates and take precautionary measures until a fix is available.
A security vulnerability has been discovered in the Applied Systems Engineering ASE2000 V2 Communications Test Set, affecting versions 2.25 to 2.37. This flaw could allow attackers to read or write local files, send unauthorized network requests, and impersonate trusted connections, leading to potential interception and modification of secure communications. Users are strongly advised to upgrade to version 2.38, which addresses these vulnerabilities by updating the log4net library and correcting TLS certificate validation logic. Until the upgrade is applied, users should limit access to installation directories and avoid using the software over untrusted networks. The vulnerabilities were reported to CISA by Enoch Wang, and while no public exploitation has been confirmed, the risks remain significant for organizations using affected versions.
Russian hackers have shifted their focus to targeting EU officials through popular messaging apps like Signal and WhatsApp. This change comes as governments in the EU are trying to move away from traditional email communication to these platforms for enhanced security. The attackers are using phishing tactics to compromise the accounts of officials, posing significant risks to sensitive information and national security. As these messaging services gain popularity among officials, the threat of phishing is evolving, highlighting the need for robust security measures and user awareness. This situation underscores the ongoing challenges that government entities face in protecting their communications from sophisticated cyber threats.
Carhartt recently suffered a significant data breach, with the ShinyHunters extortion group publishing sensitive information from nearly 13 million user accounts. This incident was reported by the data breach notification service Have I Been Pwned. The compromised data includes personal details that could be exploited by cybercriminals, raising concerns for customers who may be at risk of identity theft or phishing attacks. The breach underscores the vulnerability of retail companies to cyber threats and the importance of robust data protection measures. Users should be vigilant and consider changing their passwords and monitoring their financial accounts for unusual activity.
Hackers are taking advantage of npm and its mirrors to host fake HTML pages that mimic Cloudflare's CAPTCHA system. These pages trick users into clicking links that redirect them to websites controlled by the attackers. This tactic poses a significant risk, especially for developers and users who rely on npm for package management. By using trusted platforms like npm, attackers can increase the likelihood that users will fall for their scams. The incident raises concerns about the security of widely used software repositories and the potential for further exploitation if left unchecked.
A new phishing-as-a-service platform named AnonyMousKIT has been discovered, which automates the process of stealing passcodes from iPhones. This service utilizes voice AI agents to trick users into providing their unlock codes, specifically targeting those who have had their Apple devices stolen. Once attackers obtain the passcodes, they can disable the Activation Lock, allowing them to access and potentially resell the stolen devices. This poses a significant risk to iPhone users, as it could lead to increased theft and exploitation of stolen devices. Users are urged to remain vigilant and skeptical of unsolicited calls requesting sensitive information.
BleepingComputer
WhatsApp is enhancing its account security with the introduction of multiple passkeys and a more robust two-step verification process. These features aim to provide users with better protection against unauthorized access to their accounts. The update is part of WhatsApp's ongoing efforts to improve security, especially as the platform continues to grow in popularity. Users will benefit from these added layers of security, making it harder for attackers to compromise their accounts. This move is particularly important given the increasing number of phishing attempts and account takeovers targeting messaging apps.
Ebyte's NE2-D11 firmware, version FW-9167-0-11, has multiple serious vulnerabilities that could allow attackers to gain unauthorized access and control over devices. Issues include inadequate authentication, cleartext transmission of sensitive information, and weaknesses in session management, which could lead to unauthorized configuration changes and data breaches. The vulnerabilities, which have a CVSS score as high as 9.8, affect critical sectors like manufacturing and energy, and their impact is global. Ebyte has acknowledged the problems and is working on a patch, but there has been little communication about its status. Users are advised to contact Ebyte for updates and to implement security measures in the meantime.
Rently Smart Home has a critical vulnerability affecting versions 20.1.0 and earlier, which allows attackers to access sensitive information, including Master Pins, and override user permissions. This issue arises from insufficiently protected credentials. The vulnerability is particularly concerning for users in commercial facilities and information technology sectors across the United States and India. Rently has addressed this flaw with a patch released in late June 2026, meaning users do not need to take any additional action. However, organizations are still encouraged to improve their cybersecurity measures to mitigate risks associated with such vulnerabilities.
A serious vulnerability has been discovered in the PayRange API, affecting all versions of the product. This flaw allows both authenticated and unauthenticated attackers to access sensitive information about devices on the PayRange network. They could potentially modify device settings, leading to service disruptions or altered device displays. The vulnerability is attributed to a lack of proper authorization on management endpoints, making device details publicly accessible. PayRange has not yet collaborated with CISA to address this issue, and users are encouraged to reach out to their customer support for guidance. Given the nature of this vulnerability, it poses a significant risk to users in the commercial facilities sector across the United States and Canada.
A serious vulnerability has been identified in Zoneminder, a popular surveillance software, affecting versions 1.37.48 and 1.38.3. This flaw allows authenticated users with permission to view events to execute arbitrary commands on the server through an OS command injection in the event export functionality. While no active exploitation has been reported, the potential for remote code execution poses significant risks to users. Zoneminder recommends that users upgrade to version 1.38.3 or later to mitigate this issue. Organizations utilizing this software should act promptly to protect their systems from possible attacks.