Recent research has shown vulnerabilities in passkey systems designed to enhance online security by replacing traditional passwords and resisting phishing attacks. Three separate studies demonstrated methods for bypassing these protections without breaking the underlying cryptography. For instance, attackers were able to exploit signed authentication data exposed by Windows, leverage a cloud-synced passkey system compromised by existing malware on a victim's device, and other techniques. This is concerning for users and organizations relying on passkeys for secure authentication, as it suggests that even advanced security measures can be undermined. As these attacks become more sophisticated, it raises questions about the reliability of passkeys and the need for ongoing vigilance in security practices.
Levi Strauss recently fell victim to a cyberattack that involved social engineering tactics. Attackers gained access to the computers of three employees, allowing them to steal sensitive corporate data. This breach raises concerns about the effectiveness of employee training in recognizing phishing attempts and other social engineering schemes. The stolen data could potentially harm the company's reputation and lead to legal ramifications. Organizations must remain vigilant and strengthen their cybersecurity measures to prevent similar incidents in the future.
IEH Corporation, a U.S. defense and aerospace manufacturer based in Brooklyn, New York, recently suffered a phishing attack that compromised its Microsoft 365 inbox. This breach potentially exposed sensitive emails and export-controlled military data. IEH specializes in high-reliability electrical connectors, which are critical in military and aerospace applications. The incident raises concerns about the security of sensitive information in the defense sector, as attackers could exploit such data for malicious purposes. Companies in similar fields need to be vigilant and enhance their email security measures to prevent similar attacks in the future.
Unlimited Technology Systems, a U.S.-based healthcare technology company, has reported a data breach affecting approximately 3.8 million individuals. The breach occurred after hackers gained access to one of its commercial data centers between October 5 and 10, 2025. Stolen data includes personal, medical, and insurance information of patients, raising significant concerns about privacy and identity theft. This incident emphasizes the vulnerabilities within healthcare technology systems, which are critical for patient care and data security. Individuals affected should be vigilant about potential phishing attempts and monitor their accounts for suspicious activity.
A vishing group identified as UNC6671 has shifted its focus to targeting mergers and acquisitions (M&A) firms with extortion schemes. This group, known for using voice phishing tactics, aims to exploit sensitive financial data and negotiations occurring in these high-stakes environments. Experts are advising firms to implement managed-device logins and closely monitor audit logs to combat the rising threat of phishing-led data theft. The implications of this shift are significant, as M&A firms often handle large sums of money and confidential information, making them prime targets for attackers seeking to leverage that data for financial gain.
A recent hacking campaign has targeted over 200 firms, including prominent financial institutions like Blackstone and Bridgewater Associates, by impersonating IT support through fake help desks. The attackers, associated with various names like Redact and Falcon, set up credential-stealing websites aimed at employees to capture multi-factor authentication (MFA) credentials. This tactic raises significant concerns as it not only compromises sensitive financial data but also undermines trust in internal IT support systems. The scale of this operation suggests a well-organized effort to exploit vulnerabilities in corporate security practices, emphasizing the need for enhanced training and awareness among employees about potential phishing attempts. Companies must remain vigilant and adopt stricter security measures to protect against such impersonation schemes.
A vishing extortion group known as UNC6671 has rebranded several times, initially operating under the name BlackFile. The group has expanded its operations by adopting new names including Redact, Pink, Helix, and Falcon, reportedly making millions through their schemes. Vishing, or voice phishing, involves using phone calls to trick individuals into revealing sensitive information or transferring money. This group's activities raise concerns for both individuals and businesses, as they can lead to significant financial losses and a breach of personal data. The ongoing evolution of this group’s branding suggests they are attempting to evade detection while continuing their extortion efforts.
A recent examination of AI-generated spear phishing messages revealed that even seasoned professionals can struggle to identify these sophisticated threats. A banker at a credit union sorted a dozen personalized text messages, and one stood out as particularly convincing, resembling legitimate fraud alerts sent by the bank. This incident underscores the growing risk of AI-driven phishing schemes, where attackers craft messages that closely mimic official communications. As these tactics become more refined, they pose significant challenges for employees who must remain vigilant against such deceptive practices. The potential for falling victim to these scams can lead to unauthorized access to sensitive information, financial loss, and reputational damage for institutions.
A vulnerability has been discovered in Medixant's RadiAnt DICOM software that could allow attackers to exploit specially crafted DICOM files. Versions 2025.2 and earlier of the software are affected, which could lead to application crashes or even remote code execution due to an out-of-bounds write triggered by malicious JPEG-compressed pixel data. Users are advised to upgrade to version 2026.1 to mitigate this risk. The vulnerability is particularly concerning for healthcare and public health sectors worldwide, as it could compromise patient data and system integrity. While there are currently no reports of this vulnerability being actively exploited, users should remain cautious and only open DICOM files from trusted sources.
A recently discovered vulnerability in Johnson Controls Inc.'s TL280 device could allow attackers to access sensitive information. Specifically, versions of the TL280 prior to 5.63 are impacted due to the use of hardcoded credentials in the device's firmware. This presents a significant risk, particularly for sectors such as critical manufacturing, government services, and energy. To mitigate the threat, Johnson Controls recommends updating to firmware version 5.63 and implementing several network security measures, such as restricting access to trusted VLANs and monitoring device access logs for unusual activity. Although no active exploitation of this vulnerability has been reported, organizations should take proactive steps to protect their systems.
A recent phishing campaign is taking advantage of concerns related to the COLDCARD wallet vulnerability and a significant Bitcoin theft, estimated at $88.6 million. Cybercriminals are using this fear to trick users into downloading ScreenConnect, a remote access tool. This software could allow attackers to gain control over victims' devices, potentially leading to further theft of digital assets. Users of the COLDCARD wallet are particularly at risk as they may be targeted due to their connection to the vulnerability. The situation underscores the need for heightened vigilance among cryptocurrency users, especially in the face of ongoing scams exploiting current events.
Kali365 is exploiting Microsoft authentication to gain unauthorized access to corporate data in the United States. The phishing kit tricks users into approving device codes controlled by attackers on the legitimate Microsoft authentication page. Once users authorize this access, attackers receive tokens that allow them to access emails, documents, and cloud resources. This poses serious risks, as it opens the door to data breaches and potential financial fraud for affected organizations. Companies using Microsoft services should be vigilant and educate their employees about this method of attack, as it takes advantage of a widely trusted platform.
Cybercriminals are running a phishing campaign disguised as Bank of America communications to deceive users into downloading a harmful script. This script installs ScreenConnect, a remote access tool that allows attackers to control infected systems. Victims of this scam may unknowingly give hackers persistent access to their devices, potentially leading to data theft or further exploitation. It's crucial for users to remain vigilant against such phishing attempts and verify the authenticity of any unexpected emails. This incident serves as a reminder that even well-known brands can be used as bait in cyber attacks.
The phishing-as-a-service toolkit known as Greatness has added a new feature that allows attackers to use device code phishing to bypass Multi-Factor Authentication (MFA). This technique exploits the OAuth 2.0 Device Authorization Grant, a legitimate protocol, to gain unauthorized access to user accounts. By doing so, attackers can steal authentication tokens and control user accounts without needing to compromise passwords directly. This development is concerning as it poses risks to a wide range of applications and services that rely on MFA for security, making it easier for cybercriminals to execute their plans. Organizations and users must be vigilant and update their security practices to mitigate the risks associated with this evolving threat.
A recent analysis highlights how attackers are exploiting cloud services to bypass multi-factor authentication (MFA) using a technique called Account in the Middle (AitM). This involves leveraging service workers and platforms like Ultraviolet to host phishing sites on legitimate cloud infrastructure, making them harder to detect. Major platforms identified include Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS, which are being misused to create convincing phishing pages. This tactic poses a significant risk to users who might unknowingly provide their credentials, as it undermines the security measures intended to protect them. Companies utilizing these services should be aware of this vulnerability and take steps to secure their users against such phishing schemes.