All posts tagged: phishing

Apple Passwords App Vulnerability Exposed Users for Months

Apple Passwords App Vulnerability Exposed Users for Months

Apple’s Passwords app, designed to enhance security for iOS users, ironically left them vulnerable to phishing attacks for nearly three months. Security researchers recently revealed that the flaw exposed sensitive information, raising concerns about cybersecurity risks — even with trusted software. The vulnerability explained Researchers at Mysk identified the flaw, which stemmed from the app’s use of unencrypted HTTP connections when retrieving website icons and opening password reset pages. This security lapse allowed attackers to intercept data and redirect users to malicious phishing sites. >Mysk’s team discovered that the Passwords app contacted over 130 websites using unprotected HTTP traffic. This made it possible for hackers on the same Wi-Fi network — such as in cafes, airports, or hotels — to manipulate the requests and trick users into visiting fraudulent websites designed to steal login credentials. Apple’s response and fix Upon discovering the vulnerability in September 2024, Mysk promptly reported the issue to Apple. The tech giant addressed the flaw with the iOS 18.2 update, released in December 2024. This update implemented encrypted HTTPS connections for …

FBI & CISA Urge Immediate Action

FBI & CISA Urge Immediate Action

Image: DC_Studio/Envato Elements Federal cybersecurity officials are raising red flags over a surge in attacks by the Medusa ransomware group. First detected in June 2021, the group has gained traction recently by using basic but effective methods — like phishing emails and exploiting outdated software — to break into systems and hold data hostage. In a joint advisory released last week, the FBI, Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) urged businesses and institutions to take immediate steps to protect their systems. The warning is part of the government’s ongoing #StopRansomware initiative. Must-read security coverage A growing ransomware-as-a-service business Originally a closed operation, Medusa has now adopted a ransomware-as-a-service (RaaS) model. This means the developers provide the ransomware software to partners, known as “Medusa actors,” who carry out the attacks. These affiliates are often recruited from online criminal forums and are sometimes paid bonuses to work exclusively for Medusa. “Potential payments between $100 USD and $1 million USD are offered to these affiliates with the opportunity to …

96% of Phishing Attacks in 2024 Exploited Trusted Domains

96% of Phishing Attacks in 2024 Exploited Trusted Domains

Threat actors are increasingly targeting trusted business platforms such as Dropbox, SharePoint, and QuickBooks in their phishing email campaigns and leveraging legitimate domains to bypass security measures, a new report released today has found. By embedding sender addresses or payload links within legitimate domains, attackers evade traditional detection methods and deceive unsuspecting users. According to Darktrace’s Annual Threat Report 2024, the authors detected more than 30.4 million phishing emails, reinforcing phishing as the preferred attack technique. Legitimate enterprise services hijacked for most phishing campaigns in 2024 Darktrace noted cybercriminals are exploiting third-party enterprise services, including Zoom Docs, HelloSign, Adobe, and Microsoft SharePoint. In 2024, 96% of phishing emails utilised existing domains rather than registering new ones, making them hard to detect. Attackers were observed using redirects via legitimate services, such as Google, to deliver malicious payloads. In the case of the Dropbox attack, the email contained a link leading to a Dropbox-hosted PDF with an embedded malicious URL. SEE: How business email compromise attacks emulate legitimate web services to lure clicks Alternatively, threat actors abused hijacked …

How to Prevent Phishing Attacks with Multi-Factor Authentication

How to Prevent Phishing Attacks with Multi-Factor Authentication

Phishing takes advantage of the weakest link in any organization’s cybersecurity system — human behavior. Phishing attacks are generally launched via email, although some opening salvos have begun using text messaging or phone calls. In the most common scenario, an email arrives purporting to be from HR or IT, for example. It looks just like any other company email. It advises viewers to update their personal information or IT profile by clicking on a link or opening an attachment. When the person does so, they are told to enter personally identifiable information, such as their date of birth, full name, social security number, and passwords. This enables a bad actor to take over their account and steal their identity, and it can also be the initial stage in a ransomware attack that locks the entire company out of IT systems. According to KnowBe4’s 2024 Global Phishing By Industry Benchmarking Report, one in three employees, or 34.3% of an organization’s workforce, are likely to interact with a malicious phishing email. After 90 days of training against …

Phishing Emails in Australia Rise by 30%

Phishing Emails in Australia Rise by 30%

The number of phishing emails received by Australians surged by 30% last year, new research by security firm Abnormal Security has found. Cybercriminals have increasingly targeted the Asia-Pacific region, partly because it is becoming a larger player in critical industries like data centres and telecoms. For APAC as a whole, credential phishing attacks rose by 30.5% between 2023 and 2024, according to the research. New Zealand saw a 30% rise, while for Japan and Singapore, it was 37%. Out of all the types of advanced email attacks, including business email compromise and malware deployment, phishing saw the biggest increase. “The surge in attack volume across the APAC region can likely be attributed to several factors, including the strategic significance of its countries as epicentres for trade, finance, and defence,” said Tim Bentley, Vice President of APJ at Abnormal Security said in a press release. “This makes organisations in the region attractive targets for complex email campaigns designed to exploit economic dynamics, disrupt essential industries, and steal sensitive data.” SEE: 80% of Critical National Infrastructure Companies …

Sneaky Log Phishing Scheme Targets Two-Factor Security

Sneaky Log Phishing Scheme Targets Two-Factor Security

Security researchers at French firm Sekoia detected a new phishing-as-a-service kit targeting Microsoft 365 accounts in December 2024, the company announced on Jan. 16. The kit, called Sneaky 2FA, was distributed through Telegram by the threat actor service Sneaky Log. It is associated with about 100 domains and has been active since at least October 2024. Sneaky 2FA is an adversary-in-the-middle attack, meaning it intercepts information sent between two devices: in this case, a device with Microsoft 365 and a phishing server. Sneaky 2FA falls under the class of business email compromise attacks. “The cybercriminal ecosystem associated with AiTM phishing and Business Email Compromise (BEC) attacks is continuously evolving, with threat actors opportunistically migrating from one PhaaS platform to another, supposedly based on the quality of the phishing service and the competitive price,” Sekoia analysts Quentin Bourgue and Grégoire Clermont wrote in the firm’s analysis of the attack. Must-read security coverage How does the Sneaky 2FA phishing-as-a-service kit work? Sneaky Log sells access to the phishing kit through a chatbot on Telegram. Once the customer …

eBay and Beazley Reportedly Being Targeted by Advanced AI-Generated Phishing Scams

eBay and Beazley Reportedly Being Targeted by Advanced AI-Generated Phishing Scams

eBay, the ecommerce giant and several other companies are reportedly witnessing an increased volume of personalised phishing attacks aimed towards high-level employees. As per the report, these phishing scams are being carried out using artificial intelligence (AI) systems to make them appear human-like and avoid the telltale signs of a typical scam email. These cyber attackers are reportedly also using AI to scrape and analyse data about company executives to add a personal touch to the messages. Basic security filters are said to be insufficient to stop such emails at an organisational level. Company Executives Being Targeted by AI Phishing Scams According to a Financial Times report, companies such as eBay and the UK-based insurance firm Beazley have highlighted the increase in fraudulent emails that contain personal information about their executive-level employees. Kirsty Kelly, the chief informational security officer at Beazley, told the publication that AI is suspected to be behind these attacks due to the personal nature of the emails. Kelly reportedly also added that these targeted phishing attacks have likely been conducted after …

Protect 3 Devices With This Maximum Security Software

Protect 3 Devices With This Maximum Security Software

TL;DR: Protect your privacy on three devices with a 1-year subscription to Trend Micro Maximum Security for $19.99 (reg. $49.99). Cyber threats have become more sophisticated, and even cautious users can find themselves vulnerable to ransomware attacks, phishing schemes, and identity theft. A single click on the wrong link or a cleverly disguised email can lead to encrypted files, stolen credentials, or compromised accounts. Tech-savvy users know how to spot the signs of a scam or avoid malware, but skilled tech users also know it’s easier to invest in tools that keep you from being hyper-vigilant. Trend Micro Maximum Security defends against ransomware, phishing, and identity theft. It protects your documents from unauthorized encryption, backs up locked files, detects spam and phishing scams, and it’s $20 for one year on three devices. What does Trend Micro do? Trend Micro gives you tools to identify dangerous links in emails and social media so you can browse confidently. Parental controls help give you peace of mind by letting you restrict access to unsuitable websites and monitor desktop …

Reported cybersecurity incidents in banking sector fell by 81% between 2021 and 2023: MoS | Latest News India

Reported cybersecurity incidents in banking sector fell by 81% between 2021 and 2023: MoS | Latest News India

Incidents of cybersecurity in the Indian banking sector reported to the Indian Computer Emergency Response Team (Cert-In) fell by 81% between 2021 and 2023, minister of state for electronics and information technology Jitin Prasada said in a written response to the Lok Sabha on Wednesday. Such incidents fell by 15.7% between 2022 and 2023. BJP MP Jitin Prasada speaks in the Lok Sabha during the ongoing winter session of Parliament in New Delhi. (SansadTV) As per the data presented in the Parliament, 122,764 cybersecurity incidents, including phishing, network scanning and probing, website hacking, and virus and malware, were reported from the banking sector in 2021. This number fell to 27,482 in 2022 and 23,158 in 2023. Prasada presented the data while responding to a question by BJP MP Delkar Kalaben Mohanbhai. Phishing incidents jumped from 215 in 2021 to 1,145 in 2022, but fell to 401 in 2023. Incidents of website hacking increased from 18 in 2021 to 57 in 2022, but fell to 39 in 2023. Incidents of network scanning and probing fell from …

Itch.io is currently offline due to a ‘trash AI-powered’ phishing report

Itch.io is currently offline due to a ‘trash AI-powered’ phishing report

Indie game storefront Itch.io is currently offline because of what it describes as a bogus phishing report. While the game store’s servers are still online, the domain for the website is currently pointing towards IP addresses that itch.io doesn’t own — making it inaccessible for most people. Itch.io blames pop culture collectibles company Funko for the issues in a post on X, “because they use some trash ‘AI-powered’ Brand Protection Software called Brand Shield that created some bogus Phishing report to our registrar.” While the disputed page has been taken down, itch.io’s domain registrar, iwantmyname, still disabled the domain likely due to automated systems. According to a post on X, the indie game marketplace is now waiting on the domain registrar to respond and re-enable its domain. If you know how to tweak your hosts file that maps hostnames to IP addresses then you can use the 45.33.107.166 IP address in the meantime, but you’ll need to remove the entry once the domain is restored. Itch.io is hoping the problems will be resolved in a matter …