Articles tagged with: #phishing Clear filter
Kimsuky APT Data Leak  -  GPKI Certificates, Rootkits and Cobalt Strike Personal Uncovered

Kimsuky APT Data Leak - GPKI Certificates, Rootkits and Cobalt Strike Personal Uncovered

Cyber Security News cybersecuritynews.com

In late June 2025, a significant operational dump from North Korea's Kimsuky APT group surfaced on a dark-web forum, exposing virtual machine images, VPS infrastructure, customized malware and thousands of stolen credentials. This leak offers an unprecedented window into the group's espionage toolkit, revealing how Kimsuky conducts phishing campaigns, maintains persistence and evades detection within

Telecom Fiji taps Allot for network-based cybersecurity service

Telecom Fiji taps Allot for network-based cybersecurity service

cybersecurity www.reddit.com

Telecom Fiji announced on Saturday it has launched NetSafe, a new network-based cybersecurity service for businesses delivered in partnership with telecoms software firm Allot. The NetSafe service - which was officially launched at the end of the Pacific Fiber Conference 2025 in Fiji on Thursday - leverages the Allot Secure solution to offer protection against online threats including malware attacks, ransomware, phishing attempts and malicious websites that can infect devices or attempt to...

Hackers Leverage Google Classroom for 115,000+ Phishing Emails Targeting 13,500+ Organizations

Hackers Leverage Google Classroom for 115,000+ Phishing Emails Targeting 13,500+ Organizations

Cyber Security News cybersecuritynews.com

A large-scale phishing campaign was conducted by threat actors who abused Google Classroom to distribute over 115,000 malicious emails to more than 13,500 organizations globally. The campaign uncovered by Check Point unfolded in five distinct waves between August 6 and August 12, 2025, and weaponized the trusted educational platform to bypass conventional security filters. The

KnowBe4 Report: Global Financial Sector Faces Cyber Threat Surge

KnowBe4 Report: Global Financial Sector Faces Cyber Threat Surge

Cyber Security - AI-Tech Park ai-techpark.com

Research shows financial institutions experience up to 300 times more cyberattacks than other sectors, with large banks reporting 45% of employees susceptible to phishing attacks KnowBe4, the world-renowned cybersecurity platform that comprehensively addresses human risk management, has released its latest research paper "Financial Sector Threats Report," uncovering critical insights into...

Transparent Tribe Targets Indian Govt With Weaponized Desktop Shortcuts via Phishing

Transparent Tribe Targets Indian Govt With Weaponized Desktop Shortcuts via Phishing

The Hacker News thehackernews.com

The advanced persistent threat (APT) actor known as Transparent Tribe has been observed targeting both Windows and BOSS (Bharat Operating System Solutions) Linux systems with malicious Desktop shortcut files in attacks targeting Indian Government entities. "Initial access is achieved through spear-phishing emails," CYFIRMA said. "Linux BOSS environments are targeted via weaponized .desktop

Hackers Leverage SendGrid in Recent Attack to Harvest Login Credentials

Hackers Leverage SendGrid in Recent Attack to Harvest Login Credentials

Cyber Security News cybersecuritynews.com

A sophisticated credential harvesting campaign has emerged, exploiting the trusted reputation of SendGrid to deliver phishing emails that successfully bypass traditional email security gateways. The attack leverages SendGrid's legitimate cloud-based email service platform to create authentic-looking communications that target unsuspecting users across multiple organizations. The campaign employs a multi-faceted approach, utilizing three distinct email themes

New Gmail Phishing Attack Uses AI Prompt Injection to Evade Detection

New Gmail Phishing Attack Uses AI Prompt Injection to Evade Detection

Cyber Security News cybersecuritynews.com

Phishing has always been about deceiving people. But in this campaign, the attackers weren't only targeting users; they also attempted to manipulate AI-based defenses. This is an evolution of the Gmail phishing chain I documented last week. That campaign relied on urgency and redirects, but this one introduces hidden AI prompts designed to confuse automated

Detailed investigation of phishing site

Detailed investigation of phishing site

cybersecurity www.reddit.com

What would be your detailed approach in safely investigating a phishing site if automated tools like urlscan.io or virustotal are not available? How would you analyze the actual contents of the site and determine that it's a phishing site? submitted by /u/DancingKodan [link] [comments]

Linux Malware Delivered via Malicious RAR Filenames Evades Antivirus Detection

Linux Malware Delivered via Malicious RAR Filenames Evades Antivirus Detection

The Hacker News thehackernews.com

Cybersecurity researchers have shed light on a novel attack chain that employs phishing emails to deliver an open-source backdoor called VShell. The "Linux-specific malware infection chain that starts with a spam email with a malicious RAR archive file," Trellix researcher Sagar Bade said in a technical write-up. "The payload isn't hidden inside the file content or a macro, it's encoded directly

South Asian APT Hackers Using Novel Tools to Compromise Phones of Military-Adjacent Members

South Asian APT Hackers Using Novel Tools to Compromise Phones of Military-Adjacent Members

Cyber Security News cybersecuritynews.com

A sophisticated South Asian Advanced Persistent Threat (APT) group has been conducting an extensive espionage campaign targeting military personnel and defense organizations across Sri Lanka, Bangladesh, Pakistan, and Turkey. The threat actors have deployed a multi-stage attack framework combining targeted phishing operations with novel Android malware to compromise the mobile devices of military-adjacent individuals. The

Hackers Weaponize QR Codes Embedded with Malicious Links to Steal Sensitive Information

Hackers Weaponize QR Codes Embedded with Malicious Links to Steal Sensitive Information

Cyber Security News cybersecuritynews.com

Cybersecurity researchers have observed a surge in phishing campaigns leveraging QR codes to deliver malicious payloads. This emerging threat, often dubbed "quishing," exploits the opaque nature of QR codes to conceal harmful URLs that redirect victims to credential-harvesting sites or malware downloads. Unlike traditional phishing links that can be flagged by email gateways, QR codes