Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
Cyber attackers are increasingly exploiting vulnerabilities in SaaS environments, using sophisticated methods like vishing for data theft and control over systems.
Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
Cyber attackers are increasingly exploiting vulnerabilities in SaaS environments, using sophisticated methods like vishing for data theft and control over systems.
ShinyHunters' extortion campaigns are expanding, using vishing and victim-branded credential harvesting to compromise SSO and bypass MFA in cloud and SaaS environments.
ShinyHunters claim to be behind SSO-account data theft attacks - DataBreaches.Net
Voice phishing targeting Okta, Microsoft, and Google SSO lets attackers bypass MFA, access corporate SaaS platforms, and steal company data for extortion.
PDFSider is a stealthy Windows backdoor deployed via social engineering and DLL side-loading to provide persistent, encrypted access and data exfiltration over DNS.
Why Google is really warning 2.5 billion Gmail users to stop using their passwords
Google advises abandoning passwords in favor of stronger protections after Salesforce-sourced data boosted targeted phishing and impersonation attacks.
Teen charged with Las Vegas casino cyber heist | Computer Weekly
A teenage suspect surrendered and faces multiple charges for Scattered Spider cyberattacks that disrupted MGM and Caesars, causing major losses and data theft.
Google Says Claims of Mass Gmail Security Breach Are "Entirely False"
Google denied issuing mass Gmail security alerts, confirmed a UNC6040 vishing incident exposed basic business contact data but said Gmail accounts were not broadly compromised.
Mother of all Google breaches puts all 2.5b Gmail users at risk
A breach of a Google Salesforce-managed database exposed contact data for 2.5 billion Gmail users, enabling scammers to attempt account hijacking through vishing and phishing.