Tag phishing

Russian Hackers Leverage New NTLM Vulnerability to Distribute RAT Malware through Phishing Campaigns

A newly discovered security vulnerability in Windows NT LAN Manager (NTLM) has been exploited in a zero-day attack, with suspected ties to Russian threat actors targeting Ukraine. This vulnerability, designated as CVE-2024-43451 and rated with a CVSS score of 6.5, allows attackers to possibly expose a user’s NTLMv2 hash. Microsoft…

Read MoreRussian Hackers Leverage New NTLM Vulnerability to Distribute RAT Malware through Phishing Campaigns

Understanding the Surge in Data Breaches

Recent analyses indicate a troubling rise in cyber intrusions, fueled by the proliferation of criminal tools and insufficient defenses. A recent episode of The Indicator from Planet Money delves into how data breaches are accelerating, the decreasing costs of entry for attackers, and the implications this holds for patients, consumers,…

Read MoreUnderstanding the Surge in Data Breaches

HHS Watchdog Identifies IT Security Vulnerabilities in Medicaid Across Several States

Governance & Risk Management , Healthcare , Industry Specific Penetration Testing Reveals Vulnerabilities in State Medicaid Systems Marianne Kolbasuk McGee (HealthInfoSec) • October 21, 2025 HHS OIG’s penetration testing of ten state Medicaid systems highlighted critical security gaps that must be addressed to safeguard data from advanced cyber threats. (Image:…

Read MoreHHS Watchdog Identifies IT Security Vulnerabilities in Medicaid Across Several States

Researchers Alert Iranian Users to Rampant SMS Phishing Schemes

A recent phishing campaign has emerged, leveraging socially engineered SMS messages to deliver malware to Android devices. This operation appears to impersonate Iranian governmental and social security entities, aiming to extract credit card information and facilitate financial theft from victims’ bank accounts. In contrast to other forms of banking malware,…

Read MoreResearchers Alert Iranian Users to Rampant SMS Phishing Schemes

Rising Cross-Border Phishing Attacks Sweep Across Asia

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Phishing Campaigns Transition from China to Malaysia Targeting Chinese-Speakers Prajeet Nair ( @prajeetspeaks) • October 17, 2025 Image: Shutterstock Recent investigations reveal that a series of coordinated cyberattacks targeting Chinese-speaking individuals across the Asia-Pacific region can be traced back to a single…

Read MoreRising Cross-Border Phishing Attacks Sweep Across Asia

The Surge in Airline Data Breaches: Understanding the Reasons Behind It

Cybercriminals have increasingly turned their attention to airlines, drawn by the vast amounts of personal data these companies collect. Among the most sought-after information are passports and government identification, which pose a significant risk for long-term identity theft. According to Incogni, a company specializing in data privacy and removal, leaks…

Read MoreThe Surge in Airline Data Breaches: Understanding the Reasons Behind It

North Korean Hackers Steal Millions from Global Cryptocurrency Startups

Recent intelligence reveals that operators linked to the Lazarus group’s BlueNoroff sub-group have orchestrated a series of cyberattacks targeting small and medium-sized enterprises across the globe. The objective of these attacks is to siphon cryptocurrency assets, marking a significant maneuver by this recognized North Korean state-sponsored actor. Kaspersky, a prominent…

Read MoreNorth Korean Hackers Steal Millions from Global Cryptocurrency Startups

How Hackers Target User Credentials Through Phishing and Sell Them Online

Cybersecurity Alert: The Rising Threat of Stolen Credentials Recent trends in cybercrime highlight the concerning prevalence of stolen account credentials as a primary vector for initial access attacks. A single compromised set of credentials poses significant risks, potentially jeopardizing an entire organization’s network security. The 2023 Verizon Data Breach Investigation…

Read MoreHow Hackers Target User Credentials Through Phishing and Sell Them Online

Microsoft Issues Alert on New “Payroll Pirate” Scam Targeting Employee Direct Deposits

Microsoft has issued a warning about a sophisticated scam known as “Payroll Pirate,” which is currently targeting employees by redirecting their paycheck deposits into accounts controlled by fraudsters. This attack begins with the compromise of employee profiles on platforms like Workday or other cloud-based HR services. The scammers initiate the…

Read MoreMicrosoft Issues Alert on New “Payroll Pirate” Scam Targeting Employee Direct Deposits