Phishing-as-a-Service lowers barriers to entry for cybercriminals to such an extent that hardware-based authentication according to FIDO2 standards becomes an essential defensive measure.
An AI agent executed a ransomware attack with complete automation, demonstrating that autonomous malware can significantly increase the speed and efficiency of attacks.
Around 290 fake GitHub repositories impersonate legitimate security and developer tools while distributing infostealers to compromise credentials and sensitive data from developers.
The U.S. Department of the Treasury sanctions a VPN provider for the first time for systematically supporting ransomware groups and other cybercriminals.
Forg365 is a PhaaS service sold for 400 dollars monthly that combines device-code phishing and AitM attacks against Microsoft 365 and is optimized through antibot evasion and AI-powered lure automation.
An exposed Python HTTP server instance with directory listing enabled revealed an attacker’s phishing toolkit and enabled the discovery of a total of three Evilginx campaigns targeting Microsoft 365.
Security incidents frequently arise not from sophisticated attacks, but from overlooked configurations, reused resource names, and tolerated misadministration.