Reading view

There are new articles available, click to refresh the page.

Phishing Emails Use New Technique to Bypass Microsoft 365 Security Filters

Threat actors are using phishing emails with blank SMTP sender fields to bypass Microsoft 365 security filters, according to researchers at ReliaQuest.

Microsoft 365 Exchange Online uses a feature called “RejectDirectSend” to block unauthenticated Direct Send emails from an organization’s trusted domain. If an attacker omits the domain field from these emails, however, RejectDirectSend will no longer block the messages. Attackers can therefore exploit this technique to impersonate internal users.

Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters

Phishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated domains, and multi-stage URL cloaking designed to defeat conventional email inspection. The continuously running VBSpam comparative test evaluated ten public full email-security products and one open-source solution against wanted, unwanted, and malicious mail streams. The assessment was conducted under the […]

The post Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

UK Government Enables Passkey Login for 23 Million Users to Fight Phishing Attacks

The UK government has started implementing passkey authentication for GOV. UK One Login,UK One Login, providing over 23 million users with a faster and more secure way to access public services. This initiative aims to reduce reliance on passwords and SMS-based verification codes, which are common targets for fraud and credential theft. UK Enables Passkey […]

The post UK Government Enables Passkey Login for 23 Million Users to Fight Phishing Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Social Engineering Campaign Uses Phony NDAs to Avoid Detection

Researchers at Gen Digital are tracking a sophisticated social engineering campaign that’s using phony NDA documents to trick employees into moving the conversation to WhatsApp and personal email accounts. The attackers targeted an employee at Gen itself, but the employee recognized that it was a scam and played along to see what the attackers would do.

Warning: “Slop Squatting” Directs AI Users to Phishing Pages

Threat actors are increasingly leveraging AI hallucinations to plant phishing links and other malicious content in AI output, IEEE Spectrum reports. Large language models (LLMs) sometimes fabricate information, including web domains, when answering users’ questions. Attackers are registering these hallucinated web domains to host phishing pages.

FBI Alert: OAuth Consent Phishing is Targeting Users of Messaging Apps

The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting “prominent victims, their family members, and personal acquaintances.”

OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and disrupted, this campaign delivers malicious content assembled only after a user follows the attack chain. A blob URL is a […]

The post New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials

A large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly personalized credential-harvesting pages, and, in some cases, install ScreenConnect remote-access software. The campaign’s central advantage is that it presents trusted Google-owned domains at nearly every point a gateway, proxy, or analyst is likely to […]

The post Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud

Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help organizations reduce phishing and fraud risks associated with malicious QR code campaigns. Listed under Microsoft 365 Roadmap ID 570439, this feature is currently in development and is scheduled for rollout in […]

The post Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes

QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather than placing clickable links directly in emails. The shift is helping attackers bypass traditional secure email gateways and move victims from managed corporate devices to less-protected smartphones. The company recorded an average of […]

The post QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning

QR-code phishing, commonly known as quishing, is evolving beyond image-based payloads. Threat actors are now rendering scannable QR codes directly from HTML tables or text within email bodies, leaving no image attachment, embedded bitmap, or <img> element for traditional email scanners to inspect. The technique targets a structural blind spot in Secure Email Gateways (SEGs). […]

The post HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New Phishing Kit Uses AI to Fully Automate Vishing Attacks

A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB.

The phishing platform, called “Balonx,” includes a module dubbed “CallFlow” that the researchers say “represents a fundamental evolution” in the phishing-as-a-service market. This module uses four commercial AI services to conduct the attacks: OpenAI’s GPT-4o-mini, ElevenLabs’s AI voice generator, OpenAI Voice, and OpenAI Whisper.

Hacking the Healers: New KnowBe4 Whitepaper Highlights Record Security Breaches in Healthcare

When an organization has a security breach, it can cause significant financial, reputational and logistical damage. But in healthcare, where patient lives are on the line, the consequences can be much more catastrophic.

KnowBe4’s latest whitepaper on healthcare cybersecurity, “Hacking the Healers: How the Digital Workforce Became Cybersecurity's Frontline,” examines how decentralized clinical operations, remote staff and autonomous AI agents have dissolved traditional network perimeters, leaving healthcare organizations and patient safety vulnerable to targeted cyberattacks.

❌