❌

Reading view

There are new articles available, click to refresh the page.

Social Engineering Campaign Uses Phony NDAs to Avoid Detection

Researchers at Gen Digital are tracking a sophisticated social engineering campaign that’s using phony NDA documents to trick employees into moving the conversation to WhatsApp and personal email accounts. The attackers targeted an employee at Gen itself, but the employee recognized that it was a scam and played along to see what the attackers would do.

The Blind Spot: How β€œBulletproof” Phishing Redirectors Slip Past SEGs

By Shikhar Dalela and Jeewan Singh Jalal

The operators named the kit themselves.

Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called β€œ/.bulletproof”, and the PHP session cookie the kit sets on every visitor is named β€œbp_redir_sess.” The β€œbp” stands for bulletproof, which is an unusual degree of candor from a threat actor whose entire design philosophy is concealment.

Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation

Security operations teams face a constant balancing act: stopping sophisticated email threats, maintaining visibility across their attack surface and keeping administrative workflows running smoothly. When security tools operate in silos or rely on rigid, manual processes, friction builds up quickly. This friction consumes valuable time that analysts could spend on higher-priority initiatives.

❌