The fact that phishing attacks have been on the rise is no secret. One of the most interesting developments is that malicious emails are now being timed to coincide with the "mid-afternoon slump" common to office workers.
According to the Phishing Activity Trends Report by the Anti-Phishing Working Group (APWG), phishing attacks surpassed one million for the first time in three months in the first quarter of 2022.
Study shows effects of phishing awareness training starts to wear off after four months and many employees will have lost what they learned almost entirely after six months.
The embassy phishing campaign is just one element of a rash of recent activity by the Russian hackers referred to as APT 29, probably better known to the general public as Cozy Bear.
Researchers have discovered a new phishing campaign leveraging Facebook posts to bypass email security and steal users' account credentials and personal information.
A dark web forum recruited affiliates in a phishing campaign targeting YouTube creators with cookie stealing malware to hijack their accounts and stream cryptocurrency scams.
Phishing emails were sent to DoD vendors to capture login credentials on lookalike vendor payment website. The hackers then routed payments to shell entity.
MetaMask, a popular crypto wallet app, has a default setting, apparently unbeknownst to many users, that automatically writes the recovery seed phrase for the wallet to the user's iCloud backups.
US government employees will soon be required to use a stronger measure of multi-factor authentication to access their work accounts. Aimed at putting an end to phishing, the measure is phasing out less secure forms of authentication.
PHP open-source team averted a potential supply chain attack after hackers compromised their self-managed Git server and inserted malicious code in PHP’s “under development” version.










