Tag

Phishing

All articles tagged with #phishing

Health systems warn patients about MyChart-brand phishing emails
health-it16 hours ago

Health systems warn patients about MyChart-brand phishing emails

More than a dozen health systems warn patients about phishing emails that impersonate Epic's MyChart portal to steal personal data; the scammers are abusing the MyChart brand rather than indicating a security breach, and Epic urges patients to verify senders, avoid unknown links, and know that MyChart will never ask for account changes or sensitive information via email.

UK PM Burnham contacted by impersonator posing as Trump's aide
world8 days ago

UK PM Burnham contacted by impersonator posing as Trump's aide

Britain’s Prime Minister Andy Burnham exchanged messages with someone who pretended to be Susie Wiles, a close adviser to Donald Trump. Burnham became suspicious and alerted authorities; Politico first reported the incident, and the British embassy in Washington raised it with the White House. Downing Street did not comment on national security. The article notes ongoing phishing attempts linked to Wiles dating back to a 2025 incident.

Azure Credential Breach Leaks Millions of Enterprise Directory Records
security8 days ago

Azure Credential Breach Leaks Millions of Enterprise Directory Records

A threat actor named TheHatman is selling massive Azure/Entra tenant dumps containing employee records from multiple major companies, including McDonald’s (~1.7M) and Vodafone (~425k), exfiltrated via compromised credentials. The data fields cover names, corporate emails, phone numbers, addresses, job titles, departments, and privileged accounts, enabling targeted BEC and privilege escalation. While the exact intrusion vector isn’t confirmed, researchers link the leaks to Infostealer infections and credential abuse rather than a Azure zero-day. Defenders should monitor for credential exposure, enforce MFA, and review third-party access to Azure directories to mitigate risk.}

Most Android Users Don’t Need Antivirus Apps, Here’s Why
technology9 days ago

Most Android Users Don’t Need Antivirus Apps, Here’s Why

For the vast majority of users, Android’s built‑in protections (Google Play Protect, app sandboxing, regular OS updates, and prudent permission controls) provide solid defense against malware and risky apps, making third‑party antivirus apps largely unnecessary. An antivirus may offer peace of mind for high‑risk users or those who sideload apps, but choose a reputable developer and don’t rely on it alone. Real threats often come from social engineering, fake alerts, insecure public Wi‑Fi, and other attack vectors that antivirus can’t fix; safe habits and, when relevant, a VPN are typically more effective. Older devices without updates may still benefit from additional protection, but updates remain the best defense overall.

DEF CON attendees linked to rogue onboard Wi‑Fi phishing on Delta flight
security14 days ago

DEF CON attendees linked to rogue onboard Wi‑Fi phishing on Delta flight

DEF CON attendees are suspected after Delta Flight 591 (Las Vegas–Atlanta) reportedly encountered a rogue onboard Wi‑Fi network, named “Delta WiFi Fast,” with a phishing landing page designed to harvest credentials. Delta said the unauthorized network was present briefly and that the official onboard Wi‑Fi was offline for about 30 minutes; flight safety was not compromised. The FBI’s Atlanta office is investigating, with no arrests announced at this time.

Valve warns Steam hardware buyers' data compromised in CEVA logistics breach
technology15 days ago

Valve warns Steam hardware buyers' data compromised in CEVA logistics breach

Valve has informed European Steam hardware buyers that their personal data may have been exposed in a cyberattack on CEVA Logistics, which handles Steam Deck, Steam Machine, and Steam Controller deliveries. The breach occurred July 29–August 1 and was reported August 7; affected data include names, street addresses, postal codes, cities, countries, phone numbers, email addresses tied to Steam accounts, and the type and price of the ordered hardware, while payment data, passwords, and Steam Guard codes were not affected. CEVA said the intrusion affected part of its European operation and several warehouses, with Valve notifying data protection authorities. Customers are warned to expect phishing attempts referencing orders, and Steam Support will never request passwords. The exact number of affected customers has not been disclosed.

AI Turbocharges Cyberattacks, Forces a New Era for Defense
technology17 days ago

AI Turbocharges Cyberattacks, Forces a New Era for Defense

AI is dramatically reshaping cybersecurity by acting as a force multiplier for attackers—enabling fast, scalable phishing, credential theft, voice cloning and prompt-injection across multiple models—while defenders deploy AI-powered defenses. The landscape is highly asymmetric, with attackers able to outpace patching and discover zero-days more quickly, all amid evolving defense strategies from major players like Microsoft, as the future remains uncertain.

ClickFix macOS malware drains crypto wallets and steals credentials
technology18 days ago

ClickFix macOS malware drains crypto wallets and steals credentials

A Go-based malware delivered through ClickFix phishing emails targets macOS users to steal cryptocurrency assets, browser passwords, and Apple Keychain data, and can intercept or redirect crypto transactions. It uses a Bash profiler and loader to load a Mach-O payload, hides itself by copying as com.apple.verified and removing quarantine attributes, and establishes persistence via fake prompts to grab credentials. The malware can modify transactions before signing, potentially draining only a percentage of funds across assets like Bitcoin, Ethereum, XRP, Monero, Litecoin, and Dogecoin. C2 traffic points to Aeza Group infrastructure (AS 210644), a sanctioned bulletproof-hosting provider.

Wall Street ransom plot relies on simple phone scams
technology18 days ago

Wall Street ransom plot relies on simple phone scams

Hackers are using basic social-engineering to trick employees at major Wall Street firms into revealing passwords and MFA codes by spoofing internal IT helpdesk numbers and directing staff to fake passkey websites. The campaign targeted over 200 companies in about five weeks, including Blackstone, KKR, Apollo Global Management, Bain Capital, CME Group and others; some victims reportedly paid ransoms while many intrusions were blocked. The attackers use voice calls and booby-trapped sites to harvest credentials and hijack accounts in real time, illustrating a persistent human-factor vulnerability despite high-tech defenses.

Public Wi‑Fi Risks Escalate as Captive Portal Attacks Target Travelers
privacy19 days ago

Public Wi‑Fi Risks Escalate as Captive Portal Attacks Target Travelers

Microsoft Threat Intelligence warns of the CaptiveCrunch campaign that targets hospitality wifi networks (hotels, airports, conference centers) by abusing captive portal prompts to phish credentials, push malware, and perform man-in-the-middle attacks. Travelers are urged to rely on private connections (mobile hotspots or cellular data), use an enterprise-managed travel router or VPN with a kill switch if public wifi must be used, carefully inspect login prompts, avoid downloading software through captive portals, and keep devices and apps up to date to minimize risk.

CaptiveCrunch Hijacks Hotel Wi‑Fi with Fake Updates, Microsoft Warns
technology20 days ago

CaptiveCrunch Hijacks Hotel Wi‑Fi with Fake Updates, Microsoft Warns

Microsoft warns of a campaign called CaptiveCrunch that compromised hotel Wi‑Fi networks, using fake login and update pop-ups to steal credentials, keystrokes, and even remotely hijack devices, with alleged ties to Russia. To stay safe, travelers should use a private connection (like a mobile hotspot) or be wary of unexpected prompts after connecting to hotel Wi‑Fi.

technology21 days ago

AI-powered phishing scams: seven schemes you need to know

AI-generated phishing emails are becoming almost indistinguishable from legitimate messages, and attackers use new tricks like OAuth device code flows to bypass MFA and QR codes to hide links. The piece outlines seven current scams—Microsoft 365 login theft, support scams, fake Defender warnings, cloud/OneDrive phishing, parcel-delivery impersonations, online-banking fraud, and Postident fraud by post—and provides practical defenses: verify via official sites, enable MFA, use a password manager, avoid clicking links or scanning unknown QR codes, and resist unsolicited remote-support requests.

Hotels’ Wi‑Fi Gateways Become Phishing Vectors for Microsoft 365 Logins
technology23 days ago

Hotels’ Wi‑Fi Gateways Become Phishing Vectors for Microsoft 365 Logins

Hackers are hijacking hotel and conference Wi‑Fi gateways to redirect business travelers to fake Microsoft 365 sign‑in pages, potentially bypassing MFA via deceptive device prompts and WPAD abuse. Active since at least June, the campaign alters DNS to serve phishing domains (e.g., m365-owa.com, ms365-live.com) and can affect many industries; defenses include using a full‑tunnel VPN, a mobile hotspot, verifying login URLs, avoiding unexpected prompts, updating devices, and having IT disable WPAD where possible.