Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.
email
DarkMe RAT trades zero-days for plain phishing emails

DarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has …

Phishing
Fake Claude Max giveaway tricks users into handing over their Google account credentials

A fake Claude Max giveaway uses a spoofed Google sign-in window to steal users’ login credentials, Malwarebytes researchers have found. …

phishing
Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes

The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and …

ChatGPT phishing
A fake ChatGPT billing email is after your OpenAI password

A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing …

phishing awareness
Companies may be measuring phishing resilience the wrong way

Companies that judge phishing simulation programs by how often employees click simulated attack emails may be overlooking more important indicators of cyber resilience, …

social engineering
Attackers call employees’ personal phones to break into Microsoft 365 accounts

Attackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into handing over access to …

phishing
Cybercriminals are building phishing pages that exist only inside victims’ browsers

A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, …

Trezor
Trezor customers hit with phishing calls and letters after shipping-partner breach

Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone …

Microsoft 365 phishing
IT help-desk vishing tricks executives into handing over Microsoft 365 access

IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and …

Microsoft Teams
Microsoft Teams is about to make QR code phishing much harder

Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the …

Phishing
Attackers are going after prominent individuals through OAuth phishing, FBI warns

Attackers are targeting prominent individuals, their relatives and personal contacts to gain persistent access to their accounts, including private emails and files, the FBI …

Phishing
Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks

A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools