Once popular for attacking AI, ASCII smuggling is embraced by spammers
A previously overlooked block of invisible Unicode characters is becoming increasingly widely used, drawing more attention as its applications expand.
Everything tagged phishing, newest first. Tags come from the classifier reading each item's summary; 394 tags used 25 times or more have their own page.
A previously overlooked block of invisible Unicode characters is becoming increasingly widely used, drawing more attention as its applications expand.
A hacker impersonated a cryptocurrency news website employee to target cybersecurity experts with malware via Google Docs.
A vulnerability involving a secret parameter enabled hackers to steal passwords from victims who clicked on a malicious link.
A passenger on a flight from Las Vegas to Atlanta, following the DEF CON cybersecurity conference, allegedly created a scam Wi-Fi network, leading to the temporary shutdown of the plane's Wi-Fi by Delta's crew, amidst conflicting reports about federal involvement and the exact nature of the incident.
The FBI warns of a new phishing-as-a-service platform, Cali 365, which exploits Microsoft 365 access tokens to bypass multi-factor authentication, with cybercriminals using Telegram to distribute phishing campaigns and obtain user credentials via device code phishing.
Organizations using AI and automation saved $2 million and 65 recovery days on data breaches, with phishing remaining the top cause, but passkeys offer a promising solution.
The 2026 Cost of a Data Breach report highlights the revolutionary impact of AI models like Anthropic Mythos in identifying cybersecurity vulnerabilities, emphasizing the urgent need for organizations to improve defenses as attack timelines shorten and costs of breaches increase rapidly.
Hackers focus on exploiting human psychology and system weaknesses, using techniques like social engineering and phishing to gain access, rather than relying solely on technical skills.
In 2026, AI enables hackers to create highly realistic and personalized phishing attacks, making cybersecurity threats more dangerous as fake emails, job offers, and websites become indistinguishable from legitimate ones.
A security breach at a major travel company potentially exposed customers' personal information, including names, emails, addresses, and phone numbers.
The dark web, a hidden part of the internet accessed via special tools, can contain both illicit and legitimate activities, with personal information often appearing there due to phishing attacks leading to data breaches.
The podcast discusses the security implications of AI's internal monologue, highlighting how it can be exploited for phishing attacks, and emphasizes the need for better training and guardrails for AI systems to prevent widespread vulnerabilities.
A scam involving fake Shopify orders sent push notifications to iPhones, tricking users into calling a scam number embedded in the order details.
Scammers exploiting Microsoft's reputable name can make fraudulent activities more difficult to detect, increasing the risk of successful deception.
AI has transformed the cyber threat landscape by enabling faster, more scalable, and polished attacks, necessitating enhanced training for defenders to effectively counteract these threats.
After enduring over 63,000 attacks in twelve days, this guest post offers actionable steps to enhance network security.
In 2026, new scams and variations of old ones are emerging, targeting individuals and specific professions through phishing texts, scam emails, fake calendar invites, and deceptive packages, emphasizing the need for awareness and caution.
Pass keys, using public key cryptography, aim to replace traditional passwords by providing a more secure and phishing-resistant authentication method, though they face challenges in cross-device usage and public understanding.
Scammers exploit Apple's support system to deceive users into granting account access by creating fake support cases and sending real Apple emails, all while impersonating Apple support representatives.
Hackers exploit Gmail accounts by altering users' ages to gain control, posing a significant threat that could escalate with potential regulatory implications.
Cloud-based workspaces like Google Workspace are crucial for organizations but face security threats, and Material Security provides enhanced protection against these vulnerabilities.
The Draco team, an elite yet secretive cyber crime-fighting group within Bitdefender in Romania, has saved victims over a billion dollars by dismantling criminal empires, using advanced AI to combat cyber threats, while maintaining anonymity due to the dangerous nature of their work.
Email scams are increasingly sophisticated, using personalized tactics and AI manipulation to deceive users, requiring heightened vigilance and direct website navigation to avoid phishing traps.
Google has alleged that "Phishing for dummies" kits are simplifying the process for scammers to deceive millions of people.
Smishers are innovating in their search for new infrastructure to enhance their phishing schemes, adapting to technological advancements and security measures.
The podcast episode discusses the evolution of AI and cybersecurity threats, including deep fakes, ransomware, phishing, and identity scams, while exploring the ongoing activities of threat groups like Scattered Lapsis Hunters and analyzing major threats to critical infrastructure.
A massive supply chain attack on npm compromised popular JavaScript packages, targeting cryptocurrency transactions, but was quickly neutralized, highlighting the need for stronger security measures.
Activists Saber and Cyborg compromised a North Korean hacker's computer, revealing espionage operations, cybercrime activities, and sensitive data targeting South Korea, all published in a report and available for download.
Organizations are struggling to prevent phishing attacks, prompting a shift towards implementing stronger security measures and technologies to protect against these threats.
Recent claims suggesting that phishing techniques can bypass FIDO security measures are inaccurate, as FIDO remains robust against such attacks.
A security breach in McDonald's hiring platform, Mukhire, exposed personal data of 64 million applicants due to a simple password vulnerability, highlighting significant risks and ineffective security measures.
The Sinaloa cartel hired a hacker to surveil an FBI agent using spyware and Mexico City's camera system, while Russian hackers employed sophisticated phishing tactics to target a British expert, highlighting the growing intersection of crime and cyber espionage.
QR codes, while convenient, pose security risks through "quishing" attacks that can lead to malware infections and data theft, necessitating cautious use and awareness.
Duo announces its new Identity and Access Management (IAM) solution, Duo IAM, which offers security by default, passwordless authentication, and strong multifactor authentication without additional costs, addressing the evolving threats of credential theft and phishing.
A sophisticated phishing scam exploits Google's email system and DKIM Replay to send seemingly legitimate emails from Google, tricking users into providing sensitive information through a fake login page hosted on sites.google.com.
The video explores five methods used by hackers to compromise passwords—guessing, harvesting, cracking, spraying, and stuffing—while providing tips to protect against these attacks.
The IBM X-Force Threat Intelligence Index Report reveals a decline in ransomware and phishing attacks, but highlights rising credential theft and infostealer threats, emphasizing the need for robust cybersecurity measures.
Phishing, the second leading cause and cost of data breaches, exploits human trust through social engineering to steal credentials via various attack methods like email, SMS, voice calls, and QR codes.
In 2025, scammers are using new variations of scams like unpaid tolls, PayPal phishing, Windows Run Command, and "I Accidentally Reported You" scams, which can be avoided by being informed.
An overlooked attack method has been exploited since last August, leading to numerous account takeovers.
Hackers exploit Google's ad policies to create phishing scams, while a pastor defrauds his congregation with a fraudulent crypto scheme, highlighting vulnerabilities in online security and the gullibility of individuals.
Several Chrome extensions, including featured ones, were found to contain malicious code after hackers hijacked developer accounts, leading to potential data theft and necessitating user action to uninstall and change passwords.
Cybersecurity trends for 2025 include increased adoption of pass keys, AI-enhanced phishing, deepfake scams, and ongoing challenges with generative AI's accuracy.
Cybersecurity in space involves autonomous systems like Bit Defender's Gravity Zone protecting devices on the International Space Station without real-time updates or physical repairs.
Zimperium's experts forecast a focus on data privacy, increased evasive phishing attacks, and rising sideloading threats for 2025.
Phishing attacks have become increasingly sophisticated, successfully deceiving even highly experienced professionals in the industry.
Operation Synergia II targeted cybercriminal activities, specifically focusing on combating phishing, ransomware, and information-stealing threats.
The X-Force Cloud Threat Landscape report highlights key security risks in cloud environments, emphasizing phishing and vulnerabilities like cross-site scripting.
Experts discuss AI's impact on cybersecurity, ethical considerations, and future challenges, with varying opinions on phishing's evolution by 2027.
Email accounts within five US companies were unlawfully accessed via unauthorized password reset methods.