US Post Office Phishing Sites Get as Much Traffic as the Real One

Security researchers analyzing phishing campaigns that target United States Postal Service (USPS) saw that the traffic to the fake domains is typically similar to what the legitimate site records and it is even higher during holidays.

Cyware News – Latest Cyber News – ​Read More

Analysis of Native Process CLR Hosting Used by AgentTesla

The initial infection vector is a Word document that downloads and executes a 64-bit Rust-compiled binary. This binary then downloads an encoded shellcode containing the AgentTesla payload.

Cyware News – Latest Cyber News – ​Read More

Japanese police create fake support scam payment cards to warn victims

The cards are labeled “Virus Trojan Horse Removal Payment Card” and “Unpaid Bill Late Fee Payment Card,” and were created by the Echizen Police in the Fukui prefecture in Japan as an alert mechanism.

Cyware News – Latest Cyber News – ​Read More

Hackers Claim to Have Infiltrated Belarus’ Main Security Service

A Belarusian hacker activist group claims to have infiltrated the network of the country’s main KGB security agency and accessed personnel files of over 8,600 employees.

The post Hackers Claim to Have Infiltrated Belarus’ Main Security Service appeared first on SecurityWeek.

SecurityWeek – ​Read More

Okta Warns of Unprecedented Surge in Proxy-Driven Credential Stuffing Attacks

Identity and access management (IAM) services provider Okta has warned of a spike in the “frequency and scale” of credential stuffing attacks aimed at online services.
These unprecedented attacks, observed over the last month, are said to be facilitated by “the broad availability of residential proxy services, lists of previously stolen credentials (‘combo lists’), and scripting tools,” the

The Hacker News – ​Read More

9 Best Password Managers (2024): Features, Pricing, and Tips

Keep your logins locked down with our favorite password management apps for PC, Mac, Android, iPhone, and web browsers.

Security Latest – ​Read More

Ukraine Targeted in Cyberattack Exploiting 7-Year-Old Microsoft Office Flaw

Cybersecurity researchers have discovered a targeted operation against Ukraine that has been found leveraging a nearly seven-year-old flaw in Microsoft Office to deliver Cobalt Strike on compromised systems.
The attack chain, which took place at the end of 2023 according to Deep Instinct, employs a PowerPoint slideshow file (“signal-2023-12-20-160512.ppsx”) as the starting point, with

The Hacker News – ​Read More

School Employee Allegedly Framed a Principal With Racist Deepfake Rant

Plus: Google holds off on killing cookies, Samourai Wallet founders get arrested, and GM stops driver surveillance program.

Security Latest – ​Read More

Russia Vetoed a UN Resolution to Ban Space Nukes

A ban on weapons of mass destruction in orbit has stood since 1967. Russia apparently has other ideas.

Security Latest – ​Read More

FBI: Fraudsters Using Fake Online Dating Verification Apps to Scam Lovers

The FBI published a warning on Friday about the scam, noting that it was akin to an offshoot of romance scams and pig butchering schemes that have proliferated in recent years.

Cyware News – Latest Cyber News – ​Read More