ClickFix Campaign Spoofs Booking.com for Malware Delivery

ClickFix Campaign Spoofs Booking.com for Malware Delivery

Cofense Intelligence has identified a rise in Booking.com-spoofing phishing attacks using fake CAPTCHAs to deliver malicious scripts disguised as verification codes. These campaigns surged in March 2025, with 75% spoofing Booking.com templates ... Read More
Behind the Script: Unmasking Phishing Attacks Using Google Apps Script

Behind the Script: Unmasking Phishing Attacks Using Google Apps Script

| | cybersecurity trends
A recent campaign identified by the Cofense PDC disguises phishing emails as invoices, linking to a Google Apps Script-hosted page to appear legitimate. This tactic exploits Google's trusted environment, making it easier to deceive recipients into sharing sensitive information ... Read More
Fake Course, Real Threat: Learning a Phishing Lesson the Hard Way

Fake Course, Real Threat: Learning a Phishing Lesson the Hard Way

| | cybersecurity trends
The Cofense PDC recently identified a phishing campaign that lures victims with a fake online course invitation. It initially spoofs the Coursera platform but ultimately redirects users to a counterfeit Meta login page to steal credentials ... Read More
New Weapon of Choice - How Threat Actors Hijack Legitimate Remote Access Tools

New Weapon of Choice – How Threat Actors Hijack Legitimate Remote Access Tools

New Weapon of Choice - How Threat Actors Hijack Legitimate Remote Access Tools ... Read More
Phishing in the Multiverse: Analyzing a Malicious Email Targeting Apple and Yahoo Users

Phishing in the Multiverse: Analyzing a Malicious Email Targeting Apple and Yahoo Users

| | cybersecurity trends
Apple Pay is a mobile payment and digital wallet service that allows users to make payments using their Apple devices. Digital wallets are now widely embraced, and Apple Pay is considered one of the most trusted and secure platforms ... Read More
Using Blob URLs to Bypass SEGs and Evade Analysis

Using Blob URLs to Bypass SEGs and Evade Analysis

Starting in mid-2022, Cofense Intelligence detected a new technique for successfully delivering a credential phishing page to a user’s inbox: blob URIs (Uniform Resource Identifier).  ... Read More
Spain and Portugal Power Outages Spark a Surge in Phishing Attacks

Spain and Portugal Power Outages Spark a Surge in Phishing Attacks

Spain & Portugal Power Outages Spark a Surge in Phishing Attacks ... Read More

Global Manufacturing Leader Strengthens Email Security

| | Case Studies
Global Manufacturing Leader Strengthens Email Security ... Read More

Protecting Your Business from Vishing Threats

| | Industry Best Practices
Vishing, or "voice phishing," continues to be a silent yet formidable cyber threat for businesses of all sizes. While traditional phishing and smishing (SMS phishing) are widely recognized, vishing often flies under the radar, leaving organizations vulnerable to devastating attacks.  ... Read More
Custom-Crafted, Qantas-Spoofing Emails Target Australian Victims

Custom-Crafted, Qantas-Spoofing Emails Target Australian Victims

Custom-Crafted, Qantas-Spoofing Emails Target Australian Victims ... Read More