Understanding Rockstar 2FA and the Evolution of Phishing-as-a-Service
The fight to protect digital systems from cyber criminals grows more challenging every day, especially with the rise of sophisticated tools like the recently discovered Rockstar 2FA phishing-as-a-service kit. Featured in a recent article from Forbes, this latest exploit is causing waves due to its ability to bypass two-factor authentication ... Read More
End-of-Year PTO: Days Off and Data Exfiltration with Formbook
The holiday season is a time of joy and relaxation, but it often brings an influx of corporate emails ranging from leave approvals to scheduling paid time off. The Cofense Phishing Defense Center (PDC) has recently intercepted a malicious phishing email masquerading as a legitimate end-of-year leave approval notice. Disguised ... Read More
End-of-Year PTO: Days Off and Data Exfiltration with Formbook
The holiday season is a time of joy and relaxation, but it often brings an influx of corporate emails ranging from leave approvals to scheduling paid time off. The Cofense Phishing Defense Center (PDC) has recently intercepted a malicious phishing email masquerading as a legitimate end-of-year leave approval notice. Disguised ... Read More
Wolves in Sheep’s Clothing: Industry-Specific Targeted Phishing Attacks
Subject customization using either the recipient’s name, email address, phone number, or company name is a common tactic used in phishing emails to deceive recipients. Threat actors often include the company name or designated recipient’s personal information to disguise the true intent of the email. Our analysis shows that certain ... Read More
Missing URL Structure: Mistake or a Masterfully Effective Tactic?
In an ever-changing threat landscape, where AI and automation are being leveraged to not only detect but stop malicious campaigns, how does an attack that seems rudimentary become effective? By understanding how these tools work and by using social engineering, TAs (Threat Actors) can circumvent automation and gain access to ... Read More
Cofense and Security Matterz Announce Strategic Partnership to Enhance Email and Phishing Protection across the Kingdom of Saudi Arabia & wider Middle East region.
We’re thrilled to announce that Security Matterz has appointed Cofense as their strategic partner for email security. This collaboration marks the culmination of three years of in-depth discussions and will see Security Matterz integrating Cofense's cutting-edge solutions into their product portfolio to expand and enhance their email security offering across ... Read More
Containers Full of Secrets: Archive Files Bypassing SEGs
Modern enterprise environments make use of multiple tools such as Secure Email Gateways (SEGs) and Endpoint Detection and Response (EDR) solutions to prevent malware from getting onto a user’s device. However, many of these protection measures have flaws that threat actors often take advantage of. One of the easiest ways ... Read More
Phish Swimming in the OpenSea: The OpenSea Phishing Threat
OpenSea is a well-known NFT (non-fungible token) platform and is the go-to platform for many entry-level NFT enthusiasts looking to enter the crypto collectible market. However, what if OpenSea itself could be exploited to gain access to new user crypto wallets who are likely unaware of TA (Threat Actor) phishing ... Read More
The Dangerous Blend of Phishing for Government IDs and Facial Recognition Video
In an era where online convenience has become the norm, the risk of identity theft through scam websites has surged. The potential for exploitation grows as more services transition to conducting business online. These sites pose a significant risk to personal security and undermine public trust in the digital infrastructure ... Read More
Cofense Quarterly Trends Report Reveals Evolving Threats in Email Security
LEESBURG, Va., November 19, 2024 -- Cofense, the pioneer and leading provider of email security awareness training (SAT) and advanced phishing detection and response (PDR) solutions, today announced the release of its Q3 2024 Phishing Intelligence Trends Review curated from the Cofense Phishing Defense Center. The report shows that Cofense detected ... Read More

