Cloud Services Abused by Clever Phishing Campaign

Cloud Services Abused by Clever Phishing Campaign

Security researchers detected a clever new phishing campaign that abused three enterprise cloud services in an attempt to steal victims’ credentials. On July 18, Bleeping Computer revealed that the phishing campaign’s attack ...

Business Email Compromise (BEC) Criminal Ring

A criminal group called Cosmic Lynx seems to be based in Russia: Dubbed Cosmic Lynx, the group has carried out more than 200 BEC campaigns since July 2019, according to researchers from ...
Nigerian National Extradited to United States on BEC Scam Charges

Nigerian National Extradited to United States on BEC Scam Charges

A Nigerian national entered into the custody of the FBI to face charges of having targeted several U.S. companies with business email compromise (BEC) scams. On July 3, the U.S. Attorney’s Office ...
employees

Employees’ Reasons for Not Using Secure Communications

How heavily do you invest in cybersecurity? How much of that is in your communications infrastructure? Regulations and compliance requirements, customer or client demand and simply maintaining your business’s reputation all contribute ...
Security Boulevard
Assessing an Email’s Legitimacy

Assessing an Email’s Legitimacy

| | email, Phishing, security
I recently received an email sporting “Wells Fargo” logos. It asked me to do a survey. It was actually sent from the domain ‘morpace.com,’ which used to belong to a product survey ...
Beware of Phone Phishing

Beware of Phone Phishing

Just because the email (or letter) directs you to a phone number doesn’t mean you aren’t being phished. The nearby image shows part of a recent phishing email. It claims that I ...
New Trickbot Campaign Uses Fake Emails from U.S. Department of Labor

New Trickbot Campaign Uses Fake Emails from U.S. Department of Labor

A new campaign is targeting people with messages that seem to come from the U.S. Department of Labor (DoL), trying to trick them into opening a DOC file, enabling macros, and eventually ...
Digital Fraudsters Masquerading as FINRA in Phishing Emails

Digital Fraudsters Masquerading as FINRA in Phishing Emails

The Financial Industry Regulatory Authority (FINRA) warned that digital fraudsters are impersonating it in an ongoing phishing email campaign. In a regulatory notice published on its website, FINRA revealed that malicious actors ...
Zerologon

COVID Email Attack or Email Harvesting?

The well-publicized publishing of 25,000+ emails and passwords allegedly associated with the World Health Organization, the Gates Foundation and the National Institutes of Health has captured the attention of both infosec practitioner ...
Security Boulevard

Detecting a Phish on an iPhone

| | Apple, email, iPhone, Phishing, security
In their obsession with simplifying the phone interface, the iPhone designers make it a bit harder to detect dangerous emails. Here is an email claiming to be from “Humana Health” asking me ...