2024-10-30 05:44 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Explore our latest findings on the surge of cyberattacks in the Balkan region, focusing on threats to financial institutions and critical infrastructure. Discover how phishing scams impersonating postal services are targeting citizens in Croatia, Romania, Serbia, and Slovenia, and learn about the implications for public safety and security. Stay informed and protected against the rising tide of cybercrime.
P0
2024-10-09 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in GitLab Pages allowed attackers to take over dangling custom domains pointing to 'instanceX.gitlab.io'. The issue occured when adding an unverified custom domain to GitLab Pages, which serves content for 7 days before disabling. This could lead to cookie stealing, phishing campaigns, and bypassing of Content-Security Policies and CORS.
P0
2024-10-08 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how to prevent business email compromise attacks and learn how to communicate this emerging cyber threat to your employees.
P0
2024-10-02 05:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
In this article, Group-IB specialists uncovered a large-scale fraud campaign involving fake trading apps targeting Apple iOS and Android users across multiple regions through the UniApp framework, and distributed through official app stores and phishing sites.
P0
2024-09-03 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Join Huntress team members as they walk through some of the most malicious phishing techniques, presented from the attacker's perspective.
P0
2024-08-21 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover how our new Unwanted Access capability strengthens your defenses against session hijacking and credential theft. Dive in and learn how to minimize risks and protect your business-critical assets from evolving cyber threats.
P0
2024-07-25 05:58 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Specializing in AI-powered phishing-as-a-service and Android malware capable of intercepting OTP codes, the GXC Team targets Spanish bank users and 30 institutions worldwide
P0
2024-06-12 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Get to know Phishing Defense Coaching, the latest addition to Huntress SAT. This personalized feature helps teach learners how phishing simulations tricked them so they can better identify potential threats.
P0
2024-04-18 11:09 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB takes part in a global operation to cripple Canadian Phishing-as-a-Service provider LabHost
P0
2023-12-23 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Read about our newest addition to Huntress Managed SAT, Managed Phishing, offering you expert-backed, hassle-free simulated phishing campaigns.
P0
2023-10-18 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore the art of phishing, learn how to spot common phishing scams and red flags, and understand the importance of security awareness training.
P0
2023-10-16 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Read up on how and why Huntress built its Managed ITDR (formerly MDR for Microsoft 365) solution to help combat the growing threat of business email compromise (BEC).
P0
2023-08-17 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Get an inside look at how threat actors use phishing and social engineering tactics to target users and infiltrate organizations.
P0
2023-08-09 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover how Huntress caught an attempted business email compromise (BEC) scam that would have cost the company more than $100,000 had it gone undetected.
P0
2023-07-27 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore how Huntress stopped a massive business email compromise (BEC) attack targeting multiple user accounts within a single organization.
P0
2023-07-13 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, explore how Huntress caught an attempt at financial fraud through business email compromise (BEC) in Microsoft 365.
P0
2023-07-06 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Can we use anomalous user agents to detect potential business email compromise (BEC) in Microsoft 365? Explore what we found through threat hunting for BEC.
P0
2023-06-27 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover how Huntress Managed Identity Threat Detection and Response identified three business email compromise (BEC) attacks within 72 hours of each other.
P0
2023-04-25 04:19 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB Digital Risk Protection discovers more than 3,200 fake Facebook profiles in ongoing phishing campaign that sees scammers impersonate Meta support staff
P0
2023-04-21 03:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
How to investigate phishing campaigns
P0
2023-04-21 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Google users can find and install third-party OAuth applications from Google Marketplace that are integrated with Google Workspace. Each OAuth application client in Google is associated with a GCP project. A bug in the way a GCP project enters a "pending deletion" state when deleted, could have allowed threat actors to make a malicious application invisible and unremovable from the user's account. If an attacker had managed to install an application in an account (e.g., through a phishing attac…
P0
2023-01-13 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Several vulnerabilities were present in how Google Cloud Shell (ssh.cloud.google.com) handled OAuth credentials. These included an open-redirect vulnerability, where attackers could redirect users to malicious sites to capture their credentials, and a validation bypass that allowed tokens to be submitted to user-defined URIs, circumventing normal security checks. Additionally, Google Cloud Workstations did not correctly tie the state parameter to the session that generated it, which allowed val…
P0
2022-08-25 09:02 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Over 130 organizations have been compromised in a sophisticated attack using simple phishing kits
P0
2022-08-09 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
This blog explores phishing and smishing, diving into how to analyze text messages for their validity and legitimacy.
P0
2022-06-09 15:53 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB identifies massive campaign capable of targeting clients of major Vietnamese banks
P0
2021-12-28 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability was discovered in Cloud Shell that enabled command injection and remote shell access. The "Open in Cloud Shell" functionality allowed a user to provide values for both the "git_repo" and "go_get_repo" parameters, which would clone the target repo in the user's environment. While "git_repo" was validated against a list of trusted repos, "go_get_repo" was not. Therefore, an attacker could have supplied a trusted repository as "git_repo" and an arbitrary command in the "go_get_repo…
P0
2021-10-28 14:19 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB uncovers largest networks of fake shops – phishing websites disguised as card shops
P0
2021-09-16 14:26 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Phishers take an approach to bypass security controls never seen in the country
P0
2021-07-14 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Cybersecurity experts John Hammond and Sébastien Goutal provide insider insight on the current state of phishing, ransomware and email-based attacks.
P15
2021-06-03 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this testimonial, learn firsthand from one of our Security Awareness Consultants at Curricula about how a fake IRS phishing scam worked on one student.
P0