Google has moved to bolster detection and disruption of the Cobalt Strike red teaming tool that has since evolved into a remote access tool deployment system through the release of a VirusTotal collection and YARA rules, SecurityWeek reports.
BleepingComputer reports that threat actors have leveraged TeamViewer and fake support chats in a new cryptocurrency stealing phishing campaign that evades multi-factor authentication to compromise Coinbase, Crypto.com, MetaMask, and KuCoin accounts.
A new survey of security professionals around the globe finds that the vast of majority of respondents say they are concerned their organization will successfully be attacked in the next year.
Ten state attorneys general are asking Apple to address data privacy gaps in the wake of the U.S. Supreme Court abortion ruling by enacting stricter app standards and an auditing program.
Countries in the Middle East experienced a twofold increase in email-based phishing attacks last month prior to the kickoff of the World Cup in Qatar, with many of the emails spoofing the FIFA help desk and ticketing office, as well as team departments and managers, reports The Record, a news site by cybersecurity firm Recorded Future.
Unit 42 researchers said the campaign is expanding in scope and will continue to escalate because of the low per-target cost, low risk of detection, and fast monetization.
North Americans shopping online are being subjected to a new sophisticated phishing kit with detection aversion techniques that leverages holiday-focused lures since September, BleepingComputer reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.