Russian state-sponsored hacking group APT29, also known as Cozy Bear or Nobelium, has launched spear-phishing campaigns aimed at government and diplomatic organizations in the Americas, Europe, and Asia since January, The Hacker News reports.
Emotet malware operators have restarted their newly-launched phishing campaign after fixing a vulnerability that prevented infections when malicious email attachments were opened, BleepingComputer reports.
Proofpoint researchers say the Emotet botnet's use of low volume attacks via Microsoft OneDrive URLs may be the first round of larger campaigns to come.
The Hacker News reports that SonarSource has identified a high-severity vulnerability in the open-source RainLoop web-based email client which could be leveraged for email exfiltration.