The campaign begins with emails impersonating eLibrary, a Russian scientific electronic library, using a domain registered six months prior to avoid detection.
BleepingComputer reports that legitimate PayPal emails with fraudulent purchase notifications have been sent by exploiting the fintech platform's "Subscriptions" billing functionality as part of a new email scam.
Email attack techniques are evolving quickly, and traditional secure gateways can't keep up. Context-aware, AI-powered email monitoring may be the solution.
The Hacker News reports that multiple new tactics have been employed by the advanced persistent threat operation ToddyCat to compromise corporate Outlook emails and Microsoft 365 access tokens.
Microsoft Entra B2B tenant invitations have been exploited by threat actors to facilitate a new Telephone-Oriented Attack Delivery phishing campaign, according to Cybernews.