Callback phishing attacks, or hybridized voice phishing that also includes pre-call emails, have increased by 625% between the first quarter of 2021 and second quarter of 2022 even though overall phishing volumes only rose by 6% during the same period, indicating hackers' evolving techniques in phishing, reports BleepingComputer.
Twilio, a major provider of cloud communications services, uncovered a security breach last week that affected 125 of its customers, whose data was briefly accessed by malicious actors, BleepingComputer reported.
An ongoing phishing campaign is targeting the healthcare sector with malspam emails that appear as legitimate Evernote sites, in an attempt to harvest credentials.
More than $86 million in NFT value has been stolen since 2020, according to Comparitech researchers, who have been tracking NFT thefts for more than two years.
The Hacker News reports that Quantum, Silent Ransom, and Roy/Zeo, three autonomous threat groups that split from the Conti cybercrime cartel, have created and adopted their own targeted call back phishing tactic called BazaCall as initial vector to access and breach targeted network, according to a report from cybersecurity firm Advintel.
Cryptocurrency platform users are being targeted by a massive phishing operation exploiting Microsoft Azure Web and Google Sites, according to BleepingComputer.
An HP Wolf Security Threat Insights Report found that 14% of email-related malware discovered in companies’ systems had slipped past at least one email gateway security scan in the second quarter of 2022.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.