The threat group APT28/Fancy Bear has is now using a little used technique in Microsoft Office that enables it to executive arbitrary code using a Word document, but without requiring macros being enabled.
An attack campaign targeting Android users in Austria has been employing a unique trio of techniques to steal their funds: a credentials phishing web page, malicious banking app overlays, and credit card phishing screens.
Asian entertainment website Crunchyroll.com is blaming a DNS hijack attack, after site visitors in the early morning of Nov. 4 were redirected to a malicious website designed to infect them with malware.