Attackers impersonated human resources departments in malicious emails purporting to be about salary updates containing PDF attachments with malicious QR codes.
Many of these "unknown" attacks are old wine in new bottles, so by focusing on familiar vectors like phishing, teams will find that these threats will decrease.
Hackread reports that organizations in the IT and technology industry were most spoofed in phishing scams between January 2020 and March 2024, followed by those in the banking and financial services sector.
U.S. federal agencies recorded 32,211 cyber incidents in 2023, representing a 9.9% increase over 2022, most of which involved violations of system usage policies, The Register reports.
BleepingComputer reports that threat actors have launched phishing campaigns involving phony job and recruitment offers to facilitate the spread of the new advanced Warmcookie malware that enables screenshot capturing, machine fingerprinting, and further payload delivery on Windows machines.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.