Bitpanda spoofed in advanced phishing operation Infosecurity Magazine reports that Austrian cryptocurrency brokerage Bitpanda had its customers subjected to a sophisticated phishing campaign that sought to pilfer credentials and personal data through a highly convincing replica of the cryptocurrency platform.
The Diesel Vortex campaign, also marketed as "Global Profit" and "MC Profit Always," utilizes 52 domains and a highly organized operation that includes a call center and dedicated staff.
Ad tech firm Optimizely, which counts PayPal, Salesforce, Vodafone, and Zoom among its clients, has been impacted by a data breach stemming from a voice phishing attack against certain systems, according to BleepingComputer.
Cybernews reports that Microsoft, Google, Apple, Facebook, and other platforms have had their legitimate login pages exploited by the new Starkiller phishing kit for credential theft.
Manufacturing, technology, and financial entities are having their Microsoft Entra accounts subjected to combined device code phishing and voice-based phishing intrusions exploiting the OAuth 2.0 Device Authorization flow, according to BleepingComputer.
Infosecurity Magazine reports that AI has been allowing low-skilled cybercriminals to craft convincing extortion messages with deadlines and pressure tactics with the new "vibe extortion" technique.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.