The technology sector continues to be the primary target for brand impersonation, with Google, Amazon, and Apple also appearing frequently in phishing campaigns.
Infosecurity Magazine reports that threat actors have leveraged fraudulent PayPal alerts to deploy legitimate remote monitoring and management tools in a bid to pilfer credentials as part of a phishing attack campaign.
Security researchers have uncovered a sophisticated malware campaign where cybercriminals are exploiting Cloudflare's free-tier services and TryCloudflare tunneling domains to host malicious WebDAV servers, effectively concealing AsyncRAT attacks behind trusted infrastructure, according to Cyber Press.
The phishing campaign involves bot-like profiles creating comments that falsely claim users have violated LinkedIn's policies and that their accounts are temporarily restricted.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.