The attackers likely initiated access using previously compromised email addresses, sending phishing emails containing a SharePoint URL disguised with subjects like "New Proposal - NDA," according to Microsoft.
Threat actors are poised to launch credential-harvesting phishing and spoofed websites, as well as harness event system software and API flaws ahead of the Milano-Cortina Winter Olympics next month, according to Infosecurity Magazine.
Afghan ministry and administrative office workers have been targeted with malware-spreading phishing emails purporting to be from the office of the country's prime minister as part of the Nomad Leopard campaign, according to The Record, a news site by cybersecurity firm Recorded Future.
The technology sector continues to be the primary target for brand impersonation, with Google, Amazon, and Apple also appearing frequently in phishing campaigns.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.