Infosecurity Magazine reports that threat actors have leveraged fraudulent PayPal alerts to deploy legitimate remote monitoring and management tools in a bid to pilfer credentials as part of a phishing attack campaign.
Security researchers have uncovered a sophisticated malware campaign where cybercriminals are exploiting Cloudflare's free-tier services and TryCloudflare tunneling domains to host malicious WebDAV servers, effectively concealing AsyncRAT attacks behind trusted infrastructure, according to Cyber Press.
The phishing campaign involves bot-like profiles creating comments that falsely claim users have violated LinkedIn's policies and that their accounts are temporarily restricted.
Infosecurity Magazine reports that cyber-enabled fraud has been named by business leaders as their primary cybersecurity concern this year, surpassing ransomware intrusions.
More threat actors have been exploiting the Browser-in-the-Browser attack technique to pilfer Facebook account credentials in phishing intrusions during the last six months, according to BleepingComputer.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.