The scammers are adopting various tactics, including posing as TechCrunch staff to request introductory calls and extract proprietary details from companies.
The Hacker News reports that Microsoft account credentials have been pilfered by the upgraded Sneaky 2FA phishing-as-a-service kit through the newly embedded Browser-in-the-Browser functionality, which conceals phishing URLs via pop-up login forms.
Microsoft Entra B2B tenant invitations have been exploited by threat actors to facilitate a new Telephone-Oriented Attack Delivery phishing campaign, according to Cybernews.
BleepingComputer reports that threat actors have revived the abuse of the decades-old "finger" command to facilitate remote command execution as part of new ClickFix malware attacks.
The FBI has warned that Chinese speakers across the U.S. have been subjected to a new health insurance fraud scheme that threatens extradition should they fail to pay their surgical bills, The Register reports.
The breach, detected on October 25, 2025, occurred when an employee fell victim to a social engineering scam, allowing the attacker to access names, addresses, emails and phone numbers of individuals across DoorDash's operational regions.
Hackers have harnessed Australia's cyber incident disclosure platform ReportCyber to compromise cryptocurrency wallets as part of a new scam campaign, Cybernews reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.