Cybersecurity researchers have observed a growing trend of threat actors exploiting Telegram's Bot API to covertly exfiltrate sensitive data from high-value organizations and government entities, reports Cyber Security News.
Cybercriminals are shifting from traditional phishing to sophisticated "ramp-and-dump" schemes targeting brokerage accounts, exploiting gaps in multi-factor authentication, researchers say, according to Krebs on Security.
Organizations in the U.S, Europe, and other parts of the world have been targeted with spear-phishing emails purporting to be copyright infringement notices that facilitate Noodlophile information-stealing malware deployment, reports The Hacker News.
SquareX researchers demonstrated during DEF CON an attack technique that could allow attackers to bypass passkey-based login security using process manipulation, SecurityWeek reports.