Massive US payment card compromise facilitated by Chinese smishing operations The U.S. had 12.7 million to 115 million payment cards compromised in Chinese smishing campaigns involving digital wallet tokenization exploits from July 2023 to October 2024, leading to financial losses in the billions of dollars, Infosecurity Magazine reports.
Hackread reports that Microsoft 365 users have been subjected to a novel phishing campaign that exploits Discord CDN links to facilitate the distribution of the Atera and Splashtop remote monitoring management tools under the guise of a fake OneDrive attachment.
More than 15,000 fraudulent websites impersonating TikTok Shop have been leveraged to facilitate the deployment of information- and cryptocurrency-stealing malware, as well as spyware, as part of the global ClickTok scam campaign, Cybernews reports.
Hackread reports that threat actors have been exploiting Microsoft 365's Direct Send feature, which is originally meant to expedite fax and scan deliveries to email addresses, to facilitate a phishing campaign that involves malicious internal-looking emails.
Artificial intelligence has been used to create a new malicious npm package impersonating the "NPM Registry Cache Manager" that includes a clandestine cryptocurrency wallet drainer that could compromise Windows, Linux, and macOS systems, reports The Register.
Hackread reports that malicious actors have begun using malicious Windows shortcut files to distribute the Remcos RAT malware as part of a new attack campaign.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.