Category: phishing
-

Akamai’s new study: Bots, phishing and server attacks making commerce a cybersecurity hotspot
The study shows attackers are using more bots and doing more sophisticated phishing exploits and server attacks, especially targeting retail. Image: Sashkin/Adobe Stock Attacks on commerce are booming, according to a new study by security firm Akamai. The company’s 15-month review beginning in January 2022 found that commerce was the most targeted web vertical, with…
-

Verizon 2023 DBIR: DDoS attacks dominate and pretexting lead to BEC growth
In Verizon’s just-released 2023 Data Breach Investigations Report, money is king, and denial of service and social engineering still hold sway. Image: Ar_TH /Adobe Stock Verizon’s just-released 2023 Data Breach Investigations Report shows the continued effectiveness of business email compromises. The study, which tracked incidents occurring between November 1, 2021 and October 31, 2022, found…
-

How business email compromise attacks emulate legitimate web services to lure clicks
—
by
New BEC cyberattacks use phishing with a legitimate Dropbox link as a lure for malware and credentials theft. Image: Adobe Stock. Threat actors have added a new wrinkle to traditional business email compromise cyberattacks. Call it BEC 3.0 — phishing attacks that bury the hook in legitimate web services like Dropbox. Avanan, a unit of…
-

At RSA, Akamai put focus on fake sites, API vulnerabilities
Image: Ar_TH/Adobe Stock Last year, attacks using vulnerabilities in applications and application protocol interfaces reached record highs, according to security company Akamai in its new State of the Internet report. The firm said several common vulnerabilities and CVEs — common vulnerabilities — persisted last year on the heels of the well-known Log4Shell, ProxyNotShell, Spring4Shell and…
-

BECs double in 2022, overtaking ransomware
A look at 4th quarter 2022, data suggests that new threat surfaces notwithstanding, low-code cybersecurity business email compromises including phishing, as well as MFA bombing are still the prevalent exploits favored by threat actors. Image: Adobe Stock Cybersecurity defenders peering into the fog hoping to catch a glimpse of the next threat might be staring…
-

OneNote documents spread malware in several countries
A new phishing campaign abuses OneNote documents to infect computers with the infamous AsyncRAT malware, targeting users in the U.K., Canada and the U.S. Image: Sashkin/Adobe Stock As Microsoft decided to change the default of its Office products to block macros on files downloaded from the internet, cybercriminals saw one of their favorite infection methods…