New Phishing Kits Use Open-Source Tools to Bypass MFA

Researchers at Lexfo are tracking three sophisticated phishing kits that were built using open-source components, primarily based on the publicly available adversary-in-the-middle (AiTM) ...

Inside the OS-Aware Phishing Kit Profiling Your Device

Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal The lure email has been received. This is a fabricated iCloud sign-in alert designed to feel like an official security ...

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called “Jalisco,” is a device code phishing ...

5 Essential Cybersecurity Defenses for Cloud Email Security

Cloud email has become the center of modern business. Regardless of your organization's industry or size, email connects employees, customers, vendors, executives, financial systems and ...

Report: Device Code Phishing is Surging

Multiple sophisticated phishing kits are now focusing on harvesting device codes to breach accounts without a password, according to researchers at LevelBlue.

New Extortion Scam Uses IT Impersonation to Breach Organizations

A newly surfaced extortion brand called “Pink” is using voice phishing and fake IT support calls to breach organizations, the Register reports. The threat actor may be a rebrand of prior ...

I Love Device-Bound Session Credentials, But They Are Still Phishable and Hackable

Google recently released Device-Bound Session Credentials (DBSC) for Google Chrome and Google Workspace. It is a long-awaited new security enhancement to fight back against local cookie ...

FBI: Kali365 Phishing Kit is Targeting Microsoft 365 Accounts

The US Federal Bureau of Investigation (FBI) has warned that a new phishing-as-a-service (PhaaS) platform called “Kali365” is targeting OAuth tokens to gain direct access to users’ ...

Chinese-Language Phishing Kits Are Growing More Advanced

Google’s Threat Intelligence Group (GTIG) is tracking phishing-as-a-service offerings in the rapidly expanding Chinese cybercriminal ecosystem, noting that at least a dozen of these ...

Report: The Tycoon 2FA Phishing Kit Has Evolved

The Tycoon 2FA phishing-as-a-service platform is now using OAuth device code phishing to compromise devices that are protected by multifactor authentication, according to eSentire’s ...