Sneaky Log Phishing Scheme Targets Two-Factor Security

Sneaky Log Phishing Scheme Targets Two-Factor Security

Security researchers at French firm Sekoia detected a new phishing-as-a-service kit targeting Microsoft 365 accounts in December 2024, the company announced on Jan. 16. The kit, called Sneaky 2FA, was distributed through Telegram by the threat actor service Sneaky Log. It is associated with about 100 domains and has been active since at least October 2024. Sneaky 2FA is an adversary-in-the-middle attack, meaning it intercepts information sent between two devices: in this case, a device…

Read More

Microsoft’s Security Copilot Enters General Availability

Microsoft’s Security Copilot Enters General Availability

Microsoft Security Copilot, also referred to as Copilot for Security, will be in general availability starting April 1, the company announced today. Microsoft revealed that pricing for Security Copilot will start at $4/hr, calculated based on usage. At a press briefing on March 7 at the Microsoft Experience Center in New York (Figure A), we saw how Microsoft positions Security Copilot as a way for security personnel to get real-time assistance with their work and…

Read More

Sekoia: Latest in the Financial Sector Cyber Threat Landscape

Sekoia: Latest in the Financial Sector Cyber Threat Landscape

A new report from French-based cybersecurity company Sekoia describes evolutions in the financial sector threat landscape. The sector is the most impacted by phishing worldwide and is increasingly targeted by QR code phishing. The financial industry also suffers from attacks on the software supply chain and stands among the most targeted sectors impacted by ransomware in 2023. And an increase in attacks on Android smartphones affects the sector, both for cybercrime and cyberespionage operations. Jump…

Read More

Shifting Cybersecurity: The Impact and Implications of LLMs

Shifting Cybersecurity: The Impact and Implications of LLMs

Artificial Intelligence & Machine Learning , Fraud Management & Cybercrime , Next-Generation Technologies & Secure Development Proofpoint CEO Ashan Willy on Taking an Experimental Approach to Applying Gen AI Tom Field (SecurityEditor) • August 25, 2023     Ashan Willy, CEO, Proofpoint While a significant number of attacks are not yet AI-driven, there’s a noticeable shift in the creation of generative malware and lures for business email compromise, warned Ashan Willy, CEO at Proofpoint….

Read More

COVID-19 Vaccine Themes Persist in Fraud Schemes

COVID-19 Vaccine Themes Persist in Fraud Schemes

Business Email Compromise (BEC) , COVID-19 , Fraud Management & Cybercrime Fraudsters Impersonate Vaccine Manufacturers, WHO, DHL Prajeet Nair (@prajeetspeaks) • January 18, 2021     A COVID-19 vaccine phishing landing page asking users to login with Office 365 credentials (Source: Proofpoint) Researchers at the security firm Proofpoint are tracking several fraud schemes leveraging COVID-19 vaccine-themed emails. See Also: The Evolution of Email Security The schemes include business email compromise scams, messages with malicious…

Read More