From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud

Credit to Author: Paul Oliveria| Date: Tue, 12 Jul 2022 16:00:00 +0000

A large-scale phishing campaign that attempted to target over 10,000 organizations since September 2021 used adversary-in-the-middle (AiTM) phishing sites to steal passwords, hijack a user’s sign-in session, and skip the authentication process, even if the user had enabled multifactor authentication (MFA).

The post From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud appeared first on Microsoft Security Blog.

Read more

A week in security (June 20 – June 26)

Credit to Author: Malwarebytes Labs| Date: Mon, 27 Jun 2022 09:30:06 +0000

The most important and interesting computer security stories from the last week.

The post A week in security (June 20 – June 26) appeared first on Malwarebytes Labs.

Read more

Rogue cryptocurrency billboards go phishing for wallets

Credit to Author: Christopher Boyd| Date: Thu, 23 Jun 2022 15:15:21 +0000

We take a look at reports of rogue cryptocurrency billboards out to phish wallet details from unwary victims.

The post Rogue cryptocurrency billboards go phishing for wallets appeared first on Malwarebytes Labs.

Read more