AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – t… Continue reading AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

Bogus recruiters go after high-value corporate credentials on mobile

Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are using a technique called browser-in-the-browser, or BitB, which CTM360 documente… Continue reading Bogus recruiters go after high-value corporate credentials on mobile

INTERPOL crackdown on West African crime rings uncovers troubling new trend

Police across 22 countries arrested 58 people and identified 263 suspects during an eight-month INTERPOL operation targeting West African organized crime groups. Suspects detained in an operation targeting West African crime groups (Source: INTERPOL) O… Continue reading INTERPOL crackdown on West African crime rings uncovers troubling new trend

Fake OpenAI Codex download tricks macOS users into installing malware

A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks. It’s a variation of ClickFix, a popular social engineeri… Continue reading Fake OpenAI Codex download tricks macOS users into installing malware

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system. The admission came after the extortion group Sh… Continue reading ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

TruffleHog AWS Analyze reduces remediation time on leaked AWS credentials

Truffle Security announced TruffleHog AWS Analyze, a new addition to TruffleHog Enterprise. TruffleHog AWS Analyze enriches found AWS credentials to highlight permissions and access levels, so a security team can assess the risk and prioritize its resp… Continue reading TruffleHog AWS Analyze reduces remediation time on leaked AWS credentials

Cybersecurity job ads demanding AI skills double in a year

Job postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium. Analysis from recruitment firms Cornerstone and Indeed covering 24 months, from A… Continue reading Cybersecurity job ads demanding AI skills double in a year

Android car head units infected with proxy botnet malware through built-in software updaters

A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in a proxy botnet, Kaspersky has found. According to the researchers, it’s the … Continue reading Android car head units infected with proxy botnet malware through built-in software updaters