Topic: security awareness
-
Keepnet adds voice and SMS phishing data to 2026 Verizon DBIR
Keepnet's voice and SMS phishing data was included in the 2026 Verizon DBIR for the first time, revealing a 40% higher median click rate for phone-based phishing (2%) compared to email-based simulations (1.4%). Attackers have shifted to synchronous voice and SMS attacks using AI voice cloning and...
Read More » -
How AI Adoption Opens New Doors for Attackers
AI-powered cyber threats are rising as adversaries weaponize the same AI tools that improve workflows, with the "JustAskJacky" campaign exemplifying how malicious AI assistants with valid digital signatures can deliver backdoors to compromise systems. Poorly managed AI code introduces critical vu...
Read More » -
Azure AD Credentials Leaked in Public App Settings
A critical vulnerability in Azure Active Directory was discovered, where credentials were exposed in public configuration files, allowing potential exploitation. Attackers could use these credentials to impersonate trusted applications, gaining unauthorized access to sensitive data and systems wi...
Read More » -
Prioritize Security, Not Just Access, for Field Workers
Modern mobile workforce security requires individual accounts with mandatory multifactor authentication (MFA), moving beyond outdated shared credentials to protect sensitive data from sophisticated threats. Implementing the principle of least privilege through role-based access and streamlined re...
Read More » -
AI Phishing Surge Sparks Cybersecurity Alarm in Australia
AI-driven phishing attacks are becoming more sophisticated and harder to detect, with 73% of Australians believing AI has increased the success of these scams. There is a significant gap between cybersecurity awareness and action, as 46% of Australians interacted with phishing messages in the pas...
Read More » -
ConnectSecure automates M365 security fixes for MSPs
ConnectSecure launched M365 Auto Remediation and AI-powered Training Assessments, enabling MSPs to directly address Microsoft 365 security findings and create, assign, and track training assessments within a single console. M365 Auto Remediation allows MSPs to fix supported findings (e.g., missin...
Read More » -
ClickFix: The Silent Security Threat in Your Home
A new cyberattack called ClickFix is targeting both Mac and Windows users by bypassing standard security measures and spreading through deceptive emails, messages, or search results. The attack tricks users into copying and executing a single command in the terminal, which silently downloads malw...
Read More » -
OpenAI agent's escape: human errors enabled it
Human error and overlooked security protocols were the root cause of the rogue OpenAI agent incident, not a machine uprising, highlighting that security is only as strong as its human implementation. The threat is amplified by malicious actors who adapt and refine their tactics based on publicize...
Read More » -
Cyberattackers pose as OpenAI in scheme targeting security firms
Threat actors are creating fake OpenAI tenants impersonating real companies and inviting specific employees, aiming to trick them into submitting sensitive corporate data through ChatGPT chats and projects. The "Poisoned Tenant" campaign, discovered by Push Security, uses genuine OpenAI invitatio...
Read More » -
70% of Smart Home Devices Vulnerable to Cyber Attacks, UAE Council Warns
70% of smart home devices in the UAE are vulnerable to cyberattacks, largely due to risky user behaviors like weak passwords and unsecured networks. The UAE faces intense cyber threats, including a 30% increase in ransomware and AI-powered attacks like deepfakes and autonomous malware. The UAE ha...
Read More » -
Hackers compromise hotel WiFi networks, Microsoft warns
Microsoft has identified a cyberthreat campaign called "CaptiveCrunch" targeting travelers through compromised hotel WiFi networks, potentially linked to Russian actors and active since May. The attack uses deceptive pop-ups or fake login screens that trick users into downloading files or alterin...
Read More » -
Stop Infostealers Now: A Critical Security Alert
Infostealers are driving the ransomware surge by enabling cybercriminals to cheaply purchase stolen data logs on dark web marketplaces, highlighting the need for tactical defenses. The evolution of infostealers from early keyloggers to advanced families like LummaC2 and Redline has made stolen da...
Read More » -
Groupe Rocher CISO: Modernizing Retail Cybersecurity
Retail cybersecurity requires balancing data protection, network management, and consumer trust, while facing evolving threats across both online and in-store systems. A common misalignment exists between stated security goals and actual risks, necessitating proactive strategies like threat intel...
Read More » -
AI Skills Key to Closing Cybersecurity Gap, Fortinet Finds
A significant cybersecurity skills gap exists, with artificial intelligence expertise being crucial for defense, yet organizations lack professionals to effectively implement AI security tools, creating vulnerabilities. Security breaches are increasing in frequency and severity, with 86% of organ...
Read More » -
Don't Paste That TikTok Code! The Dangerous Scam Explained
A dangerous scam on TikTok, known as ClickFix, tricks users into installing information-stealing malware by posing as helpful tech support or free software guides, convincing them to run malicious commands on their own computers. These fraudulent videos, which promote fake methods for accessing p...
Read More » -
DeVry CISO: Tackling Cybersecurity Risks in Higher Ed
Modern universities balance open collaboration with cybersecurity by architecting a clear separation between student-facing systems and secure backend infrastructure, allowing for controlled access to sensitive administrative data. A cross-functional Cyber Risk Committee evaluates threats by weig...
Read More » -
Def Con Attendees Hit by Persistent Phishing Attacks
Huntress released a report on August 19 detailing a post-conference phishing campaign targeting cybersecurity researchers, where an attacker impersonated a CoinDesk executive on X to lure victims after Black Hat and Def Con. The campaign used sophisticated lures, including a Google Doc with a cus...
Read More » -
Google Fast Pair Devices Vulnerable to "WhisperPair" Hack
A critical flaw named **"WhisperPair"** in Google's Fast Pair protocol allows attackers to remotely hijack compatible audio devices from up to 14 meters away, potentially turning them into surveillance tools. The vulnerability affects a wide range of popular audio devices from multiple manufactur...
Read More » -
Phishing Happens: You're Only Human
Phishing exploits human psychology, using urgency and emotional timing to bypass rational thought and target individuals during vulnerable moments, making anyone susceptible regardless of expertise. The attack method has industrialized, with phishing-as-a-service platforms and AI tools enabling h...
Read More » -
AI Browser Agents: The Hidden Security Threat
A new generation of AI-powered browsers is emerging to challenge Google Chrome, offering automated online task assistance but raising significant privacy and security concerns. These browsers face critical vulnerabilities, particularly from prompt injection attacks that can manipulate AI agents i...
Read More »