A large-scale campaign is targeting developers on GitHub with fake Visual Studio Code (VS Code) security alerts posted in the Discussions section …
Fraud Tracker
- Fraud Tracker
Coruna, DarkSword & Democratizing Nation-State Exploit Kits
by AiNewsBlogby AiNewsBlogCoruna, a high-grade mobile exploit kit armed with zero-day vulnerabilities for high-level espionage efforts, turns out to have links to 2023’s Operation …
- Fraud Tracker
Dutch Police discloses security breach after phishing attack
by AiNewsBlogby AiNewsBlogThe Dutch National Police (Politie) says a security breach resulting from a successful phishing attack has had a limited impact and hasn’t …
- Fraud Tracker
TikTok for Business accounts targeted in new phishing campaign
by AiNewsBlogby AiNewsBlogThreat actors are targeting TikTok for Business accounts in a phishing campaign that prevents security bots from analyzing malicious pages. TikTok Business …
- Fraud Tracker
Citrix urges admins to patch NetScaler flaws as soon as possible
by AiNewsBlogby AiNewsBlogCitrix has patched two vulnerabilities affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions, one of which is very similar …
- Fraud Tracker
‘CanisterWorm’ Springs Wiper Attack Targeting Iran – Krebs on Security
by AiNewsBlogby AiNewsBlogA financially motivated data theft and extortion group is attempting to inject itself into the Iran war, unleashing a worm that spreads …
A threat actor is systematically targeting cloud credentials, SSH keys, authentication tokens, and other sensitive secrets stored in automated enterprise software build …
- Fraud Tracker
FBI links Signal phishing attacks to Russian intelligence services
by AiNewsBlogby AiNewsBlogThe FBI has issued a public service announcement warning that Russian intelligence-linked threat actors are actively targeting users of encrypted messaging apps …
- Fraud Tracker
Microsoft Azure Monitor alerts abused for callback phishing attacks
by AiNewsBlogby AiNewsBlogMicrosoft Azure Monitor alerts are being abused to send callback phishing emails that impersonate warnings from the Microsoft Security Team about unauthorized …
- Fraud Tracker
Google adds ‘Advanced Flow’ for safe APK sideloading on Android
by AiNewsBlogby AiNewsBlogGoogle has announced a new mechanism in Android called Advanced Flow, which will allow sideloading APKs from unverified developers for power users …
A United Nations-sponsored plan has drawn a collection of major businesses into cooperating to boost efforts to combat rampant online fraud, and …
Navia Benefit Solutions, Inc. (Navia) is informing nearly 2.7 million individuals of a data breach that exposed their sensitive information to attackers. …
- Fraud Tracker
Aura confirms data breach exposing 900,000 marketing contacts
by AiNewsBlogby AiNewsBlogIdentity protection company Aura has confirmed that an unauthorized party gained access to nearly 900,000 customer records containing names and email addresses. …
- Fraud Tracker
LeakNet ransomware uses ClickFix, Deno runtime in stealthy attacks
by AiNewsBlogby AiNewsBlogThe LeakNet ransomware gang is now using the ClickFix technique for initial access into corporate environments and deploys a malware loader based on …
Broadcom’s acquisition of VMware in 2023 set off a wave of migrations that shows no signs of subsiding. But moving from VMware …
The FBI is asking gamers who installed Steam titles containing malware to provide information as part of an ongoing investigation into eight malicious …
Nonprofits work to provide free or reduced cost aid, education, and essential resources throughout communities worldwide, but they often struggle to meet …
- Fraud Tracker
Canadian retail giant Loblaw notifies customers of data breach
by AiNewsBlogby AiNewsBlogLoblaw Companies Limited (Loblaw), the largest food and pharmacy retailer in Canada, announced that hackers breached a portion of its IT network …
WhatsApp has begun rolling out parent-managed accounts for pre-teens, allowing parents and guardians to decide who can contact them and which groups …
- Fraud Tracker
New ‘BlackSanta’ EDR killer spotted targeting HR departments
by AiNewsBlogby AiNewsBlogFor more than a year, a Russian-speaking threat actor targeted human resource (HR) departments with malware that delivers a new EDR killer named …
- Fraud Tracker
Microsoft brings phishing-resistant Windows sign-ins via Entra passkeys
by AiNewsBlogby AiNewsBlogMicrosoft is rolling out passkey support for Microsoft Entra on Windows devices, adding phishing-resistant passwordless authentication via Windows Hello. The feature is …
Hackers are increasingly exploiting newly disclosed vulnerabilities in third-party software to gain initial access to cloud environments, with the window for attacks …
- Fraud Tracker
Hackers abuse .arpa DNS and ipv6 to evade phishing defenses
by AiNewsBlogby AiNewsBlogThreat actors are abusing the special-use “.arpa” domain and IPv6 reverse DNS in phishing campaigns that more easily evade domain reputation …
- Fraud Tracker
Termite ransomware breaches linked to ClickFix CastleRAT attacks
by AiNewsBlogby AiNewsBlogRansomware threat actors tracked as Velvet Tempest are using the ClickFix technique and legitimate Windows utilities to deploy the DonutLoader malware and …
- Fraud Tracker
Microsoft 365 Backup to add file-level restore for faster recovery
by AiNewsBlogby AiNewsBlogMicrosoft will soon begin rolling out a significant upgrade to Microsoft 365 Backup to speed up recovery by allowing administrators to restore …
- Fraud Tracker
Ghanain man pleads guilty to role in $100 million fraud ring
by AiNewsBlogby AiNewsBlogA Ghanaian national pleaded guilty to his role in a massive fraud ring that stole over $100 million from victims across the …
- Fraud Tracker
Google says 90 zero-days were exploited in attacks last year
by AiNewsBlogby AiNewsBlogGoogle Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities actively exploited throughout 2025, almost half of them in enterprise software and appliances. …
- Fraud Tracker
India APT Sloppy Lemming Targets Defense, Critical Infrastructure
by AiNewsBlogby AiNewsBlogThe India-linked advanced persistent threat (APT) “Sloppy Lemming” has significantly increased its operational tempo over the past year, adopting more sophisticated tactics …
A new Qualcomm bug has been exploited in limited and targeted attacks against vulnerable Android devices. Google published its monthly Android security …
- Fraud Tracker
Fake Google Security site uses PWA app to steal credentials, MFA codes
by AiNewsBlogby AiNewsBlogA phishing campaign is using a fake Google Account security page to deliver a web-based app capable of stealing one-time passcodes, harvesting …
