Browsing Tag
Phishing
7 posts
Phishing attacks, impersonation scams, and credential theft.
ACR Stealer Turns ClickFix Lures Into Browser-Token Theft
Microsoft says ACR Stealer activity rose across customer environments from late April to mid-June, with campaigns using ClickFix lures, WebDAV, MSHTA, obfuscated PowerShell, and even JPEG-hidden payloads. Security teams should treat infections as token and document-exposure events, not just password resets.
Signal Backup-Key Phishing Turns Account Recovery Into an Espionage Target
The FBI and CISA warn that Russian intelligence-linked actors are impersonating messaging-app support accounts to steal Signal backup recovery keys, verification codes, and account PINs. The attacks do not break encryption, but they can expose message backups and keep account-takeover paths alive until users replace compromised keys.
LastPass Says Klue Breach Exposed Support Case Data, Not Password Vaults
LastPass says attackers used Klue-held OAuth tokens to access customer CRM and support case data in Salesforce, while its password vaults and core infrastructure were not affected. The practical risk is targeted phishing and social engineering built from real support histories.
Android Fake Call Detection Uses RCS to Fight AI Voice Scams
Google’s Android fake call detection uses an encrypted RCS signal in Phone by Google to warn when a saved contact’s number may be spoofed. The protection is useful, but only works when both phones meet the requirements.
Maine’s Fake Breach Notices Expose a New Weak Point in Cyber Reporting
Maine temporarily shut down public access to its breach-notice database after fake Discord and VRChat filings appeared there, showing how official transparency systems can be abused for misinformation.
Google Targets Outsider Enterprise as AI Scam Texts Become Infrastructure
Google says the Outsider Enterprise used phishing kits, fake sites, Telegram coordination, and mass text campaigns to turn scam messages into a repeatable criminal business.