PhishingInfosecurity Magazine·3 weeks ago

AiTM Phishing Becomes Top Initial Access Threat to Law Firms

Adversary-in-the-middle (AiTM) phishing attacks have emerged as the primary initial access vector for threats targeting law firms, accounting for 56% of identified threats. The reliance on identity-based attacks underscores a shift in how threat actors are compromising legal organizations and their sensitive client data.

VulnerabilityZero Day Initiative·3 weeks ago

The July 2026 Apple Security Update Review

Apple's July 2026 security update addresses 210 CVEs, a dramatic spike from 37 in June, with three vulnerabilities standing out as particularly severe: CVE-2026-43818 (ImageIO arbitrary code execution via malicious images across iOS and macOS), CVE-2026-64747 (AVEVideoEncoder kernel-level code execution affecting all platforms), and CVE-2026-64767 (AFP network-reachable kernel memory corruption affecting macOS). Additional critical risks include multiple file-parsing exploits and remote kernel-corruption vulnerabilities across SMB, Model I/O, and SceneKit components that security teams should prioritize for patching.

PhishingInfosecurity Magazine·3 weeks ago

Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages

Check Point researchers have identified a Teams-themed phishing campaign that leverages Microsoft's legitimate authentication infrastructure rather than deploying fake login pages. By abusing the actual Microsoft login system, attackers are able to bypass traditional security controls that typically flag fraudulent authentication portals. This technique represents an evolution in phishing tactics, making detection more challenging for organizations relying on standard indicators of compromise.

VulnerabilityTrail of Bits·3 weeks ago

Building secure Uniswap v4 hooks

Uniswap v4's hook architecture enables powerful customization but shifts security responsibilities to application developers, as demonstrated by the Cork ($12M) and Bunni ($8.4M) exploits—both stemming from flawed hook code rather than protocol vulnerabilities. The article identifies seven recurring failure patterns in hook development, including missing caller checks, unvalidated pool selection, accounting bugs, and callback state management issues, alongside an eight-point secure development checklist for builders and seven-point audit framework for reviewers. Understanding these patterns is critical for developers integrating with v4, as hooks execute in the same transaction as pool actions and can silently leak value even when settlement invariants are satisfied.

Nation-StateUnit 42·3 weeks ago

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

A Chinese-speaking threat actor is leveraging AI models to automate vulnerability scanning across seven different vulnerabilities while maintaining manual exploitation capabilities. This hybrid approach combines the speed and scale of autonomous AI-driven reconnaissance with targeted manual attack techniques, representing an evolving tactic in adversarial operations.

Nation-StateGraham Cluley·3 weeks ago

North Korea’s elite hackers turned on their own government – and got caught

North Korea's state-sponsored hackers, known for orchestrating major heists against foreign banks and cryptocurrency exchanges to fund the regime's weapons program, reportedly turned their skills against their own government in an unprecedented reversal. The operation appears to have ended badly for the attackers involved, marking a dramatic departure from their typical targeting of international financial institutions. This incident highlights internal fractures within North Korea's cybercriminal apparatus and raises questions about dissent within the regime's most elite hacking units.

VulnerabilityInfosecurity Magazine·3 weeks ago

Google Releases Patches for 370 Vulnerabilities in Chrome 151

Google has released Chrome 151, addressing 370 vulnerabilities across the browser, including seven critical flaws. Security professionals should prioritize updating to this version to mitigate exposure to these patched critical issues.

Policy & LegalInfosecurity Magazine·3 weeks ago

NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Devices

The UK's National Cyber Security Centre is calling on network device vendors to embed enhanced forensic observability capabilities into their products to improve incident investigation and threat detection. This push aims to give security teams better visibility into network device behavior and activity logs for post-incident analysis and forensic investigations.

PhishingGraham Cluley·3 weeks ago

Smashing Security podcast #478: This job interview could destroy your company

North Korean threat actors are exploiting fake cryptocurrency job recruitment schemes that use webcam-enabled assessments to socially engineer victims, with reported losses exceeding $643 million in crypto theft this year. Separately, researchers discovered that 2.2 million U.S. vehicles equipped with a specific aftermarket car alarm system can be remotely unlocked or disabled due to a critical cryptographic flaw in the alarm's design that has persisted undetected since 2017.

Steam Malware situation so bad the FBI has a page for it!

PC Security Channel·111K views · 3 weeks ago
MalwareInfosecurity Magazine·3 weeks ago

Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack

Russian-aligned threat actor TA488 has resumed operations with a sophisticated attack targeting Outlook Web Access (OWA) using a half-click exploit technique. The campaign deploys a custom implant called OWAReaper that demonstrates persistence capabilities even after system re-imaging, presenting a significant challenge for defenders attempting to remediate compromised environments.

Data BreachInfosecurity Magazine·3 weeks ago

The Average Cost of a Data Breach Rises to $5 Million

IBM's latest Cost of a Data Breach Report reveals that organizations now face an average breach cost of nearly $5 million globally, marking a significant increase from previous years. AI-powered attacks have contributed to this escalating financial impact, underscoring the evolving threat landscape that security professionals must contend with.

Load more