Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress
Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users with Huntress SAT.
Authorities disrupted multiple global cybercrime rings this week, marking significant progress in international enforcement efforts. Attackers leveraged DocuSign in phishing campaigns associated with NovaCookies, exploiting trusted document services to increase credential theft effectiveness. Spark RAT activity was observed targeting Cambodia through exploitation of vulnerable drivers, demonstrating continued geographic-specific malware campaigns.
Read full article at SentinelOne Labs ↗Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users with Huntress SAT.
Get ready for a phishing trip! Learn about the strategy behind phishing simulations and how it can help your organization build resilience against real phishing threats.
Learn the essentials of phishing simulation training with our beginner's guide. Protect your organization by simulating real phishing attacks.
A widespread phishing campaign leveraged counterfeit voicemail SVG attachments to circumvent email security controls, distributing more than 26,000 malicious messages across over 5,500 organizations. The use of SVG files as an obfuscation technique allowed attackers to evade traditional defenses while maintaining a convincing social engineering pretext.