A phishing campaign is targeting Google accounts with lures that promise free subscriptions to Anthropic’s Claude Max AI model, Malwarebytes warns.
![]()
A phishing campaign is targeting Google accounts with lures that promise free subscriptions to Anthropic’s Claude Max AI model, Malwarebytes warns.
![]()
Researchers at Netskope are tracking a phishing kit that hijacks users’ browser windows to display fake security alerts. The malicious websites are distributed via Google Ads, and pose as normal online stores. Once a user clicks a link on the page, however, the site will present them with an urgent-looking security warning.
![]()
Lead Analysts: Lucy Gee and Emily Hanlon
As millions of shoppers prepare their wishlists and await discounts for Amazon’s Prime Big Deal Days starting October 6, cybercriminals are gearing up for their own payday.
![]()
At any given moment, there’s an employee somewhere in the world tuning out of a phishing training module that was translated from another language. Every word is rendered correctly, yet the learner still stops paying attention.
In these situations, the translation often gets the blame for not engaging the learner, but the real culprit is design. When training isn’t made for international consumption in the first place, the module is set up for failure regardless of what happens when it reaches the translator.
![]()
Attackers are continually finding new ways to refine business email compromise (BEC) attacks, according to Douglas McKee, Director of Vulnerability Intelligence at Rapid7.
When attackers compromise trusted tools and accounts, they can manipulate victims’ view of reality. One way attackers can achieve this is through what McKee calls “calendar warfare,” in which attackers use calendar meetings to trick users into falling for attacks.
![]()
Spies have always relied on technology, disguises, secret communications and clever gadgets, at least if the movies are to be believed.
But some of the most effective tools in the espionage business have always been people. Convince the right person to open a door, reveal a secret or trust someone they should not, and suddenly bypassing the sophisticated security system becomes unnecessary.
![]()
41% of CISOs said an audio deepfake targeted their organization within the last 12 months, according to a new survey by Gartner. Additionally, 36% of respondents said employees were targeted by deepfake video calls over the past year.
Craig Porter, Director Analyst at Gartner, noted that social engineering and human deception remain at the core of these AI-assisted attacks.
![]()