Lead Analysts: Karthikeyan D, Prabhakaran Ravichandhiran, Jeewan Singh Jalal
![]()
Somewhere in your security and compliance stack, there are records that prove your employees completed their security awareness training. But when these records need to serve as evidence, would they actually hold up to scrutiny?
![]()
Researchers at Fortra are tracking a new variant of calendar phishing in which threat actors trick employees into sharing meeting links internally.
The attackers pose as prospective customers and contact non-sales employees, asking to be directed to a sales representative in order to discuss a business opportunity. The attacker then sends the employee a meeting link to forward to a sales contact.
![]()
A phishing campaign is targeting Google accounts with lures that promise free subscriptions to Anthropic’s Claude Max AI model, Malwarebytes warns.
![]()
Researchers at Netskope are tracking a phishing kit that hijacks users’ browser windows to display fake security alerts. The malicious websites are distributed via Google Ads, and pose as normal online stores. Once a user clicks a link on the page, however, the site will present them with an urgent-looking security warning.
![]()
Lead Analysts: Lucy Gee and Emily Hanlon
As millions of shoppers prepare their wishlists and await discounts for Amazon’s Prime Big Deal Days starting October 6, cybercriminals are gearing up for their own payday.
![]()