Malicious purchase order attachment emails are driving a new wave of phishing attacks against businesses. Cybercriminals are sending fake procurement messages that appear routine and urgent. The attached document, presented as a purchase order, contains hidden malware designed to compromise corporate systems. Security researchers warn that this tactic exploits everyday business workflows. Finance, procurement, and…
A coordinated freight phishing campaign is targeting logistics and transportation organizations across the United States and Europe. Security researchers report that attackers are using shipment-themed emails to trick freight companies into downloading malicious files or revealing credentials. The campaign focuses on businesses involved in shipping, freight forwarding, and supply chain management. By impersonating legitimate partners…
Cybercriminals are expanding phishing beyond inboxes. The hardware wallet phishing letters campaign targets cryptocurrency holders using printed mail that appears official and urgent. Instead of malicious links in emails, victims receive physical documents claiming a critical security update is required. The realistic presentation lowers suspicion and encourages immediate action. How the scam reaches victims Recipients…
Signal account targeting has escalated as state-linked cyber actors focus on high-profile users of the encrypted messaging platform. Security agencies warn that attackers rely on social engineering rather than technical flaws to gain access to private communications. The campaign shows how manipulation can bypass strong encryption without exploiting software vulnerabilities. How attackers access Signal accounts…
Exchange Online false phishing flags have disrupted email delivery after the service began misclassifying legitimate messages as malicious. Users and administrators reported that normal emails suddenly landed in quarantine without warning. The issue has interfered with both internal and external communication across affected environments. The problem highlights how sensitive email filtering systems can impact daily…
A new Apple Pay phishing scam shows how attackers can bypass two-factor authentication by manipulating users directly. The campaign relies on fake fraud alerts and convincing phone calls that pressure victims into sharing verification codes in real time. Security researchers warn that the method makes even strong account protections ineffective when users trust the wrong…
Hackers have reportedly bypassed internal security at major dating platforms through targeted voice phishing attacks. The Bumble OkCupid voice phishing incidents did not rely on software vulnerabilities but instead exploited employee trust through convincing phone calls. This approach highlights how human-focused attacks continue to succeed even when technical safeguards are in place. The incidents underline…
A new Chrome phishing extension malware service shows how cybercriminals now monetize browser abuse at scale. The service advertises guaranteed placement of malicious extensions inside the official Chrome Web Store. By promising to bypass review processes, it lowers the barrier for attackers who want to deploy phishing tools through trusted platforms. This development threatens user…
1Password phishing warnings now appear as pop-up alerts when users attempt to enter credentials on suspicious websites. The update targets phishing pages that imitate legitimate services and trick users into revealing usernames and passwords. The new feature aims to stop credential theft at the moment users are most vulnerable. How the phishing warnings work 1Password…
An India China phishing campaign has emerged that uses deceptive emails to install malware designed for long-term espionage rather than immediate financial theft. The operation targets recipients with messages that impersonate official communications and pressure victims into opening malicious attachments. Once executed, the malware establishes a persistent backdoor that allows attackers to monitor activity and…