Phishing attacks that defeat MFA are easier than ever. So what are we to do? – Go Health Pro

Phishing attacks that defeat MFA are easier than ever. So what are we to do? – Go Health Pro

These sorts of adversary-in-the-middle attacks have grown increasingly common. In 2022, for instance, a single group used it in a series of attacks that stole more than 10,000 credentials from 137 organizations, and led to the network compromise of authentication provider Twilio, among others. One company that was targeted in the attack campaign but wasn’t … Read more

Microsoft Office 365 MFA targeted by ‘SessionShark’ phishing kit – Go Health Pro

Microsoft Office 365 MFA targeted by ‘SessionShark’ phishing kit – Go Health Pro

A new phishing-as-a-service (PhaaS) kit known as “SessionShark” targets Microsoft Office 365 accounts and claims to enable multi-factor authentication (MFA) bypass while evading common detection methods, SlashNext reported in a blog post Thursday.SessionShark allegedly serves as an adversary-in-the-middle (AiTM) tool that intercepts login credentials and user session tokens, the latter of which can be used … Read more

China-based SMS Phishing Triad Pivots to Banks – Krebs on Security – Go Health Pro

China-based SMS Phishing Triad Pivots to Banks – Krebs on Security – Go Health Pro

China-based purveyors of SMS phishing kits are enjoying remarkable success converting phished payment card data into mobile wallets from Apple and Google. Until recently, the so-called “Smishing Triad” mainly impersonated toll road operators and shipping companies. But experts say these groups are now directly targeting customers of international financial institutions, while dramatically expanding their cybercrime … Read more

Black Basta-like Microsoft Teams phishing leads to novel backdoor – Go Health Pro

Black Basta-like Microsoft Teams phishing leads to novel backdoor – Go Health Pro

A Microsoft Teams phishing campaign, leveraging techniques commonly used in Black Basta ransomware attacks, was found to spread a unique PowerShell backdoor in recent attacks, ReliaQuest reported Friday.The March 2025 malware campaign also leveraged a persistence tactic never before seen in the wild, according to ReliaQuest, in which the Windows Type Library (TypeLib) is hijacked … Read more

News alert: Arsen introduces new AI-based phishing tests to improve social engineering resilience – Go Health Pro

News alert: Arsen introduces new AI-based phishing tests to improve social engineering resilience – Go Health Pro

Paris, France, Mar. 24, 2025, CyberNewswire — Arsen, a leading cybersecurity company specializing in social engineering defense, today announced the full release of Conversational Phishing, a groundbreaking feature embedded in its phishing simulation platform. This AI-powered tool introduces dynamic, adaptive phishing conversations to train employees against evolving threats more effectively than ever before. Advanced phishing … Read more