Insights

SMEs – A Growing Cyber Target

Small – Medium Enterprises often think they are too small to be of interest to cyber attackers. But this is far from the case. They have long been targets and interest in them is growing. This Insight looks at why and what to do to be safer. 

 

SMEs are big targets for cybercriminals

 


Phishers Exploit Google Sites and DKIM Replay to Send Signed Emails, Steal Credential

Cyber attackers have found they can send phishing emails from real Google sites. The fact that the emails do originate from a Google site makes people trust them and more apt to click that link or follow the instructions.  

 

Message is from Google site but still a scam


State-sponsored hackers embrace ClickFix social engineering tactic

ClickFix is a hacking technique that displays a message saying a download or other install didn’t work. It requests that you run a script fix the problem. But all that does is install malware. It is an effective technique that is being used by state sponsored North Korean cyber groups.    

 

Problem message may be a scam


4 in 10 Americans Have Lost Money to Fraud, AARP Survey Finds

Fraud is more pervasive and widespread than many like to admit. New research shows that 40% of Americans have suffered financial losses due to fraud. The number may be higher as many people hesitate to report it for fear of being embarrassed. 

 

Financial fraud is pervasive


Darcula Adds GenAI to Phishing Toolkit, Lowering the Barrier for Cybercriminals

Darcula is a phishing-as-a-service provider. This means they provide all the materials and technology needed to go into the phishing business. Now they have enhanced their toolkit with AI to make the phishing emails even more believable and harder to identify. 

 

AI enhanced phishing service


Another AI Threat – Slopsquatting

Slopsquatting is another form of AI hallucinations. This time tied to code development that can infect the output of the AI system. The AI systems hallucinated over 20% of the repository dependencies. Very dangerous.

 

More AI hallucinations=more risks


Crypto Developers Targeted by Python Malware Disguised as Coding Challenges

Another attack on software developers uses job ads. When someone replies, they are sent an infected assignment. Opening it compromises and infects their systems!

 

Developers beware


ResolverRAT Campaign Targets Healthcare, Pharma via Phishing and DLL Side-Loading

A new RAT, Remote Access Trojan, has been found allowing attackers to penetrate and take control of systems. Phishing emails are how it arrives. Healthcare and pharmaceuticals are current targets.

 

New RAT discovered


MITRE Hackers’ Backdoor Has Targeted Windows for Years

The same technique that was used to compromise MITRE has been found to have been used against Windows systems for a few years. It is a complex sophisticated attack.   

 

Windows backdoor attack going on for years


Man Helped Chinese Nationals Get Jobs Involving Sensitive US Government Projects

Much was written about North Koreans being unknowingly hired by many US companies. Now Chinese nationals are getting into US companies through someone who lied and scammed the companies. Vetting new hires is getting more difficult but is more important than ever. 

 

Chinese nationals infiltrate American companies