Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Resurgence of a Fake Captcha Malware Campaign

During an Advanced Continual Threat Hunt (ACTH) investigation in early February 2025, Trustwave SpiderLabs discovered a resurgence of fake CAPTCHA verifications designed to deceive victims into executing malicious PowerShell scripts. This campaign employs a multi-stage PowerShell execution process, ultimately delivering infostealers such as Lumma and Vidar.

245% Increase in SVG Files Used to Obfuscate Phishing Payloads

The KnowBe4 Threat Research team has observed a sustained increase in the use of Scalable Vector Graphics (SVG) files to obfuscate malicious payloads. SVGs are vector based, rather than pixel-based like PNGs and JPGs. This means the graphic elements can be scaled up without loss of quality - making them perfect for sharing graphics, such as logos and icons, via email.

Combating Ransomware, Phishing, and Zelle Fraud at Financial and Bank SOCs

Banking and financial services companies sit on a goldmine of sensitive customer data, making them a prime target for phishing and ransomware attackers hoping to strike a payout. Even with defenses like MFA and security training, human error continues to be a critical point of failure for financial institutions — a 2024 report found that 3 out of every 1000 individuals working in banking click on a phishing link each month.

Elo, Agility and INETCO announce strategic partnership to revolutionize payments reliability in Brazil

2º Congresso de Prevenção e Repressão a Fraudes, Segurança Cibernética e Bancária, SÃO PAULO, BRAZIL, March 11, 2025 – Agility, one of Brazil’s leading IT and Cybersecurity service providers, and INETCO, a global leader in payments monitoring and fraud prevention, are proud to announce a new partnership with Brazilian payment processing trailblazer Elo.

Why Brand Impersonation Scams and Phishing Are Still Winning in APAC-And How to Change That

Customer confidence is the fragile foundation of developing economies, and nowhere is this more true than Asia Pacific where phishing and customer account takeovers (ATO) threaten to bring that foundation crashing down. For financial institutions and airlines in APAC, scam-related fraud is no longer an isolated cost center—it is an existential risk to digital trust and economic growth.

Harness Data to Prevent Fraud with Splunk and AWSSPLUNK_AWS_FRAUD_11202024 (1)

In this webinar, you will learn about the influence of data-driven technology on fraud detection and prevention. You will discover how businesses can use AI, machine learning, and big data analytics to proactively identify hazards and monitor transactions in real time. The workshop will provide useful insights into cutting-edge solutions that improve customer security and protect sensitive information, as well as practical tactics and case studies for successfully combating fraud.

10 Most Common Mistakes When Buying Traffic

Let's start with the biggest fear everyone has: getting scammed. Trust me, no one wants to shell out hard-earned cash for fake clicks, bots, or empty promises. Here's the cold, hard truth: many shady providers out there are more interested in draining your wallet than boosting your traffic. But here's the kicker - you don't have to fall for it. The trick is always starting with a small test buy before committing fully. It's your safety net, your way of dipping a toe in before diving headfirst into the deep end.

Protect Yourself from Job Termination Scams

ESET warns of a wave of phishing attacks informing employees that they’ve been fired or let go. The emails are designed to make the user panic and act quickly to see if they’ve actually lost their job. If a user falls for the attack, they’ll be tricked into downloading malware or handing over their login credentials.

Beware of Fake Cybersecurity Audits: Cybercriminals Use Scams to Breach Corporate Systems

Companies are being warned that malicious hackers are using a novel technique to break into businesses - by pretending to offer audits of the company's cybersecurity. With ransomware and other cybersecurity threats high in the mind of many business owners, it is all too easy to imagine how many companies might react positively to an invitation to have the security of their networks tested.