mitre-ta0006
254 articles with this tag
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Anatomy of a Silent Domain Takeover
Russian national extradited to US for alleged involvement in bank-account takeover scheme
BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
Outsider Phishing Kit Survives Takedown With 700 New Pages
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia
Identity Abuse Through Trusted Communication Channels
Hackers Using AI to Target Siemens PLCs in Critical US Sectors
Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps
Fortune 500 Companies Hit in Azure Data Theft Campaign
Dissecting the JWR phishing framework
Ready-made $500 kit puts a crypto scam within anyone’s reach
Vishing group UNC6671 now focuses on extorting M&A firms
Snowflake hacker pleads guilty, faces up to 32 years in prison
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
Russia-linked Midnight Blizzard targets hotel Wi-Fi networks in US, Europe
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Email threat landscape: Q2 2026 trends and insights
Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages
Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits
Kratos phishing-as-a-service kit loses its battle with international law enforcement
New ClickLock Stealer locks your Mac until you hand over your password
New North Korean campaign uses fake coding interviews to steal developer credentials
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Stolen identities cause 79% of ransomware attacks, says Sophos report
MacOS ‘CrashStealer’ malware poses as crash reporter to steal credentials
This fake Apple app can unlock your Mac’s password vault
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Hackers selling UK government login credentials on dark web amid FortiBleed campaign
New Ghost Phishing Wave Is Breaking Traditional Email Security
Defending the Authentication Flow: Device Code Phishing with Selena Larson
EvilTokens device-code phishing kit totally more evil than we all thought
BTS #77 - FortiBleed Uncovered: How Attackers Harvest Credentials from Fortinet Devices
US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
FortiBleed campaign used custom FortiGate sniffer to steal credentials
Fortinet Responds to FortiBleed Campaign
NCSC Urges Fortinet Customers to Tackle FortiBleed Fallout
FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
Fileless Phantom Stealer Targets Browser Credentials
Suspected North Korean actors use fake ‘coding assignments’ to steal crypto
Google fires sueball at alleged Chinese phishers over AI-powered fraud ops
INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator
Suspected North Korean actors use fake ‘coding assignments’ to steal crypto
France probes compromise of gov messaging platform after account hijack
AI brands as bait: How threat actors are using the AI hype in social engineering
North Korean Hackers Use Fake Coding Tasks to Steal Crypto
Election threats are focused on campaign systems, not voting machines
AI helps Russian-speaking GreyVibe run five parallel attack chains on Ukrainian targets
Security experts caution MFA alone can no longer stop threat actors
One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign
Ukraine identifies infostealer operator tied to 28,000 stolen accounts
[local] Windows Snipping Tool - NTLMv2 Hash Hijack
Over 70% of organizations hit by identity breaches
1 in 8 employees have sold company logins or know someone who has
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
"AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts
Email threat landscape: Q1 2026 trends and insights
Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
Microsoft: QR code, CAPTCHA-gated phishing more than double in Q1 2026
Federal charges filed against teen hacker allegedly part of Scattered Spider
Email threat landscape: Q1 2026 trends and insights
New Windows flaw stems from incomplete fix for APT28-exploited bugs
Cursor Extension Flaw Exposes Developer API Keys
Experts: Amplification of opportunistic cyberattacks central to Iran's strategy
BlackFile hackers target retail, hospitality with vishing and data extortion
BlackFile actively extorting data-theft victims in retail and hospitality sector
UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware
Scattered Spider co-conspirator pleads guilty
Over $12M stolen in North Korean crypto heist against web developers
Scottish man pleads guilty to attack spree that created Scattered Spider’s notoriety
macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets
Tycoon 2FA relinquishes crown to similar PhaaS platforms
British Scattered Spider Hacker Pleads Guilty in the US
Scot becomes second Scattered Spider-linked crook to plead guilty in US
FBI takedown of W3LL phishing service leads to developer arrest
The silent “Storm”: New infostealer hijacks sessions, decrypts server-side
Critical Marimo pre-auth RCE flaw now under active exploitation
Microsoft: Canadian employees targeted in payroll pirate attacks
New VENOM phishing attacks steal senior executives' Microsoft logins
Russian hacking group targets home and small office routers to spy on users
The Trojan horse of cybercrime: Weaponizing SaaS notification pipelines
Detecting CI/CD Supply Chain Attacks with Canary Credentials
New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs
Venom Stealer Raises Stakes With Continuous Credential Harvesting
Cybercriminals Exploit Tax Season With New Phishing Tactics
Russian APT Star Blizzard Adopts DarkSword iOS Exploit Kit
TA446 Deploys Leaked DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
Hackers Exploit Compromised Enterprise Identities at Industrial Scale, Warns SentinelOne
AI Speeds Attacks, But Identity Remains Cybersecurity’s Weakest Link
Silver Fox Cyber Campaigns Show Shift Toward Dual Espionage
“Mirax Bot” Android Malware Enables Remote Banking Fraud
Lightning-fast exploits make it essential to patch fast, ask questions later
CISA urges IT to harden endpoint management systems after cyberattack by pro-Iranian group
When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures