mitre-ta0006
231 articles with this tag
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
MEDIUM
CRITICAL
HIGH
INFO
CRITICAL
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits
Kratos phishing-as-a-service kit loses its battle with international law enforcement
New ClickLock Stealer locks your Mac until you hand over your password
New North Korean campaign uses fake coding interviews to steal developer credentials
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Stolen identities cause 79% of ransomware attacks, says Sophos report
MacOS ‘CrashStealer’ malware poses as crash reporter to steal credentials
This fake Apple app can unlock your Mac’s password vault
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Hackers selling UK government login credentials on dark web amid FortiBleed campaign
New Ghost Phishing Wave Is Breaking Traditional Email Security
Defending the Authentication Flow: Device Code Phishing with Selena Larson
EvilTokens device-code phishing kit totally more evil than we all thought
BTS #77 - FortiBleed Uncovered: How Attackers Harvest Credentials from Fortinet Devices
US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
FortiBleed campaign used custom FortiGate sniffer to steal credentials
Fortinet Responds to FortiBleed Campaign
NCSC Urges Fortinet Customers to Tackle FortiBleed Fallout
FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
Fileless Phantom Stealer Targets Browser Credentials
Suspected North Korean actors use fake ‘coding assignments’ to steal crypto
Google fires sueball at alleged Chinese phishers over AI-powered fraud ops
INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator
Suspected North Korean actors use fake ‘coding assignments’ to steal crypto
France probes compromise of gov messaging platform after account hijack
AI brands as bait: How threat actors are using the AI hype in social engineering
North Korean Hackers Use Fake Coding Tasks to Steal Crypto
Election threats are focused on campaign systems, not voting machines
AI helps Russian-speaking GreyVibe run five parallel attack chains on Ukrainian targets
Security experts caution MFA alone can no longer stop threat actors
One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign
Ukraine identifies infostealer operator tied to 28,000 stolen accounts
[local] Windows Snipping Tool - NTLMv2 Hash Hijack
Over 70% of organizations hit by identity breaches
1 in 8 employees have sold company logins or know someone who has
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
"AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts
Email threat landscape: Q1 2026 trends and insights
Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
Microsoft: QR code, CAPTCHA-gated phishing more than double in Q1 2026
Federal charges filed against teen hacker allegedly part of Scattered Spider
Email threat landscape: Q1 2026 trends and insights
New Windows flaw stems from incomplete fix for APT28-exploited bugs
Cursor Extension Flaw Exposes Developer API Keys
Experts: Amplification of opportunistic cyberattacks central to Iran's strategy
BlackFile hackers target retail, hospitality with vishing and data extortion
BlackFile actively extorting data-theft victims in retail and hospitality sector
UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware
Scattered Spider co-conspirator pleads guilty
Over $12M stolen in North Korean crypto heist against web developers
Scottish man pleads guilty to attack spree that created Scattered Spider’s notoriety
macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets
Tycoon 2FA relinquishes crown to similar PhaaS platforms
British Scattered Spider Hacker Pleads Guilty in the US
Scot becomes second Scattered Spider-linked crook to plead guilty in US
FBI takedown of W3LL phishing service leads to developer arrest
The silent “Storm”: New infostealer hijacks sessions, decrypts server-side
Critical Marimo pre-auth RCE flaw now under active exploitation
Microsoft: Canadian employees targeted in payroll pirate attacks
New VENOM phishing attacks steal senior executives' Microsoft logins
Russian hacking group targets home and small office routers to spy on users
The Trojan horse of cybercrime: Weaponizing SaaS notification pipelines
Detecting CI/CD Supply Chain Attacks with Canary Credentials
New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs
Venom Stealer Raises Stakes With Continuous Credential Harvesting
Cybercriminals Exploit Tax Season With New Phishing Tactics
Russian APT Star Blizzard Adopts DarkSword iOS Exploit Kit
TA446 Deploys Leaked DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
Hackers Exploit Compromised Enterprise Identities at Industrial Scale, Warns SentinelOne
AI Speeds Attacks, But Identity Remains Cybersecurity’s Weakest Link
Silver Fox Cyber Campaigns Show Shift Toward Dual Espionage
“Mirax Bot” Android Malware Enables Remote Banking Fraud
Lightning-fast exploits make it essential to patch fast, ask questions later
CISA urges IT to harden endpoint management systems after cyberattack by pro-Iranian group
When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures
Threat Actor Targeting VPN Users in New Credential Theft Campaign
Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials
Accertify’s Attack State targets credential stuffing and ATO attacks
Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
Undetected Discord Malware
Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks
Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale
Ransomware activity peaks outside business hours
Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens
[NEU] [kritisch] Cisco Catalyst SD-WAN Manager und SD-WAN Controller: Mehrere Schwachstellen
Steaelite RAT combines data theft and ransomware management capability in one tool
Russian group uses AI to exploit weakly-protected Fortinet firewalls, says Amazon
600+ FortiGate Devices Hacked by AI-Armed Amateur
Shai-Hulud-Like Worm Targets Developers via npm and AI Tools
Russian Cyber Threat Actor Uses GenAI to Compromise Fortinet Firewalls
Malicious Chrome extension targeting Apple App Store Connect developers through fake ASO service - full analysis
Arkanix Stealer pops up as short-lived AI info-stealer experiment
AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries
AI-augmented threat actor accesses FortiGate devices at scale
‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA
Ex-Google engineers charged with orchestrating high-tech secrets extraction
Facebook ads spread fake Windows 11 downloads that steal passwords and crypto wallets
Ukrainian gets 5 years for helping North Koreans infiltrate US firms