News

Latest news on the subject of B2B cyber security >>> PR agencies: Add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

AI-based identity theft continues to rise
AI-based identity theft continues to rise

Access data is very popular with cyber criminals. They are increasingly using artificial intelligence to steal it. Attacks based on deep fake technology are on the rise. The result is that online users are becoming more and more suspicious of digital content. Therefore, providers of online services must take security precautions to protect against identity theft. If they want to commit identity fraud, cyber criminals are increasingly relying on artificial intelligence. The quality and quantity of attacks can be significantly increased and costs and workload can be noticeably reduced. In 2025, phishing, spear phishing and social engineering attacks are therefore expected to once again be among the most popular...

Read more

APT group TA397 attacks defense companies
B2B Cyber ​​Security ShortNews

Security experts have analyzed a new attack by the APT group TA397 - also known as "Bitter" - in more detail. As is often the case, it started with a special spear phishing email with an attachment. It contained a shortcut file and malicious PowerShell code. The attack was directed against an organization in the Turkish defense industry and took place in November 2024. The cybercrime group, which is known for espionage attacks in Europe and the Asia-Pacific region, used new attack methods that further developed its previous tactics, techniques and procedures (TTPs). In particular, the use of alternative data streams (ADS) within RAR archives is...

Read more

Chinese attacks on OpenAI
B2B Cyber ​​Security ShortNews

In 2023, the threat actor SweetSpecter, presumably based in the People's Republic of China, first made headlines. At that time, his cyber attacks targeted political institutions in the Middle East, Africa and Asia. Now he has found a new target: the AI ​​company OpenAI. OpenAI has announced that some of its employees have been the target of a spear phishing attack campaign. No damage was caused. The company's security teams recognized the attack in time and the implemented security architecture held up. For his spear phishing attack, SweetSpecter sent emails with malicious attachments to OpenAI employees - both...

Read more

Manufacturing: Victims of Credential Harvesting Attacks
Manufacturing companies: victims of credential harvesting attacks

Cybercriminals are targeting the Microsoft login data of US and Canadian manufacturing companies. A provider of cybersecurity solutions has uncovered the attacks and recommends preventive measures. BlueVoyant's Threat Fusion Cell (TFC) has uncovered a new attack campaign aimed at modern US and Canadian manufacturing companies. Attackers are using credential harvesting to try to steal the Microsoft login data of employees of the affected companies. It is quite conceivable that the attack scenario could be adapted to modern European manufacturing companies - but also European companies in other sectors. BlueVoyant therefore advises caution - and more precaution. It all starts with a...

Read more

Spearphishing from North Korea
B2B Cyber ​​Security ShortNews

The US government warns of threat actors from North Korea. As a result, they use weak email DMARC (Domain-based Message Authentication Reporting and Conformance) settings to send fake spearphishing emails as if they came from a legitimate email address. “We have observed that North Korean threat actors like APT43 are exploiting the flawed DMARC configurations to easily spoof well-known institutions at major universities, think tanks and NGOs. This allowed them to target prominent facilities in specific areas and collect high-priority intelligence for the North Korean regime. They did this by stealing the email addresses of legitimate users from legitimate…

Read more

State-sponsored cyberattacks
B2B Cyber ​​Security ShortNews

A report from the European Union IT Emergency Response Team (CERT-EU) reports a high number of state-sponsored spear phishing attacks against European Union institutions in 2023. The attacks appear to have been carried out primarily by hackers and groups associated with or supported by state actors. The report finds that spear phishing continues to be the most commonly used method by state-backed cybercriminal groups when attempting to penetrate target networks. The spear phishing method underlying the attacks involves highly targeted and personalized email campaigns that...

Read more

Targeted email attacks on energy and utilities sectors
Targeted email attacks on energy and utilities sector - Image by Sergio Cerrato - Italia on Pixabay

Successful attacks on energy and utility companies such as Colonial Pipeline or Ukrainian Energy Utilities show how far-reaching an attack can be. In many cases, the first steps of the attack take place via sophisticated email attacks. Energy and utility companies are increasingly using digital technologies to manage and integrate complex distributed operations and remote locations such as wind farms, power plants and grids. Successful attacks on energy and utility companies show how far-reaching their impact can be. One example is the May 2021 ransomware attack on Colonial Pipeline, the largest fuel pipeline in the United States. This resulted in a ransom payment of...

Read more

Healthcare is a prime target for email attacks
Healthcare is a prime target for email attacks

In one survey, the healthcare industry experienced more email security breaches than average. The recovery costs following such attacks are particularly problematic for the healthcare system. Ransomware attacks on healthcare organizations have more than doubled since 2022, according to the latest Barracuda Ransomware Annual Report. However, when you look at healthcare in comparison to other industries, a more complex picture emerges, says Dr. Klaus Gheri, Vice President & General Manager Network Security at Barracuda Networks. In many cases, this sector experiences fewer major cyber incidents than other industries…

Read more

DACH: 55 percent victims of spear phishing
DACH: 55 percent victims of spear phishing

In the DACH region, 55 percent of companies have been victims of a spear phishing attack in the last 12 months, according to the new Barracuda Networks Spear Phishing Trends Report 2023. DACH was thus slightly above the average in an international comparison (50 percent). In addition, 24 percent of all companies had at least one email account affected by an account takeover. Cyber ​​criminals send an average of 370 malicious emails from each compromised account. The report includes Barracuda spear phishing data and analysis based on a dataset covering 50 billion emails across 3,5 million mailboxes, including nearly 30 million spear phishing emails. In addition…

Read more

Successful phishing thanks to AI
B2B Cyber ​​Security ShortNews

A study shows how successful AI-generated cyber attacks already are. The greatest danger lies in the easy scalability of spear phishing attacks - both in terms of quantity and quality. In addition to a lot of encouragement for the current developments in the field of artificial intelligence (AI), some critical voices have also been raised in recent weeks. Cybersecurity experts, including those at SoSafe, Europe's leading provider of security awareness and training, have long warned of the possibility that generative AI could write better phishing emails than humans can. Initial studies* by SoSafe now show that…

Read more