Menlo Security’s report reveals a significant increase in browser-based phishing attacks and zero-hour phishing attacks, driven by factors such as browser reliance, zero-day vulnerabilities, advanced phishing tools, and generative AI adoption. Criminals are leveraging AI to create realistic phishing websites and automate targeted attacks, with fake AI sites also distributing infected files on mobile devices. The rise of AI-driven cyber fraud poses a challenge in distinguishing between legitimate and malicious sites, emphasizing the importance of recognizing common phishing scams and verifying the authenticity of emails and websites before sharing sensitive information.
Full Article
CVE-2025-24054 Under Active Attack—Steals NTLM Credentials on File Download
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a medium-severity security flaw, CVE-2025-24054 (CVSS score: 6.5), to its Known Exploited Vulnerabilities (KEV) catalog due to reports of its active exploitation. This vulnerability pertains to Windows New Technology LAN Manager (NTLM) hash disclosure. CISA's action underscores the importance of addressing potential security risks in Microsoft Windows systems. Full Article
Read more