Fraud Starts at Home

Virgin Money warns consumers to be vigilant against scams this festive season, stressing personal responsibility and simple security measures. Their head of fraud highlights that individuals are the first line of defense, advising to trust instincts, secure devices, and avoid sharing sensitive information. Research shows various fraud types target different generations, with a notable increase in online scams. Customers are urged to verify sources and check for website security before sharing payment details. The bank emphasizes common sense as key to staying safe online.

https://www.creditstrategy.co.uk/knowledge-hub/fraud-starts-at-home

Major Leak Reveals One of the Largest Lead-gen Databases Ever Exposed

A major data leak exposed 4.3 billion records, including LinkedIn-derived personal information, due to an unprotected MongoDB database. Researchers discovered 16TB of data, with details like emails, employment histories, and personal profiles. The leak poses significant security risks, enabling targeted phishing and social engineering attacks, as attackers can exploit this structured and current data. The incident underscores vulnerabilities in data management practices and highlights growing threats from extensive data leaks.

https://cybernews.com/security/database-exposes-billions-records-linkedin-data/

15+ Retail Cybersecurity Statistics for 2026: Threats and Protection

Retailers increasingly face cyber risks with data breaches averaging $10.22 million in the US. High transaction volumes, sprawling systems, and third-party dependencies make them prime targets. Major threats include phishing, malware, ransomware, and supply chain vulnerabilities. To combat these, retailers must adopt robust security measures, educate staff, and continuously monitor systems. Recent breaches, like those affecting Forever 21 and Neiman Marcus, highlight the need for strong risk management and third-party oversight.

https://www.shopify.com/enterprise/blog/retail-cybersecurity

Beware: PayPal Subscriptions Abused to Send Fake Purchase Emails

PayPal subscriptions are being exploited in a scam where fake purchase emails are sent, misleading people into believing they made expensive transactions. The emails, appearing legitimate, originate from “[email protected]” and include modified customer service URLs displaying fake purchase notifications. Scammers intend to instill fear, prompting recipients to call a fake PayPal support number. Although legit email formats are used, PayPal is working to mitigate this scam. Recipients are advised to ignore such emails and verify their account directly through PayPal.

https://www.bleepingcomputer.com/news/security/beware-paypal-subscriptions-abused-to-send-fake-purchase-emails/

Stop Hacklore!

Hacklore merges hacking and folklore, spreading digital safety myths rather than facts. Its aim is to debunk these myths for better understanding of real threats and effective safety measures, such as software updates and strong passwords. Emphasizes accurate, actionable advice for everyone.

https://www.hacklore.org/

AI Poisoning: Black Hat SEO Is Back

Black Hat SEO, once diminished by advancements in Google algorithms, is resurfacing through AI manipulation. Research shows just 250 malicious documents can contaminate large language models (LLMs), enabling bad actors to distort AI responses about brands. This “AI poisoning” risks misrepresenting companies in comparisons and could damage reputations. Brands must maintain vigilance by monitoring AI outputs related to their name and addressing suspicious online activity to prevent potential poisoning. Despite the temptation to exploit loopholes for a competitive edge, ethical content creation remains essential for long-term success.

https://www.searchenginejournal.com/ai-poisoning-black-hat-seo-is-back/561217/

New Advanced Phishing Kits Use AI and MFA Bypass Tactics to Steal Credentials at Scale

TLDR: New phishing kits like BlackForce, GhostFrame, InboxPrime AI, and Spiderman use advanced tactics, including AI and MFA bypass, to steal credentials at scale. BlackForce targets brands, GhostFrame hides in iframes, InboxPrime automates email campaigns, and Spiderman replicates bank pages for European targets. These innovations make phishing attacks easier to execute and more difficult to detect.

https://thehackernews.com/2025/12/new-advanced-phishing-kits-use-ai-and.html

UK Fines LastPass £1.2 Million for Data Breach Affecting 1.6 Million People

UK fines LastPass £1.2 million for 2022 data breach affecting 1.6 million users. Two attacks compromised employee data, leading to access of encrypted user information. ICO criticized LastPass for inadequate security measures. No evidence passwords unencrypted but concerns remain about hackers cracking vaults. LastPass acknowledges shortcomings, focusing on enhancing data security.

https://therecord.media/uk-fines-lastpass-over-1-million-data-breach

The Biggest Catch: How Whaling Attacks Target Top Executives

Whaling attacks target senior executives, exploiting their time constraints, online visibility, and access to sensitive information. Attackers often use phishing tactics, enabling them to execute large financial frauds. AI enhances these threats by facilitating data gathering and creating convincing communication. Mitigation strategies include personalized training, strong approval processes for fund transfers, and robust email security measures. Protecting against whaling not only safeguards financial assets but also corporate reputations.

https://www.welivesecurity.com/en/business-security/big-catch-how-whaling-attacks-target-top-executives/

New ConsentFix Attack Hijacks Microsoft Accounts Via Azure CLI

ConsentFix attack hijacks Microsoft accounts via Azure CLI without passwords or MFA. It tricks users into submitting OAuth codes through a fake CAPTCHA on compromised sites, giving attackers full access to accounts using Azure authentication. Monitoring for unusual Azure CLI activity is recommended to detect this threat.

https://www.bleepingcomputer.com/news/security/new-consentfix-attack-hijacks-microsoft-accounts-via-azure-cli/

HTTPS Certificate Industry Phasing Out Less Secure Domain Validation Methods

Google is phasing out less secure domain validation methods for HTTPS certificates to enhance internet security. This involves retiring 11 outdated validation practices like email and phone-based verifications, which are vulnerable to attacks. The transition will be gradual, fully implemented by March 2028. The goal is to adopt stronger, automated validation methods that ensure certificates are issued only to legitimate domain owners, ultimately making the web safer for all users.

https://security.googleblog.com/2025/12/https-certificate-industry-phasing-out.html

New DroidLock Malware Locks Android Devices and Demands a Ransom

New DroidLock malware targets Android users, locks screens for ransom, and can access personal data. It spreads via fake apps, gaining permissions to control devices. It can wipe data, change passwords, and threaten file destruction. Android users are advised to avoid sideloading apps and check permissions.

https://www.bleepingcomputer.com/news/security/new-droidlock-malware-locks-android-devices-and-demands-a-ransom/

Fighting Payment Fraud With AI

AI combats rising payment fraud effectively, adapting rapidly to evolving threats. Traditional fraud defenses struggle against sophisticated attacks, leading to increased false declines that harm customer loyalty. Businesses are turning to AI for more accurate, real-time fraud detection, which boosts legitimate transactions and reduces losses. AI-enabled systems analyze vast data for nuanced risk scoring, transforming fraud prevention into a strategic growth tool. Investing in AI is essential for safeguarding revenue and enhancing customer experience.

https://www.independent.co.uk/news/business/business-reporter/payment-fraud-ai-cyber-attacks-security-b2881360.html

Scroll to Top