Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Apple Warns Users to be Wary of Unsolicited FaceTime Calls

Apple is warning users to be wary of unsolicited FaceTime calls amidst a wave of scams impersonating Apple Support, Malwarebytes reports. The scammers inform the user that there’s been fraudulent activity or a technical problem associated with their account, and trick the victim into handing over payment card details, banking credentials or Apple ID logins.

Evil Twin Attack: What It Is, How It Works, and Why Your Customers Are the Target

An evil twin attack is a man-in-the-middle attack in which an attacker creates a rogue wireless access point that impersonates a legitimate network. Victims connect believing the network is genuine, allowing the attacker to intercept traffic or present fraudulent login experiences designed to capture credentials. Evil twin attacks have traditionally been treated as wireless-security incidents. For enterprises with large customer bases, however, the consequences extend well beyond the network layer.

The Fuyao Enterprise: Building an Ad-Fraud Empire with AI and Kids' Coding Blocks

In this post, we will uncover the “Fuyao Enterprise,” a previously unknown, sophisticated and highly modular botnet operating within Android TV boxes. This operation marks a shift in modern ad-fraud, where automated bots fake both clicks and views to defraud advertisers and ad-networks. While deploying novel tactics and techniques, Fuyao managed to escape public research for several years. Now, its operators openly advertise their network of over 120,000 “AI digital humans.".

How to Protect Yourself from Online Scams and Cyber Threats

The internet has become a huge part of our daily lives, from banking and shopping to connecting with friends and family. While this digital integration is incredibly convenient, it also exposes us to more and more sophisticated online scams. To protect your digital assets, you need to stay alert and understand the threats out there. This guide offers practical steps to help you navigate the online world safely and avoid common problems.

Majority of Organizations Hit by Targeted Impersonation Attacks

Fifty-three percent of organizations have had an executive or employee impersonated in targeted social engineering attacks over the past year, according to a new report from Outtake. Just over half of this impersonation activity took place on social media platforms using fake profiles, followed by video platforms.

Securing Digital Identities Against Emerging Cyber Threats

As more of our lives move online, from banking and shopping to using government services, our digital identity has become incredibly valuable. Protecting it isn't just about using a strong password anymore. Cybercriminals are using more advanced tactics, which means security measures constantly need to evolve to keep up. This includes developing better threat detection systems, using multi-factor authentication, and adding subtle protections like browser checking to confirm who a user is.

Securing Your Data Pipeline from Internal Threats

When organisations design security strategies, they often focus on building a fortress to keep external threats out. However, some of the biggest risks to data integrity don't come from outside; they start within. Securing a data pipeline, the complex system that moves information from source to destination, needs strong defences against internal threats, whether they're intentional or accidental.

What Indian Banks Can Teach Every Enterprise About Real-Time Fraud Pressure

Organisations are discovering that trust decisions now must happen before certainty arrives. Ajay Biyani, Senior Vice President, APJ, Securonix Most executives assume the most important fraud decisions happen after an incident. Inside a modern bank, many of the most important decisions happen much earlier.

AI Threat Intelligence vs. Traditional Threat Intelligence: A Practical Guide for CISOs

Most CTI programs aren’t failing because analysts lack skill. They’re failing because signal volumes have outpaced what any manual workflow can process. Thousands of newly registered domains, phishing kit variants, and brand impersonation attempts surface daily. Human teams can’t triage all of it. Threat intelligence automation addresses the throughput problem by automating collection, enrichment and prioritization so analysts spend time on decisions, not data wrangling.

Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo

Scammers can use AI tools to find your location in photos you post to social media, according to researchers at McAfee. This information can then be used in targeted social engineering attacks. The researchers found that free AI models can correctly identify a photo’s location with around 90% accuracy.

The MemcycoFM Show: Ep 27 - What Is Agentic Threat Intelligence?

In the recently published blog from Memcyco titled "What Is Agentic Threat Intelligence?", we discussed agentic threat intelligence as an emerging CTI model. Bounded agents support repetitive investigation work, such as collection, enrichment, prioritization, and evidence packaging, while analysts retain control over takedown and escalation decisions. Vendor briefings are full of “agentic AI” right now. Most of them describe the same thing: faster dashboards and smarter alerts. That is not agentic threat intelligence.

How Threat Intelligence Automation Helps Security Teams Prioritize External Threats

Phishing sites now live for under 24 hours. By the time a manual review cycle completes, the credential harvesting is done. That window is why threat intelligence automation has moved from a nice-to-have to an operational necessity for security and fraud teams managing external threats. Threat intelligence automation solves the prioritization problem by enriching raw signals before they reach analysts.

The MemcycoFM Show: Ep26 - From Brand Impersonation to Account Takeover: The ATO Attack Chain

In the recently published blog from Memcyco titled "From Brand Impersonation to Account Takeover: The ATO Attack Chain" we discussed how brand impersonation attacks operate as a fast-moving sequence from lookalike domains and cloned pages to credential harvesting and account takeover, why traditional brand monitoring and domain takedown tools consistently miss the exposure window, and how real-time signal correlation can connect impersonation indicators directly to fraud and authentication workflows before the attack concludes.

Identity Verification Software: Why It Matters for Secure Digital Onboarding

As more financial services, lenders, fintech firms, and digital businesses move customer journeys online, identity verification has become a critical part of building trust. Customers expect fast onboarding, but organisations also need to prevent fraud, meet compliance obligations, and protect sensitive data. This is where identity verification software plays an important role. It helps businesses confirm that customers are who they claim to be while keeping the process efficient, secure, and user-friendly.

Behind the Fake Tax Notice - Part II: ValleyRAT Unmasked

In Part I of this series — “Behind the Fake Tax Notice” — the Foresiet Threat Intelligence Team mapped a multi-country, tax- and invoice-themed phishing network built around hxxps://adresesvip/. That infrastructure, hosted on Alibaba Cloud in Hong Kong, was used to target taxpayers across India, Germany, Malaysia and Japan. The first report documented the lure, the sender and the hosting, but left one question open: what does the campaign actually deliver?

How Brand Impersonation Leads to Account Takeover (ATO)

Brand impersonation and account takeover (ATO) are often treated as separate security problems. One is viewed as a phishing or brand abuse issue. The other is viewed as an authentication or fraud issue. Attackers often see them differently. Many ATO attacks begin long before a login attempt appears on a dashboard. They begin when a customer encounters a fake website, fraudulent search result, impersonating social media profile, cloned mobile app, or spoofed communication that appears legitimate.

Fake Tax Notice Phishing: How the Cross-Border Scam Network Operates

Foresiet identified adreses[.]vip as part of a localized phishing infrastructure cluster using tax, invoice, payroll, and document-download themes. The strongest evidence supports malicious phishing infrastructure and campaign-level clustering; named-actor elevation remains evidence-weighted and under active validation.

Candidate verification: Stop fraud before it enters your workforce

Sophisticated fraudsters are now targeting the recruiting process. Whether it's a "fake" candidate built on synthetic data, an interviewee hiding behind a deepfake, or a candidate getting a friend to take their technical test, hiring teams are facing a fraud crisis.

New pattern analysis techniques to defend against fraud

Sophisticated fraudsters scale systems to increase their ROI. But it’s also a weakness that you can exploit to shut down fraud rings and keep attacks from scaling. In this discussion, fraud experts Nisreen Hussain, Irfan Faizullabhoy, and Ashley Fang show off how pattern and link analysis stop AI-powered fraud, account takeovers, and large fraud rings.

Gen. AI used to mislead victims in fraud campaigns

It is almost impossible to trust the source of an image or video anymore. On The Cybersecurity Defenders Podcast, Tamas Kadar, CEO and Co-Founder of SEON, explains how generative AI has reshaped what fraudsters can pull off. Setting up sophisticated fraud operations no longer requires coding skills, and synthetic identities and deepfake documents have become convincing enough that visual verification alone is no longer reliable.