Phishing remains a significant and ever-evolving cybersecurity threat, with recent data showing a 28% rise in attacks between Q1 and Q2 of 2024. This trend highlights how persistent and evolving phishing tactics continue to be, impacting a staggering 94% of cybersecurity decision-makers in 2023. Attackers are increasingly using compromised internal accounts, shifting the platforms they use, and incorporating QR codes, which is becoming a new favorite way to deliver malicious content. This article describes some of the recently observed threat actor tactics as well as some tips for staying safe.
Read more…
Source: Water ISAC
Related:
- Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
October 2, 2026
Epic, the software technology giant that makes the widely used MyChart software for accessing patients’ medical data, has paused most of its product development as the company works to protect its software and systems from cyberattacks. Judy Faulkner, the founder and chief executive of Epic, told Modern Healthcare last month that the pause would likely last ...
- Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
October 2, 2026
Days after a journalist claimed that Meta’s Muse app on Mac read their private messages — a claim that Meta disputed — Apple announced that it’s introducing additional controls around a setting called “Full Disk Access” on macOS. The feature was designed to allow backups to function properly, but AI agents have now increased “the ...
- Update your iPhone, iPad, or Mac: Flaw could run attackers’ code
September 29, 2026
Apple has released updates for iPhones, iPads, and Macs to fix a flaw that could let an attacker run code when a device processes a malicious file. Apple says it may have been used in highly targeted attacks against iPhone users running versions of iOS before iOS 27. The fix is in iOS and iPadOS 26.7.1, ...
- Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack
September 25, 2026
Technology giant Kiteworks is urging customers to shut down their systems after the company received information that hackers may attempt to target them. Kiteworks (formerly Accellion), which makes tools for transferring large files and sensitive datasets over the internet, confirmed to TechCrunch that it had notified its customers about a potential threat. The news was first ...
- CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM
September 23, 2026
On September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending ...
- US proposes AI incident alert system in talks with China
September 21, 2026
Treasury Secretary Scott Bessent said Sunday the U.S. has proposed a new “notification mechanism” for artificial intelligence incidents that could affect national security, part of weekend discussions ahead of talks at the White House this week between President Donald Trump and China’s Xi Jinping. “We want a shared vision of common goals and common threats,” Bessent ...
