Posts tagged with “phishing”

Astrana data breach disclosed to SEC after phone spoofing

US healthcare technology company Astrana has told the Securities and Exchange Commission (SEC) that attackers gained access to its servers and made off with private or confidential information. The company describes the incident as material to its financial position.

The filing, submitted on Tuesday evening, makes Astrana the latest in a string of healthcare tech firms to disclose a cyberattack to the US markets regulator in recent months.

Spoofed phone number opened the door

According to the report, the intrusion did not start with a software flaw. It started with a phone call. The attackers posed as Astrana staff and spoofed the company's main corporate telephone number, so calls to employees appeared to come from a trusted internal line.

Read More


RemControl Android banking malware hits Europe and Canada

A newly discovered Android malware-as-a-service (MaaS) platform called RemControl is going after banking customers in Europe, Canada and the Middle East. According to Group-IB, the malware spreads through malvertising campaigns that impersonate TVTap, an IPTV streaming app.

Researchers say the infrastructure behind RemControl has been running since at least May. The first samples appeared in July and already carried more than 30 phishing overlays built to capture banking credentials. Targeted countries include Italy, France, Spain, Poland and Portugal, as well as Canada and several Middle Eastern states.

Fake Google Play pages and ad-driven traffic

Victims land on fake Google Play pages that pose as the TVTap download. At least one Italian campaign used geofencing and checked mobile User-Agent strings, so only visitors who matched the intended profile would see the malicious content.

Read More


third-party.com placeholder domain now serves ClickFix

The domain third-party.com, a common stand-in for external websites in developer documentation and code samples, is now hosting a fake Cloudflare verification page. The page tries to trick Windows users into running malicious PowerShell commands.

Manifold Security spotted the page while reviewing public AI skills and MCP (Model Context Protocol) server documentation that referenced the domain. BleepingComputer later confirmed the findings.

Developers have long used third-party.com the way they use example.com, to represent some arbitrary outside site, API or service. There is one important difference. IANA, the body that manages key internet naming resources, reserves example.com, example.net and example.org for documentation, and they cannot be registered or transferred. third-party.com has no such protection. It is an ordinary registered domain, and whoever owns it decides what it serves.

Read More


SalesBleed flaws let attackers hijack Salesforce Agentforce

Researchers at Zenity Labs have disclosed three vulnerabilities in Salesforce Agentforce, the company's platform for AI agents. Attackers could have abused the flaws to turn trusted agents against their own organizations. The agents could be made to leak sensitive customer relationship management (CRM) data or to send phishing messages to employees.

The researchers call the set of bugs SalesBleed. According to Zenity Labs, two of the flaws allowed zero-click data exfiltration. The third let an attacker weaponize an Agentforce agent to spread phishing inside a company.

Zenity Labs reported the issues to Salesforce on June 1. Salesforce confirmed that all three had been fixed by August 19.

Read More