Cyren Security Blog

Delve into the world of cybersecurity and cybercrime as Cyren experts explore the latest threats targeting businesses, as well as industry trends and technological advances, and how these pressures, risks, and changes impact business reputation and growth.

Subscribe to this Blog

Office 365 Top Brand Targeted by Phishing Kits in 2018

by

Phishing Security Research & Analysis

Criminals are nothing if not financial opportunists, and the boom in phishing has been like a cybercrime gold rush: While some are panning for gold, others are selling the tools and equipment. In 2018, the underground phishing economy has come of age, with the evolution of phishing kits offering spoofed web pages – basic ‘equipment’ for any phishing attack – a prime example. “Phishing-as-a-Service” has ushered in a new era of sophistication and access for the low-level cybercriminal – democratizing phishing attacks.  What used to take a team of skilled designers, developers, and hackers to architect, build and deploy can now be purchased on the internet for as little as fifty bucks, or rented as a turn-key service for roughly the same amount a month.

Office 365 Security Budgets Increase to Stop Phishing

by

Email Security Phishing Security Research & Analysis

With 78 percent of businesses that utilize Office 365 reporting one or more successful cyberattacks this year, it’s not surprising that IT managers at over half of Office 365-enabled organizations also say they’ve increased their security spending by a robust average 18 percent compared to 2017. 

Evasive Phishing is Targeting Office 365

by

Phishing Security Research & Analysis

Phishing emails targeting Office 365 customers are increasing dramatically and are the top source of security breaches, according to an Osterman Research survey commissioned by Cyren. Fifty-four percent of organizations using Office 365 as their corporate email platform reported at least one successful phishing attack during the past 12 months, although usually far more than one—the average number of phishing breaches reported was 11.7. 

Fileless Malware Already Targeting Holiday Suppliers

by

Security Research & Analysis Threat Analysis

It gets earlier and earlier every year. The first Yuletide-related malware campaign has already been spotted. There’s always an expected and monumental amount of consumer spam and phishing in the run-up to Black Friday and then Christmas itself, but we’ve found one malware author getting into the Christmas “spirit” in late October by targeting backdoor-delivering emails at the Yuletide supply chain, specifically Christmas goods suppliers whose preparations for the year-end commercial convulsion are well underway.

Not-Really-Password-Protected Evasion Technique Resurfaces

by

Security Research & Analysis Threat Analysis

Today we came across an e-mail with an Excel Workbook attachment, which upon first inspection appears to be password-protected. The presence of the EncryptedPackage stream in an OLE2 document indicates that it is protected by a password, which obviously would require the user to enter one in order to open the document properly. Or at least that’s what the bad guys would like email or AV scanners to think. 

Police Phishing Attack Targets Bank Credentials

by

Phishing Security Research & Analysis Threat Analysis

An email impersonating the Icelandic police was sent to thousands of Icelanders this past weekend, falsely requesting the recipient come in for questioning.