Avanan Blog Attack Briefs (22)


PhishGun: How Phishing Attacks From Services Like Mailgun Bypass Microsoft 365 Security

Avanan researchers have identified a new attack form whereby adversaries leverage reputable Email Delivery Services (EDS) to launch and obfuscate their attacks again...

Read more

A Microsoft Swing and a Google Miss: Spoofed Pages Get to the Inbox

Credential harvesting is one of the most popular attack forms out there. It's simple. Get a user to click on a link. At the link, get them to enter their information...

Read more

Lucky Penny: Missing ATM Card Attack Bypasses Scanners

Believe it or not, the classic Nigerian Prince scam is still around and still kicking. In 2018, Americans lost over $700,000 to the scam. Yikes.

Read more

Hidden Meaning: Using Obfuscation to Fool Natural Language Processing

A rapidly increasing attack campaign is hitting inboxes.

Read more

We Shouldn't Transfer: Getting End-Users to Give Over Credentials

You may have heard about the recent Accellion breach. Accellion, a file-sharing app, was breached and now tons of universities and corporations have been hit. Major ...

Read more

When a Legitimate Pension Fund Uses Fraudulent Phishing Tactics

Avanan researchers have discovered an interesting “marketing” campaign from a legitimate company that leverages pension fund fraud tactics normally used in phishing ...

Read more

Can I Have Some More? Blatant Financial Scam Makes Way to Inboxes

Avanan researchers have uncovered a widespread financial scam attack. The attack aims to get sensitive bank and financial information from the victim.

Read more

ZeroFont Phishing: Three Years Later, the Attack Form is Still Out There

Back in 2018, Avanan uncovered an attack we called ZeroFont phishing. The idea is that hackers insert hidden words into the text with a font size of zero. The recipi...

Read more

Flipping Out: Hackers Hijack Legitimate File Service to Reach Inboxes

Avanan researchers have uncovered a specific attack that was seen 282 times across 18 different environments in the past two weeks. This attack leverages Flipsnack, ...

Read more

Bad Check: Another Malicious Invoice Gets Through

Another day, another invoice scam. This time the fake invoice is actually a malicious HTML file. Despite this being a very basic credentials harvesting attack it was...

Read more

14-Day Free Trial – Experience the power and simplicity of Avanan Cloud Security.   Start Free Trial