Exotic files: unexpected sources of cyberthreats
We break down the file formats that can be unfamiliar to some users, and that aren’t always scanned by security solutions but can still pose cyberthreats.
3933 articles
We break down the file formats that can be unfamiliar to some users, and that aren’t always scanned by security solutions but can still pose cyberthreats.
Handing it to a store manager or cashier, posting about it in your neighborhood chat, or just keeping it – these are common actions if a bank card is found on the street, but they’re also the wrong ones. Here’s what you should actually do.
Sketchy online stores, crypto investments promising fast returns, hidden subscriptions, and browser extensions loaded with harmful software… online scams have moved well beyond classic phishing. Here’s how to spot the websites operating in this gray area, and what kind of harm they can do.
Attackers have found yet another source of free computing resources: automotive head units. We take a look at the first malware specifically targeting cars for infection.
We revisit the key rules for setting up IP cameras and related devices so that you don’t end up starring in a reality show — whether at home, in a hotel, or in rented accommodation.
Steam forums are the latest battleground for ClickFix attacks. We break down how attackers disguise themselves as helpful commenters to trick gamers into installing a crypto miner on their PCs.
How one “cybersecurity expert” published 445 books on Amazon in a single year — and what that means for anyone trying to learn something real in the age of AI slop.
Visit a familiar website, and along with the usual ad banner you could pick up a script that steals cryptocurrency. How can you protect yourself from attacks delivered through online ads?
Attackers are crafting files that devices can read as two different document types at once, and using these “nesting dolls” to smuggle in malware. How to detect and neutralize these two-faced files?
Our experts investigated which file extensions cybercriminals use most in their email blasts. Here’s a breakdown of the most dangerous attachment types — and how to keep your devices safe from malicious files.
Japanese researchers have again tackled a classic high-tech espionage challenge: accurately identifying keystrokes based purely on how they sound.
An analysis of key characteristics of AI agent-driven cyberattacks, why open-source models are sufficient to execute them, and what measures can help defend an organization.
CrashStealer is a macOS infostealer disguised as a videoconferencing app. It abuses Apple’s own trusted mechanisms to sneak onto your computer unnoticed.
What information security issues should be addressed when migrating to a new platform?
A look into silent phone calls, how they relate to modern scam tactics, and where artificial intelligence fits in
How attackers distribute ScreenConnect under the guise of free software to deploy AsyncRAT.
ClickFix attacks, which were once seen mostly on Windows, are now spreading to macOS. We break down the mechanics of the attack, and ways to protect your device.
Did you know that live chat agents on websites can see everything — even messages you never actually sent? This post looks at how this works, and what you can do about it.
We analyze the first-ever real-world incidents where attackers targeted AI agents deployed in corporate environments.
Who sends regular hidden requests from your smartphone and why, how phone number verification works, and whether you should turn it off.
A new variation of ClickFix allows attackers to gain access to Microsoft 365 accounts. We break down how this technique works, and what threat it poses to organizations.