CoFense Scam News.
Cofense Cofense
- Cybersecurity Awareness Month – 4 Key Tactics to Prevent Phishingby Cofense on October 8, 2025 at 5:00 am
October is Cybersecurity Awareness Monthāthe ideal time to focus on education and strengthening your defenses against phishing. Embracing good cybersecurity habits in daily life not only enhances safety but also makes managing personal and business tasks easier and less stressful. To help bolster your organizationās security, Cofense Intelligence recommends four key tactics.
- Phishing from Home ā The Hidden Danger in Remote Jobs Lurking in Tesla, Google, Ferrari, and Glassdoorby Cofense on October 7, 2025 at 5:00 am
In Q3 2024, the Cofense Phishing Defense Center (PDC) identified a phishing campaign that impersonated several Fortune 500 companies by targeting individuals in social media and marketing positions through fake job applications. Earlier this year, the team researched how resume details have become valuable tools for threat actors in a blog titled āJob Application Spear Phishing.ā Since then, the PDC has continued to monitor the use of this tactic by threat actors who have begun utilizing other well-known brands as well as refining their techniques to further deceive potential victims.
- Phishing Defense and Data Control: Why Transparency Mattersby Cofense on September 30, 2025 at 5:00 am
Artificial intelligence is rapidly transforming how we protect our digital lives. AI-powered phishing defense tools promise to be smarter, faster, and more effective at stopping threats. But as we rely more on these advanced systems, itās important to look critically at the way they work and how they store our data. Ā
- Inside Vietnamese Threat Actor Lone Noneās Copyright Takedown-Spoofing Campaignby Cofense on September 24, 2025 at 5:00 am
Cofense Intelligence has been tracking a series of Copyright-themed campaigns conducted by the Lone None threat actor group. This Strategic Analysis will look at this campaignās current TTPs (tactics, techniques, and procedures) and IOCs (indicators of compromise) while also highlighting how this campaign has evolved.Ā
- Dual Threat: Threat Actors Combine Credential Phishing and Malwareby Cofense on September 10, 2025 at 5:00 am
Credential phishing and malware are often considered mutually exclusive; it is generally assumed that an email either delivers credential phishing or malware. While this is typically the case, several recent high-impact campaigns have combined credential phishing and malware delivery.
- From Hours to Seconds: Vision 3.0 Transforms Phishing Incident Responseby Cofense on August 28, 2025 at 5:00 am
As threat actors weaponize generative AI to craft increasingly sophisticated phishing attacks, security teams need more than traditional defenses to stay ahead. Enter Cofense Vision 3.0, our latest evolution in phishing threat detection and response technology.Ā
- Phishing Kits Uncovered: Methods and Tactics Used to Evade SEGs, Sandboxes, and Analystsby Cofense on August 27, 2025 at 5:00 am
Threat actors use many methods to avoid detection and complicate the analysis of their credential phishing pages and campaigns.
- Phishing in the Cloud: SendGrid Campaign Exploits Account Securityby Cofense on August 21, 2025 at 5:00 am
The Cofense Phishing Defense Center (PDC) has recently observed a new wave of credential harvesting attacks involving phishing emails sent via SendGrid. The campaign exploits the trusted reputation of SendGrid, a legitimate cloud-based email service used by businesses to send transactional and marketing emails. By impersonating SendGridās platform, attackers can deliver phishing emails that appear authentic and bypass common email security gateways. The campaign delivers the attack through three differently themed emails, each crafted to create a sense of urgency in both the subject line and body. The emails also use spoofed sender addresses, making them appear as if they genuinely originated from SendGrid
- Cofense Unveils Vision 3.0 with Sub-Minute Threat Containment Capabilities and Deeper Insightsby Cofense on August 19, 2025 at 5:00 am
Now supporting hybrid environments, Vision 3.0 introduces āWho Clickedā to track and identify user engagement with phishing emails for faster, more targeted response
- This ‘SAP Ariba Quote’ Isn’t What It SeemsāIt’s Ransomwareby Cofense on August 14, 2025 at 5:00 am
Ransomware has long been a staple among threat actors, and the attacks often garner large media coverage. Ransomwares such as WannaCry and NotPetya dominated both the cyber news and broader reporting landscape for months on end.
- Personalization in Phishing: Advanced Tactics for Malware Deliveryby Cofense on August 13, 2025 at 5:00 am
Subject customization is widely used in targeted malware phishing campaigns to make the email appear more authentic and increase the chances of the malicious payload being run. When combined with Remote Access Trojans (RATs) or Information Stealers, threat actors can easily obtain remote access or credentials. In this blog, Cofense Intelligence outlined the top 5 most prevalent themes associated with malware-delivery emails where subject customization was included. These themes include categories such as Travel Assistance, Response, Finance, Taxes, and Notification. Ā
- Google Redirect Abuse in 2024: Key Trends & Tacticsby Cofense on July 30, 2025 at 5:00 am
Threat actors have increasingly exploited Google AMP and Google redirect methods to bypass security defenses, leveraging Google’s reputation to mask malicious content from detection. Despite improved security measures, the quarterly volume of Google AMP abuse has remained consistently high, with attackers adapting by using varied Google URL paths, TLDs, and even services like Google Maps and Translate for redirects.Ā