ClickFix on macOS: how Apple users are being scammed
ClickFix attacks, which were once seen mostly on Windows, are now spreading to macOS. We break down the mechanics of the attack, and ways to protect your device.
556 articles
ClickFix attacks, which were once seen mostly on Windows, are now spreading to macOS. We break down the mechanics of the attack, and ways to protect your device.
Who sends regular hidden requests from your smartphone and why, how phone number verification works, and whether you should turn it off.
A new variation of ClickFix allows attackers to gain access to Microsoft 365 accounts. We break down how this technique works, and what threat it poses to organizations.
How attackers gain access to corporate services without stealing passwords or cookies: we’re analyzing the Shadow Token via Remote Debug technique used in ToddyCat APT attacks.
Microsoft has addressed approximately 600 vulnerabilities in its products, affecting its entire product line — including even Minecraft Server and Age of Empires II. How can organizations handle such a volume?
Hackers have developed a PowerShell script that hijacks Telegram sessions and grants an attacker access to accounts without a password or verification codes. Here’s a breakdown of how it works and how to stay safe.
Here’s a breakdown of the latest scams to watch out for, ensuring your World Cup experience ends with great memories — not stolen money or compromised data.
Kaspersky experts have found that a single fraudulent message in a messaging app leads to an average loss of $733. We break down new AI-powered messaging scam schemes, provide platform-specific statistics, and offer tips on how to protect yourself from digital fraudsters.
We break down how cybercriminals are using fake IPTV apps to spread malware, and how you can protect your devices and data during the World Cup.
Are you sure your Android TV box is secure? Cutting corners on streaming subscriptions could turn your device into part of a botnet, leave your IP addresses up for rent, and trigger other serious headaches.
Why subscription owners need to prioritize personal and family cybersecurity.
The new VoidStealer Trojan utilizes a novel method to bypass Chrome’s App-Bound Encryption, allowing it to hijack sessions and steal user data.
We’ve discovered over two dozen phishing apps mimicking popular crypto wallets right in the official App Store. Here’s a breakdown of the new waves of attacks targeting iPhone and Mac users and their crypto holdings.
We’re breaking down why developers have moved into the crosshairs, the specific tactics attackers are using, and how to reduce the risks of company infrastructure being compromised.
How the AirSnitch vulnerability family threatens corporate networks, and what changes you need to make to your network architecture and settings to stay protected.
Kaspersky experts have detected fake websites that steal money from BTS fans during ticket pre sales. We explain how to stay vigilant and not fall victim to the scammers.
In 2025, just as in the year prior, supply-chain attacks remained one of the most severe threats facing organizations. We’re breaking down last year’s most noteworthy incidents.
How open-source security solutions became the starting point for a massive attack on other popular applications, and what organizations that use them should do.
Intellexa’s Predator spyware can hide camera and microphone usage indicators on iOS devices. Here’s a look at how it pulls it off.
We break down the BeatBanker trojan attack, which combines espionage, crypto theft, and mining with inventive ways to dig its heels into a smartphone.
Educational institutions are increasingly falling victim to ransomware attacks. We look at some real-world incidents, explain their causes, and discuss how to mitigate risks to academic infrastructure.