logo

CyberheistNews Vol 14 #18 [Wake Up Call] A Fresh Nespresso Domain Hijack Brews an MFA Phishing Scheme

ID: 6c9b4df9-87c8-51fe-8ce2-fb1d348d24f1

STIX ID: report--6c9b4df9-87c8-51fe-8ce2-fb1d348d24f1

Feed Name: KnowBe4 Blog

Threat Score
75/100

Date Published: 2024-04-30

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

This CyberheistNews issue reports on an active MFA-phishing campaign that leverages an open-redirect vulnerability on Nespresso to host malicious redirects to credential-harvesting pages, highlights a major ransomware attack on global optics firm Hoya (with a reported $10M ransom and alleged data theft), summarizes a U.S. DOJ indictment of Iranian nationals for large-scale spear-phishing against government and defense contractors, and describes broader trends including a surge in AI-assisted phishing and MFA-bypass phishing kits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.