search
Proofpoint
Trends
- 1Compromised university email accounts used in job scam fraud●(proofpoint.com) Compromised University Accounts Exploited in Multi-Stage Job Scam and Advanced Fee Fraud Campaigns In b
Cybersecurity firm Proofpoint reports that attackers are hijacking .edu email accounts belonging to U.S. universities and using them to run multi-stage fraud schemes. The campaigns combine fake job offers with advance-fee fraud, exploiting the trust associated with legitimate university email addresses. Security researchers warn recipients to be cautious with unsolicited job-related messages, even those sent from seemingly authentic .edu accounts.
- 2China-linked TA419 targets U.S. AI policy experts with phishing●🤖 China-nexus TA419 runs AitM credential phishing against U.S. AI policy experts, impersonating economists, policymakers
Proofpoint reports that the China-nexus threat group TA419 is running adversary-in-the-middle credential phishing against U.S. AI policy experts. The attackers impersonate economists, policymakers and an Anthropic employee, using a lure titled "Request for Feedback on Military Integration of Claude". The attack chain ends on an OneDrive page using a frameless browser-in-the-browser technique to harvest credentials.
- 3
Cybersecurity firm Proofpoint reports that hackers linked to China posed as US artificial intelligence policy experts in a targeted campaign. The attackers reportedly used the fabricated identities to build trust with recipients, likely aiming to deliver malicious content or gather intelligence. The activity highlights growing interest by state-linked groups in AI policy circles in Washington.
- 4TA419 phishing campaign targeted AI-policy specialists●Proofpoint says TA419 impersonated AI-policy figures and used a real-time Microsoft 365 phishing proxy against fewer tha
Security firm Proofpoint reports that the threat group TA419 impersonated prominent AI-policy figures and used a real-time Microsoft 365 phishing proxy to steal authenticated login sessions. The highly targeted campaign hit fewer than ten specialists. Researchers say it shows how attackers can capture live sessions, though successful compromises and government attribution remain unclear.