#payroll-fraud

[ follow ]
#phishing
fromSecurityWeek
1 week ago

In Other News: Gladinet Flaw Exploitation, Attacks on ICS Honeypot, ClayRat Spyware

Gladinet vulnerability exploited in the wild A vulnerability affecting Gladinet's CentreStack and Triofox products has been exploited in the wild, Huntress warns. CentreStack is a mobile access and secure sharing solution while Triofox is a secure file access solution. Huntress earlier this year discovered exploitation of CVE-2025-30406, a hardcoded machine key issue affecting the products, and it has now detected exploitation of a new vulnerability, CVE-2025-11371, which allows unauthenticated local file inclusion. Gladinet is aware of the issue and is in the process of providing a workaround to customers until a patch is developed.
Information security
fromTheregister
1 week ago

Microsoft warns of 'payroll pirate' attacks against US unis

In a blog post, Redmond said a cybercrime crew it tracks as Storm-2657 has been targeting university employees since March 2025, hijacking salaries by breaking into HR software such as Workday. The attack is as audacious as it is simple: compromise HR and email accounts, quietly change payroll settings, and redirect pay packets into attacker-controlled bank accounts. Microsoft has dubbed the operation "payroll pirate," a nod to the way crooks plunder staff wages without touching the employer's systems directly.
Information security
#cybersecurity
fromIT Pro
1 week ago
Information security

'Payroll Pirates' target US universities, Microsoft warns

A hacking group called Storm-2657 uses AITM phishing to harvest MFA, access university HR SaaS (e.g., Workday), and divert salary payments to attacker-controlled accounts.
fromThe Hacker News
4 months ago
Growth hacking

Employees Searching Payroll Portals on Google Tricked Into Sending Paychecks to Hackers

Threat hunters identified a new SEO poisoning campaign targeting employee mobile devices to perpetrate payroll fraud.
[ Load more ]