A sophisticated VPN phishing and vishing campaign targeting over 130 US organizations uses social engineering tactics like phone calls and SMS messages to steal credentials. Threat actors impersonate IT staff, leading victims to fake login pages to gain network access.
Source: HackRead