social-engineering
351 articles with this tag
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
MEDIUM
HIGH
MEDIUM
HIGH
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
MEDIUM
MEDIUM
HIGH
LOW
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
INFO
MEDIUM
MEDIUM
MEDIUM
INFO
MEDIUM
HIGH
INFO
LOW
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
MEDIUM
INFO
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
LOW
HIGH
HIGH
MEDIUM
Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Attackers use passkey-themed scams to hijack Microsoft 365 accounts
Google’s Early Access is creating a blind spot for malicious apps
Attackers call employees’ personal phones to break into Microsoft 365 accounts
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Smashing Security podcast #483: This AI helps thieves steal your iPhone
Passkey-themed social engineering leads to identity and cloud compromise
MFA's Weakest Link: Account Recovery Is the New Attack Path
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
X Money rollout linked to password-reset attacks
Large Enterprises Targeted in Fake Merger & Acquisition Scams
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
QR Phishing With No Image: Text-Only QR Codes for Inboxes w/ Images Disabled
Breeze Comet threat actor targets Brazilian financial sector with sophisticated attacks
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
Microsoft identifies ‘TerminalFix’ campaign spreading Python reverse tunnel
Fake Claude Opus 5 app delivers malware and wipes its own tracks
TerminalFix looks like ClickFix, but delivers a very different payload
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Fake listings can turn trusted platforms into scam springboards
LLM-Based Social Engineering Scams
From Fake Workers to Account Recovery: The Growing Identity Verification Risk
ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack
ReliaQuest Rejects Compromise Claims After ShinyHunters Incident
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Extended Rapid Response: Zimperium Identifies RecruitTrap Recruit Scams are Targeting Enterprise Credentials on Mobile
Personal Information Exposed in Apollo Global Data Breach
Eltihrellar nota millifærslur til að áreita fólk
Apollo discloses data breach from ongoing wave of attacks hitting financial sector
Attackers impersonate popular AI brands to spread malware
New malware campaign combines social engineering with defense evasion
Ransomware crook poses as recovery firm to steal payments from fellow extortionists
Black Hat/DEF CON attendees targeted in malware scheme with Google Doc lure
Def Con Attendees Targeted by Persistent Phishing Campaign
MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra
Your polite reply to that text is worth $2 on the dark web
Banks look for fraud signals in customer behavior
17th August – Threat Intelligence Report
MacOS AmnesiaStealer malware spread through ClickFix, grants live browser control
1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
Novel macOS Infostealer AmnesiaStealer Spread via ClickFix
1.6 Million Likely Impacted by RingCentral Data Breach
Ukrainian police raid 94 fraudulent call centers, seize $2 million
Phishing Gets Personal
Smashing Security podcast #480: This is the AI service you should never sign up to
Lazarus hackers pair fake job offers with Windows zero-day exploit
Sexual predators targeting online accounts for intimate images, FBI warns
Fake popular sites offer a free app, instead take over PCs
Sherlock Holmes was the “OG” Social Engineer
Attackers pick Levi's pockets in social engineering attack
Corporate Data Stolen in Levi Strauss Cyberattack
Reif límmiða af heyrúllu og krotaði „Já til að sjá“
Fortra's Josh Davies on the evolving exploitation of trust
AI chat bots are sliding into League of Legends friend requests
Vishing Extortion Group UNC6671 Rebrands After Making Millions
The Evolving Exploitation of Trust - Josh Davies - BH26 #2
Amazon and Apple impersonated in “$149.99 unauthorized charge” scam
Anthropic’s Mythos AI used social engineering to target real people
AI agents caught using social engineering in UK security tests
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
Fake Roblox Xeno executor installers distribute malware
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Weaponized Email AI Assistants Could Help Attackers Hijack Accounts
Fake Roblox Xeno script launcher pushes infostealer, RAT malware
The $5 million threat: AI Is supercharging phishing attacks
AI Scammers Are Better at Building Trust Than Humans
LogoKit Phishing Kit Screenshots Victim Sites in Real Time
Chaos in Teams vishing
Steam forums used for ClickFix cryptominer attacks
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
Hospital security compromised by social engineering and poor network practices
Fake Edge Update
Talking smack about a doctor got him access to private medical files
When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover
First-Person Identity Theft Story
Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Clover Health Investments Discloses Data Breach
Redirect Chain Abuse
Italy fines WINDTRE €1.7 million over security flaws behind two data breaches
New ACR Stealer campaigns use WebDAV, MSHTA to evade detection
Scammers weaponize FaceTime to drain bank accounts
New TELEPUZ malware spreads via ClickFix lures
Modular macOS Stealer Uses Kill Loops to Force Password Entry
Finance phishing works because it sounds boringly normal
Phishing Campaign Abuses eCards to Deploy RMM Tools
New CrashStealer malware poses as Apple crash reporting tool
Fake Microsoft Installer
Thief posed as Wi-Fi fixing hero, then stole priceless trophy
The fake report message that ends with a stolen Reddit account
Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
Watch out for fake support calls in Microsoft Teams
AdaptHealth says attackers sweet-talked their way into cloud systems and stole patient data