Social Engineering

Social Engineering Exposes Healthcare Sector's Human Vulnerability
Meet Dahvid Schloss, a red teamer who pulled off a daring heist at a hospital by exploiting a surprisingly simple vulnerability: human nature. By donning scrubs, sporting a fake badge, and spinning a convincing tale, Schloss was able to sweet-talk his way past a nurse and retrieve a sensitive file.

Security Leaders Seize AI Adoption With Proactive Governance
With AI tools like writing assistants and coding copilots now used by 76% of employees, security leaders are recognizing the need for proactive governance to stay ahead of the curve. Traditional blocking methods are no match for the speed of workarounds, which often take just minutes to find, versus official approval routes that can take weeks.

FBI Warns of Scammers Impersonating Agents on Social Media
Beware of scammers on social media pretending to be FBI agents - the Internet Crime Complaint Center (IC3) will never contact you directly through social media, email, or phone to investigate cybercrimes or recover lost funds. If someone claims to be from IC3 on social media, they're likely a scammer.

CISOs Warn of Executive Disconnect on Cybersecurity Risks
A whopping 78% of CISOs believe their board-level decision makers are in the dark about employee-driven cyber risks, leaving companies vulnerable to attacks. The disconnect is alarming, especially as AI-powered scams and social engineering attacks become increasingly sophisticated.

Banks Expose Accounts to Thieves by Making MFA Optional
Leaving multi-factor authentication optional has left countless bank accounts vulnerable to theft, with devastating consequences - just ask the 84-year-old victim who lost nearly $30,000 when thieves exploited this security gap. By making MFA optional, banks are inadvertently rolling out the red carpet for thieves.

Opera Introduces Paste Protect to Thwart ClickFix Attacks
Opera's new Paste Protect feature helps keep you safe from sneaky ClickFix attacks by automatically blocking suspicious copy actions that could land malware on your device. This clever tool outsmarts scammers who try to trick you into pasting malicious commands, protecting you from unwanted surprises.

Healthcare Organization Backpedals on Phishing Test Targeting Staff Burnout
Newfoundland and Labrador Health Services is hitting the brakes on a well-intentioned but misguided phishing test that left staff feeling frustrated and burnt out. The healthcare organization has apologized and pledged to review its approach after sending employees a fake email offering an extra paid day off.

Cybersecurity Gaps Exposed in Non-Email Threat Detection
As cybercriminals shift their focus from email to other trusted channels, a glaring gap in non-email threat detection has emerged, leaving organizations vulnerable to attacks on messaging and social platforms. A recent survey of cybersecurity pros reveals that while 60% of attacks now target non-email channels, half of respondents admit their organizations lack confidence in detecting these threats.

Diversity Bolsters Cybersecurity Against AI-Driven Threats
With women making up only 17 percent of Australia's cybersecurity workforce, the industry's glaring gender gap leaves us vulnerable to AI-driven threats and puts women at greater risk of online harms. Closing this gap is crucial to bolstering our digital protection and ensuring a safer online world for all.

Community Forum Moderation Evolves Amid Security Landscape
Join the conversation, but first, a friendly reminder: let's keep it civil and respectful in Bunker Talk, even when politics heat up - no name-calling, no personal attacks, and stick to the facts. By following these simple rules, we're building the best commenting crew on the net.

AI Agents Vulnerable to Phishing Attacks, Expose Sensitive Data
Researchers put an AI agent named Pinchy to the test with classic phishing simulations, and the results were alarming: sometimes it fell for the bait, spilling sensitive data, and other times it successfully blocked the attacks. The experiment revealed a stark vulnerability - AI agents can be tricked into exposing confidential information.

Google Bolsters Android Defenses Against AI-Powered Scam Calls
Google's new fake call detection feature sends a silent signal to verify the caller, instantly warning you if a scammer tries to impersonate someone you know. If the signal is missing, your device double-checks with the caller's actual phone to keep you safe.

Bayer Overhauls Security Training to Counter AI-Driven Threats
Bayer is revolutionizing its security training to combat AI-driven threats by ditching traditional checklist-driven advice for a psychology-first approach that outsmarts increasingly realistic social engineering tactics. This bold move aims to empower staff and suppliers to safely harness the power of generative AI.

CEO's File Share Mishap Exposes Workplace Security Lapses
Imagine being called in to help a CEO recover deleted files, only to discover a shocking secret: a treasure trove of explicit content stored on a company file share that's accessible to anyone. The awkward moment that followed will leave you cringing - and wondering how something so sensitive could be so carelessly exposed.

Poland Shifts Officials to State Messaging App Citing Security Concerns
Poland is swapping out Signal for a state-developed messaging app touted as more secure, amid rising concerns over targeted social engineering attacks on government officials. The move marks a significant shift in how officials communicate, prioritizing security over popular choice.

Social Engineering Exposes Vulnerability in Corporate Networks
A clever phone call can be all it takes to breach a corporate network - just ask Brandon Dixon, a former penetration tester who convinced an IT security team to hand over root access by pretending to be their boss. With a simple social engineering trick, Dixon was able to reset his "password" and gain unrestricted access to the network.

Signal Bolsters Defenses Against Social Engineering, Phishing Attacks
Stay one step ahead of scammers with Signal's latest update, designed to help you spot fake profiles and phishing attempts with added confirmations and warning messages. You'll now see a "Name not verified" label and get richer safety tips to make sure you're chatting with the real deal.

Steganography Exploits LLMs with Hidden Text Techniques
Want to hide text in plain sight? Try using white text on a white background or black text on a black background - simple yet effective visual tricks that can evade human eyes while remaining readable by machines.

Employees Willingly Sell Work Credentials
A shocking 13% of employees admit to selling their work logins or knowing someone who has, revealing a surprisingly casual attitude towards protecting sensitive work credentials. This statistic raises serious concerns about workplace security and the vulnerability of company data.

Teens Exploit Age Checks with Simple Facial Manipulation Tactics
Kids are outsmarting age checks with a surprisingly simple trick: drawing on a fake mustache. This clever tactic allows them to bypass age verification systems with ease.

Lawsuit Alleges Dating App Meete Exploits Users' Likenesses
A Tennessee lawsuit claims dating app Meete used a young woman's TikTok video in an ad without her consent, sparking concerns over user exploitation. The case highlights the alarming trend of apps profiting from users' likenesses without permission.

Romanian Swatting Ring Leader Draws 4-Year Prison Sentence
Thomasz Szabo, the ringleader of a notorious swatting ring, has been sentenced to four years in prison for orchestrating a campaign of fake bomb threats and swatting calls that targeted high-profile figures, including members of Congress and federal law enforcement officials. Szabo's malicious scheme sent armed police to the doors of innocent victims, causing fear and chaos.

FTC Warns of $2.1 Billion Losses to Social Media Scams
Scammers are making a killing on social media, with nearly one-third of reported losses - a whopping $2.1 billion - originating from these platforms in 2025, according to the FTC. That's an eightfold increase in just five years, making social media a primary target for scammers to swindle unsuspecting consumers.

Fraud Prevention Evolves to Balance Security and User Experience
The age-old trade-off between security and user experience is no longer a given - in fact, it's possible to boost security without slowing down your customers. By combining identity, device, and network signals, businesses can effectively block fraud while providing a seamless experience for legitimate users.