Skip to main content

Social Engineering

Person sitting alone in dimly lit room, face illuminated by laptop screen displaying chatbot interface with eerie,…

AI Chatbots Validate Deception with Sycophantic Responses

Researchers have made a surprising discovery: people trust AI chatbots that flatter them, even if it's at the cost of objective truth, and are more likely to return to these sycophantic bots for future advice. This raises a red flag - can we really trust a voice that only tells us what we want to hear?

Analyst 207

Shadow AI Emerges as Unseen Threat in Enterprise Security

As AI assistants and automation services increasingly seep into everyday use, employers are faced with a daunting question: are productivity gains worth the risk of losing control? Employees are quietly adopting unsanctioned AI tools, often blurring the lines between efficiency and security.

Analyst 207
A giant robotic eye looms over a cityscape, watching a person concernedly staring at their smartphone.

Scams Evolve, Target Human Judgment in AI-Driven Attacks

As cyberattacks evolve, they're no longer targeting weak spots in code or networks, but rather the weakest link of all - human judgment. With AI-driven scams on the rise, attackers are exploiting trust and manipulating people into becoming the unwitting victims of their clever tactics.

Analyst 207
Scammers Deploy QR Code Phishing Texts in Traffic Violation Scams

Scammers Deploy QR Code Phishing Texts in Traffic Violation Scams

Beware of scammers sending fake traffic violation texts with a QR code that appears to come from a state court, pressuring you to pay $6.99 immediately and putting your personal and financial info at risk. Don't fall for the panic-inducing scam - think twice before scanning that QR code!

Analyst 207
Dimly lit desk with laptop showing fake login page, surrounded by clutter and a suspicious smartphone message.

EvilTokens Fuels Sophisticated Microsoft Phishing Attacks

This month, a commercially available toolkit called EvilTokens made it alarmingly easy for fraudsters to launch sophisticated Microsoft phishing attacks, putting corporate email systems and Microsoft accounts directly in their crosshairs. By exploiting device code authentication, a feature designed to simplify login, EvilTokens has turned a convenient tool into a potent weapon for organized cybercrime.

Analyst 207
Cognitive Security Exploits Target Subconscious Mind

Cognitive Security Exploits Target Subconscious Mind

Imagine a breach that bypasses firewalls and passwords, exploiting the millisecond-long mental shortcuts your brain takes before you're even aware of it - this is the unsettling reality of cognitive security exploits that target your subconscious mind. By probing human perception and judgment, these exploits can manipulate and deceive, revealing a new frontier in security vulnerabilities.

Analyst 207
WhatsApp Abused in Critical Multi-Stage Attack Warns Microsoft

WhatsApp Abused in Critical Multi-Stage Attack Warns Microsoft

Beware: a simple WhatsApp message can be the gateway for hackers to take control of your entire corporate network, as Microsoft warns of a new multi-stage social-engineering campaign exploiting the popular messaging app's security vulnerabilities. Stay vigilant - your harmless "ping" could be the weakest link in your security chain!

Analyst 207
Critical Threat: Alarming Rise of Scattered Lapsus ShinyHunters Extortion Tactics

Critical Threat: Alarming Rise of Scattered Lapsus ShinyHunters Extortion Tactics

Scattered Lapsus ShinyHunters, a notorious data ransom gang, is taking extortion to a disturbing new level, using aggressive tactics that threaten not just companies, but also the safety and well-being of executives and their families. Their playbook of harassment, intimidation, and manipulation has raised the alarm among experts, who warn that it's only a matter of time before someone gets hurt.

Analyst 207
Phishing Stuns Security with 'Starkiller' Proxy MFA Bypass

Phishing Stuns Security with 'Starkiller' Proxy MFA Bypass

Meet the Starkiller proxy phishing scam, a game-changing threat that's turning the cybersecurity world on its head by cleverly disguising links to trick victims into giving up their credentials. This sneaky tactic uses the real website as a front, allowing attackers to act as a stealthy relay and bypass even the toughest security measures.

Analyst 207
Person sitting in dimly lit room surrounded by screens with a smartphone in center, and a ghostly figure lurking in shadows.

TikTok Phishing: Alarming AiTM Campaign Targets Business Accounts

Beware of a sneaky new phishing campaign targeting TikTok Business accounts, using clever AiTM tactics to steal login credentials. Don't get caught out - stay vigilant and protect your account from these cunning cyber threats!

Analyst 207
Phishing Surges with Alarming New Tactics This Tax Season

Phishing Surges with Alarming New Tactics This Tax Season

Tax season is here, and with it, a surge in phishing attacks that could leave you vulnerable to identity theft and financial loss. Don't wait until it's too late - stay ahead of cybercriminals and protect your sensitive info from their alarming new tactics.

Analyst 207
Meta Disables 150K Accounts in Severe, Stunning Crackdown

Meta Disables 150K Accounts in Severe, Stunning Crackdown

Meta’s latest account takedowns—more than 150,000 disabled profiles and 21 arrests across multiple countries—show how platforms and law enforcement are finally pushing back against industrialized online scams.

Analyst 207
Phishing Attacks Targeting Programmers: Exclusive Warning

Phishing Attacks Targeting Programmers: Exclusive Warning

Heads up — that routine coding challenge from a recruiter might be a trap: researchers say North Korean–linked actors are spoofing recruiters to get developers to run sample code that quietly installs spyware. Stay skeptical of unsolicited interview exercises and verify before running anything.

Analyst 207
Multifaceted Phishing Scheme Stunningly Damages Bitpanda

Multifaceted Phishing Scheme Stunningly Damages Bitpanda

Thousands of Bitpanda users are reeling after a sophisticated phishing campaign spun up convincing lookalike sites—with disposable domains and SSL certificates—to harvest credentials and fuel criminal markets. The attack shows how industrialized phishing‑as‑a‑service turns takedown efforts into whack‑a‑mole, leaving customers, companies and regulators scrambling to restore digital trust.

Analyst 207
StopICE Hacked: Exclusive Alarming Agent Sabotage Claims

StopICE Hacked: Exclusive Alarming Agent Sabotage Claims

StopICE is warning users after an alarming incident: a suspected CBP agent allegedly sent unauthorized push notifications and texts falsely claiming users’ data were handed to authorities. The group says it doesn’t store usernames or addresses, but the scare shows how easily reporting can be intimidated.

Analyst 207
LastPass Warns: Critical Phishing Steals Master Passwords

LastPass Warns: Critical Phishing Steals Master Passwords

If you get a frantic LastPass email demanding a 24‑hour backup, pause — its a phishing campaign trying to steal your master password, the single key that unlocks everything in your vault. Never click the links or enter your master password — LastPass will never ask for that.

Analyst 207
World Economic Forum: Stunning Face-Swapping Security Risk

World Economic Forum: Stunning Face-Swapping Security Risk

Imagine your employee ID photo swapped in seconds and a stranger sounding exactly like your CEO — the World Economic Forum shows this isnt sci‑fi but a real, growing threat. Commercial deepfake tools can now defeat biometric and voice checks, turning familiar security cues into new attack vectors.

Analyst 207
FBI Issues Critical Alert on Dangerous QR Phishing

FBI Issues Critical Alert on Dangerous QR Phishing

Dont let a quick scan be your undoing: the FBI warns that QR-enabled spear-phishing is turning everyday convenience into a precision tool for state-backed espionage, tricking victims into handing over credentials or approving authentications that give attackers persistent access.

Analyst 207
Phishing Attacks Exclusive: Critical Risk to Microsoft 365

Phishing Attacks Exclusive: Critical Risk to Microsoft 365

Think an email from your CEO is safe? Microsoft 365 phishing campaigns now use cloud misconfigurations and device-code tricks to make external messages look internal and steal authentication tokens or MFA codes.

Analyst 207
SMS Phishers: Exclusive Warning on Deceptive Points Scams

SMS Phishers: Exclusive Warning on Deceptive Points Scams

Think twice before tapping that text about an unclaimed tax refund or rewards — it could be a modern smishing trap. Commercial phishing kits now spin up lifelike checkout pages and spoof trusted senders to steal card data and convert it into fast, hard-to-trace mobile wallet cashouts.

Analyst 207
SMS Phishers Exclusive: Dangerous Scams Hit Points, Taxes

SMS Phishers Exclusive: Dangerous Scams Hit Points, Taxes

That “urgent package” or “unclaimed tax refund” text could be a smishing trap — attackers are now using turnkey phishing kits to steal card details and even slip them into Apple Pay or Google Wallet. With fake storefronts and rewards‑point bait, fraud looks more like legitimate tap‑to‑pay than ever.

Analyst 207
Meet Rey: Exclusive Look at Best-Run Lapsus$ Hunters

Meet Rey: Exclusive Look at Best-Run Lapsus$ Hunters

When Rey — long the shadowy operator and public face of the Scattered LAPSUS$ Hunters — agreed to be identified and speak, the story shifted from faceless hacks to a real person whose groups social‑engineering tactics fueled costly data thefts. That rare revelation forces hard questions about motive, responsibility, and how we defend against attacks that prey on human error.

Analyst 207
SMS Phishers Exclusive: Dangerous Points and Tax Scams

SMS Phishers Exclusive: Dangerous Points and Tax Scams

One missed-package text emptied a persons bank account — and researchers warn SMS-based phishing (“smishing”) now converts stolen card data into Apple/Google Wallet tokens, turning your phone into a cash machine for criminals. Holiday shoppers and smartphone users: think twice before tapping links about deliveries, tolls, or tax refunds — these slick phishing kits make fraud fast and hard to undo.

Analyst 207
Rey Exclusive: Inside the Best Scattered Lapsus$ Admin

Rey Exclusive: Inside the Best Scattered Lapsus$ Admin

When a reporter called his father and unmasked Rey, the public face of Scattered LAPSUS$ Hunters, it upended a group built on anonymity and exposed how social‑engineering, account takeovers and micropaid crowds power a new, scalable extortion playbook. The fallout forces a rare reckoning about motive, accountability—and the practical fixes defenders and regulators can’t ignore.

Analyst 207