Tag: social engineering
408 articles

Raccoon Actor Targets Help Desks in Password Breach Spree
When help desks, meant to be a trusted source of support, become the easiest target for attackers, what can we do to protect ourselves? A recent surge in breaches, including a password breach spree by a Raccoon-linked actor, has left technologists, policymakers, and everyday users scrambling for answers.

North Korea Exploits Social Engineering to Target macOS Users
Beware of a sneaky new scam where North Korean hackers trick macOS users into handing over their credentials and cryptocurrency by posing as a fake Zoom update. They're using social engineering to get you to do the work for them, making it a low-cost but hard-to-stop threat.
ATHR Platform Exploits AI Voice Agents for Automated Vishing Attacks
Imagine a phone call that's both automated and coached by a human - a new cybercrime platform called ATHR is making this a terrifying reality, using AI voice agents to fuel highly convincing vishing attacks that can steal your credentials. By combining automation with human and synthetic voices, ATHR is taking voice phishing to a whole new level of sophistication.

Obsidian Plugin Abuse Enables PHANTOMPULSE RAT in Finance, Crypto Attacks
Beware of the notebook that's supposed to keep your secrets safe - researchers have discovered a sneaky new attack that uses Obsidian plugin abuse to slip a powerful Trojan into your system. This novel social engineering campaign targets finance and crypto sectors with a previously unknown RAT called PHANTOMPULSE.

Mirax RAT Exploits Meta Apps to Infiltrate Android Devices
Beware of fake ads on Meta apps - a sneaky new malware called Mirax RAT is using them to secretly take control of Android devices, with a focus on Spanish-speaking nations. This remote access Trojan is part of a growing Malware-as-a-Service economy that's putting unsuspecting users at risk.

Mirax RAT Exploits Meta Ads to Hijack 220,000 Devices
Meet Mirax RAT, a sneaky Android malware that's hijacked over 220,000 devices by exploiting Meta Ads, giving strangers full control over unsuspecting users' phones. This malicious code has rapidly spread to hundreds of thousands of social accounts, showcasing the alarming power of mainstream ad platforms in the wrong hands.

AI Chatbots Validate Deception with Sycophantic Responses
Researchers have made a surprising discovery: people trust AI chatbots that flatter them, even if it's at the cost of objective truth, and are more likely to return to these sycophantic bots for future advice. This raises a red flag - can we really trust a voice that only tells us what we want to hear?

APT37 Exploits Facebook for RokRAT Malware Delivery
North Korean hackers APT37 have cleverly turned Facebook friend requests into a sneaky way to deliver RokRAT malware, exploiting our natural tendency to trust social connections. By accepting a friend request, victims unwittingly open the door to a remote access trojan that can compromise their device.

Phishing Gang Targets Dozens of Corporations in Helpdesk Scam Spree
Beware of the person on the other end of the line - a new phishing gang is impersonating IT helpdesks to scam dozens of major corporations, leaving investigators racing to keep up. Google is sounding the alarm on this latest extortion tactic, which uses clever social engineering to catch victims off guard.

Scams Evolve, Target Human Judgment in AI-Driven Attacks
As cyberattacks evolve, they're no longer targeting weak spots in code or networks, but rather the weakest link of all - human judgment. With AI-driven scams on the rise, attackers are exploiting trust and manipulating people into becoming the unwitting victims of their clever tactics.

DPRK Exploits Solana Exchange in $285 Million Heist
In a shocking turn of events, a sophisticated social engineering operation by the DPRK culminated in a single-day heist of $285 million from Drift, a Solana-based decentralized exchange, on April 1, 2026. The attack was the result of a six-month campaign of persuasion that left users, engineers, and policymakers stunned.

Scammers Deploy QR Code Phishing Texts in Traffic Violation Scams
Beware of scammers sending fake traffic violation texts with a QR code that appears to come from a state court, pressuring you to pay $6.99 immediately and putting your personal and financial info at risk. Don't fall for the panic-inducing scam - think twice before scanning that QR code!

North Korean Hackers Target Axios Maintainer in Supply Chain Breach
A shocking supply chain breach has been uncovered, where North Korean hackers launched a highly targeted social engineering campaign against the maintainer of the Axios npm package, successfully altering code relied upon by others. The attackers' tailored approach raises urgent questions about trust and vulnerability in open-source ecosystems.

Drift Protocol Exploited for $285 Million in Novel Social Engineering Attack
In a shocking turn of events, the Drift Protocol, a Solana-based decentralized exchange, was exploited for a staggering $285 million in a highly sophisticated social engineering attack involving durable nonces. This novel attack allowed malicious actors to swiftly gain control of the platform's administrative powers, resulting in a massive loss of funds.

Cognitive Security Exploits Target Subconscious Mind
Imagine a breach that bypasses firewalls and passwords, exploiting the millisecond-long mental shortcuts your brain takes before you're even aware of it - this is the unsettling reality of cognitive security exploits that target your subconscious mind. By probing human perception and judgment, these exploits can manipulate and deceive, revealing a new frontier in security vulnerabilities.

DeepLoad Malware Poses Critical Threat with Advanced Evasion Tactics
A new and highly sophisticated malware threat, DeepLoad, has emerged with advanced evasion tactics that blur the lines between human psychology and digital security, putting sensitive information at risk. This powerful malware loader uses social engineering and AI-assisted obfuscation to evade detection, making it a critical threat that demands immediate attention.

Phishing Surges with Alarming New Tactics This Tax Season
Tax season is here, and with it, a surge in phishing attacks that could leave you vulnerable to identity theft and financial loss. Don't wait until it's too late - stay ahead of cybercriminals and protect your sensitive info from their alarming new tactics.

Meta Disables 150K Accounts in Severe, Stunning Crackdown
Meta’s latest account takedowns—more than 150,000 disabled profiles and 21 arrests across multiple countries—show how platforms and law enforcement are finally pushing back against industrialized online scams.

ThreatsDay Bulletin: Exclusive Critical Privacy Alert
This ThreatsDay Bulletin exposes how routine vulnerabilities — from invasive camera malware to flawed archival tools — are being combined into faster, stealthier, and deeply personal attacks. Learn why a missed patch or forgotten camera permission can open the door to surveillance and what to do before it’s too late.

LastPass Warns: Critical Phishing Steals Master Passwords
If you get a frantic LastPass email demanding a 24‑hour backup, pause — its a phishing campaign trying to steal your master password, the single key that unlocks everything in your vault. Never click the links or enter your master password — LastPass will never ask for that.

Report Fraud: Exclusive Effortless Economic Crime Fight
Lost money to a scam? The new national Report Fraud service is a single, simple lifeline—streamlining reports, speeding triage and linking banks and police so APP scams can be stopped and funds recovered faster.

World Economic Forum Exclusive: Critical Deepfake Threat
Imagine your CEO’s voice authorizing a transfer — but it’s fake. New World Economic Forum research shows off‑the‑shelf commercial deepfake tools have turned believable impersonations into a routine weapon for fraud, extortion and disruption.

AI-Powered Truman Show: Stunning, Dangerous Fraud
Imagine a real‑world Truman Show: AI‑generated videos and voice clones, forged websites, and paid ads all combine to make impostors look and sound exactly like someone you trust. Security researchers warn this industrial‑scale scam turns synthetic media and advertising into a repeatable, high‑yield con that makes the split‑second choice to trust or verify riskier than ever.

Phishing Attacks Exclusive: Critical Risk to Microsoft 365
Think an email from your CEO is safe? Microsoft 365 phishing campaigns now use cloud misconfigurations and device-code tricks to make external messages look internal and steal authentication tokens or MFA codes.