Tag: social engineering
408 articles

Meet Rey: Exclusive Look at Best-Run Lapsus$ Hunters
When Rey — long the shadowy operator and public face of the Scattered LAPSUS$ Hunters — agreed to be identified and speak, the story shifted from faceless hacks to a real person whose groups social‑engineering tactics fueled costly data thefts. That rare revelation forces hard questions about motive, responsibility, and how we defend against attacks that prey on human error.

Rey Exclusive: Inside the Best Scattered Lapsus$ Admin
When a reporter called his father and unmasked Rey, the public face of Scattered LAPSUS$ Hunters, it upended a group built on anonymity and exposed how social‑engineering, account takeovers and micropaid crowds power a new, scalable extortion playbook. The fallout forces a rare reckoning about motive, accountability—and the practical fixes defenders and regulators can’t ignore.

LinkedIn Job Scams: Exclusive Tips to Avoid Costly Fraud
When a recruiter asks for your LinkedIn password, it’s not hiring—it’s a trap. Learn simple, practical ways to spot fake job offers, protect your credentials, and keep your career and accounts safe from sophisticated scammers.

Coupang Breach Exclusive: Critical Response to 34M
The Coupang data breach affecting 34 million customers shows that stolen contact and profile details—even without payment or authentication theft—can fuel highly convincing phishing, impersonation and downstream fraud. Security leaders warn the real damage is erosion of trust, not just downtime.

Amazon Exposes Stunning GRU Cyber Campaign, Energy Risk
Amazon Web Services says it uncovered a years‑long GRU cyber campaign that probed — and in some cases breached — Western energy and infrastructure, revealing how attackers now hide in everyday cloud tools. It’s a wake‑up call: social engineering, OAuth abuse and bespoke malware can turn our networks and power grids into espionage targets.

Russian Phishing Campaign: Exclusive ISO Stealer Threat
Exclusive: a Russian phishing campaign is circulating a stealthy ISO stealer — learn how it works and quick, practical steps to keep your data safe.

Black Friday Exclusive: 3 Dangerous Scams to Avoid
Black Friday scams are getting smarter—learn the three dangerous tricks scammers use and the simple steps you can take to protect your wallet and personal info.

Lapsus$ Hunters Pose Dangerous, Exclusive Threat to Zendesk
Patchable missteps meet crowd‑powered coercion: Scattered Lapsus$ Hunters are resurfacing with new phishing domains and social‑engineering tricks aimed at support tools like Zendesk. Compromised help‑desk credentials can give attackers an exclusive backdoor into customer and corporate data—so small lapses can have big consequences.

JackFix Exclusive Alert: Dangerous Fake Windows Updates
Heads up — don’t paste that “Windows fix” command: a slick new scam uses fake CAPTCHAs and cloned sites to trick users into running malware that gives attackers persistent access to otherwise patched PCs.

AI Deepfake Stunning Surge: Identity Fraud Worsens
Identity fraud has entered a new era: generative AI churns out eerily lifelike voices and videos that let scammers impersonate bosses, loved ones and officials with uncanny accuracy. As these deepfake-enabled schemes become cheaper and harder to spot, individuals and businesses must rethink how they verify trust.

CISA: Exclusive Critical Spyware Threat to Signal, WhatsApp
CISA warns that commercial spyware and remote‑access trojans are being used to compromise Signal and WhatsApp—often via social engineering and sideloaded apps—turning everyday messaging into a gateway for stolen messages, media and device data.

Cybercriminals Exploit Push Notifications: Stunning Risks
Think your browsers push alerts are harmless? Cybercriminals are hijacking browser push notifications and fake verification prompts to deliver stealthy malware and persistent backdoors, turning everyday web conveniences into covert attack channels.

UNC2891 Money Mule Network Exclusive: Devastating ATM Fraud
Meet UNC2891: a slick, multi-year fraud machine that cloned bank cards and used fake job postings to recruit a vast money-mule network. By coordinating synchronized ATM cash-outs across borders, they turned digital theft into physical cash — a chilling playbook and a wake-up call for banks and consumers.

ThreatsDay Exclusive: Critical Cyber Threats Unveiled
Think clicking a browser add-on or plugging in a smart camera is harmless? This ThreatsDay roundup exposes how weaponized everyday tools — from extensions and smart gadgets to satellite feeds and SMS — turn convenience into a covert battleground of surveillance, social engineering, and supply‑chain attacks.

Python-Based WhatsApp Worm Exclusive: Dangerous Stealer
What would you do if your WhatsApp started messaging your friends without you? Researchers warn the Delphi-based Eternidade Stealer is hijacking accounts and weaponizing contact lists—using social engineering and IMAP-resolved C2 to spread quickly and dodge static defenses.

Eternidade Stealer Trojan Exclusive Severe Cybercrime Surge
Eternidade Stealer is a new banking trojan that weaponizes Brazil’s favorite app, WhatsApp, turning ordinary messages into a fast-moving credential theft campaign. Researchers warn one click can unleash downloaders that harvest browser-stored credentials and cookies, making everyday chats unexpectedly risky for users and businesses.

AI-Enhanced Tuoni Framework: Exclusive Affordable Win
A single crafted message—leveraging AI‑enhanced Tuoni C2, steganography and in‑memory execution—slipped past defenses at scale, showing attackers are getting smarter and stealthier. Its a wake‑up call: rapid detection, cross‑team coordination and tougher verification are now essential.

ThreatsDay Bulletin: Exclusive Critical Cyber Roundup
Every click can be the opening move in a campaign of trust-based deception. This bulletin shows how fast-moving actors like COLDRIVER are making signatures obsolete and why shifting to behavioral, intent-driven defenses is now essential.

Improve Collaboration: Best Must-Have Steps to Beat Fraud
When fraudsters thrive on delay, real-time intelligence sharing across banks, telcos, tech firms and government is the fastest way to stop them in their tracks. Getting there means practical steps, common standards and a culture that treats shared signals as the public good they are.

Quantum Route Redirect Phishing Kit: Stunningly Dangerous
The Quantum Route Redirect phishing kit quietly hijacks web traffic, rerouting victims to eerily convincing fake sites. Learn how this route redirect phishing attack works and what you can do to stay one step ahead.

NCA Campaign Exclusive: Critical Crypto Scam Warning
Dont miss this NCA-exclusive crypto scam warning — learn the latest tricks scammers use and quick, practical steps to keep your crypto safe.

SmudgedSerpent Exclusive: Dangerous Hackers Target Experts
Meet SmudgedSerpent: during the summer 2025 Iran–Israel flare-up a stealthy cyber cluster used precision social engineering to target academics and policy experts. By exploiting researchers’ networks and unpublished work, these attacks show how adversaries now shape information and influence far faster than old‑school espionage.

Cybercriminals Targeting Payroll Sites Exclusive Warning
Imagine your paycheck landing in a strangers account—criminals are targeting payroll systems with social‑engineering scams that hijack credentials and reroute direct deposits. Simple fixes like multi‑factor authentication, tighter admin privileges, and out‑of‑band approvals can stop them before paychecks disappear.

Teams Flaw: Stunning Reveal of Critical Boss Spoofing
A newly revealed Microsoft Teams vulnerability let attackers convincingly impersonate executives, forge messages and even rewrite chat history—turning everyday collaboration into a pathway for fraud and data theft. Learn how Check Point’s findings expose the danger of boss‑spoofing and what organizations need to patch now.