Tag: social-engineering
-
New malware campaign combines social engineering with defense evasion
First seen on scworld.com Jump to article: www.scworld.com/brief/new-malware-campaign-combines-social-engineering-with-defense-evasion
-
Drei Mitarbeiterkonten betroffen – Levi Strauss meldet Datenabfluss nach Social-Engineering-Angriff
First seen on security-insider.de Jump to article: www.security-insider.de/levi-strauss-cyberangriff-social-engineering-unternehmensdaten-a-ba2a5940a4ce9e231ac320e9b5d62d23/
-
ClearFake Fake CAPTCHA Campaigns Use New WordlistLoader to Deploy Amatera Stealer
A new ClearFake infection chain using a previously undocumented intermediate payload dubbed WordlistLoader to deploy Amatera Stealer. The campaign combines compromised websites, fake CAPTCHA overlays, ClickFix social engineering, WebDAV-hosted DLLs and advanced anti-analysis mechanisms to deliver one of the more actively evolving information stealers currently tracked. Clicking the “I’m not a robot” control triggers a…
-
No-Filter ‘Kriminal’ AI Platform Raises Cybercrime Concerns
The AI company officially forbids illicit use, while offering guardrail-free social engineering, offensive cybercrime, and OSINT scanning to anyone with a bit of cryptocurrency. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/no-filter-kriminal-ai-platform-cybercrime-concerns
-
AI Cybersecurity Platform
Tags: ai, attack, automation, cloud, credentials, cybercrime, cybersecurity, data, endpoint, iot, malware, network, ransomware, saas, social-engineering, theft, toolOrganizations are generating unprecedented amounts of digital data from endpoints, networks, cloud workloads, applications, identities, IoT devices, SaaS platforms, and operational technology. At the same time, cybercriminals are becoming more sophisticated, using automation, credential theft, social engineering, malware, ransomware, living-off-the-land techniques, and increasingly AI-assisted attack methods. Traditional cybersecurity tools remain important, but security teams can…
-
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
esearch by: JaromÃr HoÅ™ejšà (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique, which prompts victims to execute a PowerShell command. This leads to two stages of additional downloaders and…
-
Kimsuky Uses Local AI Development Environment to Expand Cyber Espionage Tooling in Operation GitPower
Tags: ai, cyber, data, espionage, intelligence, malware, north-korea, phishing, social-engineering, threatNorth Korean state-backed threat actor Kimsuky is extending its established espionage playbook with locally hosted artificial intelligence tooling, according to new research into an activity cluster tracked as Operation GitPower. The campaign retains familiar phishing-led intrusion chains but shows the operators preparing AI-assisted capabilities for malware development, data analysis, social engineering, and operational automation. The…
-
AI Gives Defenders an Edge in the Vulnerability Race
Tags: ai, attack, breach, data, exploit, extortion, mandiant, phone, risk, scam, social-engineering, software, supply-chain, tool, vulnerabilityMandiant Consulting’s Charles Carmakal on AI, Social Engineering and Extortion. Attackers are using AI to find vulnerabilities, build exploit tools and analyze stolen data, but defenders still hold an advantage. The greater risks now come from human-sounding phone scams, AI-assisted extortion and software supply chain attacks, said Charles Carmakal, CTO at Mandiant Consulting. First seen…
-
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware.CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within…
-
Levi Strauss Breach Began With Social Engineering of 3 Employees
Levi Strauss says hackers socially engineered three employees and stole corporate data, highlighting the growing threat of identity-based attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity-threats/news-levi-strauss-social-engineering-data-breach/
-
When Credentials Are No Longer Enough: Device Trust in the AI Era
AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation, and geolocation become easier to bypass. Specops explains why organizations are increasingly adding device trust to their Zero Trust strategies. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/when-credentials-are-no-longer-enough-device-trust-in-the-ai-era/
-
Levi Strauss Hit by Cyberattack, Hackers Use Social Engineering to Steal Corporate Data
Tags: business, computer, corporate, cyber, cyberattack, cybersecurity, data, hacker, social-engineering, unauthorizedLevi Strauss & Co. has reported a cybersecurity incident in which an unauthorized third party used social engineering techniques to compromise three employee-issued computers and exfiltrate unspecified corporate information. According to the apparel maker, the intrusion was contained, with no evidence that consumer data was affected or that business operations were disrupted. Levi Strauss Cyberattack…
-
Cyberkriminalität ist zu einer industrialisierten Wirtschaft geworden
Cyberkriminalität hat sich von isolierten Angriffen zu einer ausgefeilten, industrialisierten Wirtschaft entwickelt, die von fortschrittlicher KI, Automatisierung und spezialisierten kriminellen Dienstleistungen angetrieben wird. Heutige Angreifer agieren weniger wie opportunistische Hacker und mehr wie Unternehmen sie mieten Infrastruktur, kaufen Phishing-Kits, lagern Geldwäsche aus und nutzen KI, um überzeugende Social-Engineering-Kampagnen mit beispielloser Geschwindigkeit und Größe zu… First…
-
Levi Strauss & Co. says hackers stole corporate data in cyberattack
Levi Strauss & Co. (Levi’s) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/levi-strauss-and-co-says-hackers-stole-corporate-data-in-cyberattack/
-
Levi Strauss says hackers breached employee computers, accessed corporate data
Intruders exfiltrated certain corporate information after gaining access to three company-issued computers through a social engineering attack, Levi Strauss reported. First seen on therecord.media Jump to article: therecord.media/levis-data-breach-social-engineering
-
Social-Engineering mit Real-Time-Coaching im entscheidenden Moment verhindern
KnowBe4 führt die Lösung Real-Time Coaching ein. Sie stellt genau in dem Moment, in dem riskantes Verhalten auftritt, einen sofort verfügbaren, kurz und prägnant formulierten Sicherheitstipp bereit. Social-Engineering-Angriffe gehören nach wie vor zu den effektivsten Methoden, mit denen Angreifer technische Abwehrmaßnahmen umgehen, und sie lassen sich immer schwerer aufdecken. Laut dem Verizon-Data-Breach-Investigations-Report 2026 spielt der menschliche Faktor…
-
Who Recruits Young Hackers First?
Ricky Handschumacher on Redirecting Talent Before Cybercrime Takes Hold. Young hackers may enter cybercrime through gaming, status-seeking and online communities before they understand the consequences. Reformed criminal hacker Ricky Handschumacher explains why the industry must reach them early, offer credible pathways and take social engineering more seriously. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/who-recruits-young-hackers-first-a-32441
-
Social-Engineering-Day KI beflügelt Social-Engineering
In diesem Jahr fällt der Social-Engineering-Day auf den 6. August, dieser Aktionstag soll Menschen über die IT-Branche hinaus für die Gefahren rund um die digitale Einflussnahme durch Cyberkriminelle sensibilisieren. Social-Engineering gab es schon lange vor der Digitalisierung. Betrugsmaschen, Identitätsdiebstahl, vorgetäuschte Autorität und das Ausnutzen von Gefühlen wie Gier oder Angst werden seit Jahren eingesetzt. E-Mail,…
-
Anthropic’s Mythos AI used social engineering to target real people
Testers found that Anthropic’s AI agent Mythos attempted to social engineer Github developers into accepting malicious code. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/anthropics-mythos-ai-used-social-engineering-to-target-real-people/
-
AI agents caught using social engineering in UK security tests
First seen on scworld.com Jump to article: www.scworld.com/news/ai-agents-caught-using-social-engineering-in-uk-security-tests
-
AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems
AISI found AI agents taking unsanctioned online actions, including social engineering and code attacks, during controlled cyber tests. The UK’s AI Security Institute (AISI) has put something uncomfortable on the table: during cyber testing, frontier models didn’t just follow instructions badly. In some runs, they crossed into real-world actions, touched real people and organisations, and…
-
Mythos ran real-life supply chain attack in AI safety body test
Anthropic’s Mythos 5 has been caught orchestrating a real-world open source supply chain attack using social engineering techniques during a test run by the UK’s AI Security Institute. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366647165/Mythos-ran-real-life-supply-chain-attack-in-AI-safety-body-test
-
SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access
SMOKE#SCREEN uses fake Zoom updates to install ScreenConnect RMM, giving attackers persistent remote access while bypassing defenses. Securonix Threat Research has been tracking an active multi-wave campaign they’ve named SMOKE#SCREEN, in which unknown attackers use rotating social engineering lures, fake Zoom updates, Adobe software notices, business document reviews, system maintenance utilities, to silently install ConnectWise…
-
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
The attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/latest-rmm-fueled-phishing-attack-exposes-threat-actor-playbook
-
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Tags: access, adobe, business, cybersecurity, monitoring, social-engineering, software, threat, updateCybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect.The campaign has been codenamed SMOKE#SCREEN by Securonix Threat First seen on thehackernews.com Jump to…
-
Fake AI Tools Target Developers With Infostealers to Steal Credentials and Cloud Secrets
A large-scale malware campaign targeting developers and AI users has been uncovered ,revealing how attackers are weaponizing fake AI tools and cloned GitHub repositories to distribute infostealers and exfiltrate sensitive data. The latest evolution shows a clear tactical shift. Instead of relying solely on social engineering prompts, threat actors are now impersonating legitimate GitHub repositories…
-
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles
-
The $5 million threat: AI Is supercharging phishing attacks
According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. First seen on fortra.com Jump to article: www.fortra.com/blog/5-million-threat-ai-supercharging-phishing-attacks
-
Rund ein Drittel aller Mitarbeiter europäischer Unternehmen fällt immer noch auf Phishing-Angriffe herein
Nach wie vor sind Phishing-, Spear-Phishing und Social-Engineering-Angriffe der häufigste Ausgangspunkt erfolgreicher Cyberangriffe auf europäische Unternehmen. Anfang Juli hat KnowBe4 die Ergebnisse seines neuesten <> vorgestellt. Eine Auswertung der Ergebnisse zeigt: die Erfolgsquote von Phishing-, Spear Phishing und Social Engineering-Angriffen ist nach wie vor außergewöhnlich hoch. Rund ein Drittel aller Arbeitnehmer fällt […] First seen on…
-
Zero-Day-Schwachstelle in Zimbra – Russische Hacker stehlen E-Mails ohne Social Engineering
First seen on security-insider.de Jump to article: www.security-insider.de/laundry-bear-zimbra-half-click-exploit-cve-2025-66376-a-9e40cf73484d8a287196597419348dfd/

