Tag: social-engineering
-
A familiar face is no longer proof: rethinking social engineering defence for the deepfake era
Deepfakes have spent much of their short history being treated as a curiosity. According to Anne Cutler, cybersecurity expert at Keeper Security, that complacency is now a risk in itself. “For many people, deepfakes still feel like an internet novelty a fake celebrity video, an altered image or an amusing example of what AI The…
-
Japanese Police Impersonation Scam Operation Dismantled as 16 Suspects Detained in Timor-Leste
Timor-Leste investigators have dismantled a suspected cross-border telecom fraud operation in Dili, detaining 16 individuals accused of impersonating Japanese police officers to defraud victims in Japan. The raid exposed a professionally staged social-engineering setup that included counterfeit law-enforcement props, Japanese-language call scripts and infrastructure designed to lend credibility to “digital arrest” scams. Authorities said the…
-
MSP360 RMM Abused in Phishing Campaigns to Deploy ScreenConnect
Attackers are leaning on legitimate remote management software to slip past defenses. In July 2026, Microsoft Defender Experts tracked phishing campaigns hitting organizations in multiple industries with a disguised MSP360 Remote Monitoring and Management (RMM) installer, spread through meeting invitations, PDF-themed lures, software update prompts, and other social-engineering bait. First seen on thecyberexpress.com Jump to…
-
TerminalFix Attacks Deploy Lorem Ipsum Loader to Create Covert Tunnels Into Corporate Networks
A newly tracked intrusion set, STAC4924, is using TerminalFix social-engineering lures to deploy the Lorem Ipsum Loader and establish covert reverse tunnels into enterprise environments. The activity shifts the familiar ClickFix model from the Windows Run dialog to Windows Terminal, increasing the likelihood that victims execute complex PowerShell payloads without recognizing the risk. Unlike conventional…
-
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content.”Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected First seen on thehackernews.com Jump…
-
Threat groups ramp up social-engineering attacks against healthcare sector
Tags: attack, credentials, cybercrime, group, hacker, healthcare, phishing, social-engineering, tactics, threatHackers linked to high-profile cybercrime groups have used voice-phishing tactics to trick workers into giving up credentials in recent attacks. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/threat-groups-social-engineering-attacks-healthcare/831383/
-
Webinar tomorrow: Inside real-world Google Workspace breaches
Tomorrow’s webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/webinar-tomorrow-inside-real-world-google-workspace-breaches/
-
The latest deepfake numbers give CISOs plenty to worry about
AI is letting cybercriminals reach deeper into organizations than a phishing email ever could. 41% of CISOs reported at least one social engineering incident involving a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/22/cisos-deepfake-incidents-social-engineering-survey/
-
CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns
Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to detect First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/update-incident-response/
-
Phishing-Angriffe unter dem Deckmantel von Passkeys
Eine aktuelle Angriffskampagne die von Microsoft aufgedeckt wurde zeigt, wie konsequent Cyberkriminelle technische Sicherheitsmechanismen mit Social-Engineering umgehen können. Sie nutzen Passkeys, Multi-Faktor-Authentifizierung und Single Sign-on als Vorwand für gezielte Social-Engineering-Angriffe auf Unternehmenskonten und Cloud-Umgebungen. Dabei geben sie sich beispielsweise als Mitarbeiter des IT-Supports aus, kontaktieren Beschäftigte per Telefon oder SMS teilweise über deren private Mobiltelefone […]…
-
Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites
A suspected supply-chain compromise involving Brevo has exposed visitors and WordPress administrators across more than 100,000 websites to malware. Attackers allegedly abused Brevo-hosted JavaScript assets, signup forms, unsubscribe pages and chat widgets to distribute a WordPress backdoor and ClickFix social-engineering payloads. Brevo, formerly Sendinblue, disclosed a separate security incident on September 10 involving an SAML…
-
Handala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAM
A previously undocumented HEAVYGRAM and CRUDEEXCLUDE malware samples linked with moderate confidence to the Iran-aligned Handala Hack operation. The campaign combines targeted social engineering, Microsoft Defender exclusion abuse, multi-stage loaders, and Telegram-based command-and-control to surveil Iranian dissidents, journalists, and people perceived as opponents of the Iranian government. The research expands on U.S. government disclosures issued…
-
Authentifiziert ist nicht gleich autorisiert
Seit Mai 2026 beobachtet Microsoft-Security-Research Social-Engineering-Kampagnen, bei denen Angreifer das Thema Passkeys und Single-Sign-On (SSO) als Vorwand nutzen, um Sicherheitsbarrieren zu umgehen. Anrufer gaben sich als interne IT-Helpdesk-Mitarbeiter aus, kontaktierten Beschäftigte auf ihren privaten Mobiltelefonen und teilten ihnen mit, ihre Passkey- oder Mehrfaktor-Authentifizierung müsse dringend aktualisiert werden. Die Anrufe führten die Opfer auf täuschend echte…
-
GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation
Tags: access, breach, business, credentials, cyber, email, exploit, microsoft, phishing, social-engineeringA newly identified device-code phishing kit dubbed GhostCode exploits Microsoft Entra device enrollment to maintain access after stolen tokens are revoked. GhostCode begins with business-email social engineering rather than a conventional credential-harvesting page. Operators impersonated procurement staff from legitimate organizations, including BJ’s Wholesale Club, and submitted benign inquiries through Salesforce contact forms. Once a sales…
-
Webinar: How malicious OAuth apps can lead to Google Workspace breaches
Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/webinar-how-malicious-oauth-apps-can-lead-to-google-workspace-breaches/
-
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments.The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief…
-
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/
-
Attackers call employees’ personal phones to break into Microsoft 365 accounts
Attackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into handing over access to … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/microsoft-365-social-engineering-personal-phones/
-
Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
Threat actors are impersonating corporate IT helpdesk staff in an active social-engineering campaign that hijacks Microsoft 365 identities, establishes MFA persistence, and systematically collects data from SharePoint, OneDrive, and Exchange Online. Microsoft Security Research said it has observed the cloud-focused intrusions since May 2026. The activity is marked by unusual sign-ins, attacker-added authentication methods, extensive…
-
Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
Threat actors are increasingly using ClickFix social-engineering lures and search-engine malvertising to deploy MacSync Stealer, a macOS-focused information stealer and remote-access staging framework sold through a malware-as-a-service model. The campaigns do not require a macOS vulnerability; instead, they abuse user trust by persuading victims to paste attacker-controlled commands into Terminal, sidestepping traditional file-centric protections. However,…
-
Get to Know Our VP of Sales, EMEA: QA with Stewart Gregory
Doppel is building the leading AI-native platform for social engineering defense, helping organizations detect and disrupt threats like phishing, brand impersonation, and executive deepfakes before they cause harm. As the company expands its footprint in Europe, the Middle East, and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/get-to-know-our-vp-of-sales-emea-qa-with-stewart-gregory/
-
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/clickfix-campaigns-legitimate-services-persistent-access
-
Social-Engineering-Angriff – Datenpanne legt Informationen von 1,6 Millionen RingCentral-Konten offen
First seen on security-insider.de Jump to article: www.security-insider.de/ringcentral-hack-social-engineering-16-millionen-konten-a-241924bbdbbec3a2d29fa0df41e1099a/
-
Spring Ring Campaign Uses Teams Vishing, PowerShell RAT and NTLM Relay Attacks
A coordinated social-engineering operation tracked as Spring Ring abused Microsoft Teams external accounts to impersonate corporate IT help desks, targeting more than 150 employees across at least 10 organizations between January and April 2026. The campaign demonstrates how attackers can turn trusted collaboration channels into an initial-access route for remote-control tools, custom malware, and attempted…
-
FBI raises alarm over deceptive phishing campaign targeting prominent people
The ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts. First seen on cyberscoop.com Jump to article: cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/
-
Hackers Pose as IT Support on Microsoft Teams to Target More Than 150 Employees
A coordinated social-engineering campaign dubbed Spring Ring used external Microsoft Teams accounts to impersonate corporate IT help desk staff and target more than 150 employees across at least 10 organizations between January and April 2026. The operation demonstrates how attackers are shifting phishing activity from email into trusted collaboration platforms, using live voice calls to…
-
Hackers Abuse Legitimate ChatGPT Shared Links to Deploy NetSupport RAT
Threat actors are abusing legitimate ChatGPT shared-conversation URLs to host social-engineering lures that steer victims into a ClickFix-style infection chain, ultimately delivering a NetSupport remote-access tool (RAT). The observed chain begins with a legitimate ChatGPT shared link, chatgpt.com/s/t_6a80bc61c434819190c3eae5932307e8, which displays a fabricated availability notice claiming: “We are experiencing high traffic now. Continue on our backup…
-
Chefetage unterschätzt Risiken – CISOs kämpfen allein gegen KI-Social-Engineering
First seen on security-insider.de Jump to article: www.security-insider.de/ki-social-engineering-cisos-fehlt-rueckhalt-geschaeftsfuehrung-a-276f349dc3eb81c533bb34d574b1a317/
-
KI überholt fast alle menschlichen Cyberrisiken nur Social Engineering bleibt gefährlicher
KI steigt laut SANS Security Awareness & Culture Report 2026 zum zweitgrößten menschlichen Cyberrisiko auf. Gleichzeitig fehlen vielen Awareness-Teams Personal und Ressourcen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ki-ueberholt-fast-alle-menschlichen-cyberrisiken-nur-social-engineering-bleibt-gefaehrlicher/a46292/
-
Stage 2, Launch: The Moment the Attack Goes Live
Launch is the second stage of the social engineering attack chain: when staged domains, personas, and infrastructure go live. Learn why it’s the midpoint, not the start. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/stage-2-launch-the-moment-the-attack-goes-live/

