Tag: social-engineering
-
Webinar: How Google Workspace breaches happen and what to do next
Google Workspace breaches can begin with social engineering or forgotten third-party integrations rather than sophisticated exploits. This webinar examines real-world breaches, what happens during the critical first hours, and the security controls that can make the greatest difference. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/webinar-how-google-workspace-breaches-happen-and-what-to-do-next/
-
Apollo Confirms Data Breach Amid Cyberattacks Targeting Financial Firms
Apollo Global Management confirmed a social-engineering breach exposing sensitive personal data amid a wider hacking campaign targeting financial firms. The post Apollo Confirms Data Breach Amid Cyberattacks Targeting Financial Firms appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-apollo-data-breach-financial-firms-social-engineering/
-
From Fake Workers to Account Recovery: The Growing Identity Verification Risk
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and social engineering attacks from gaining legitimate access. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/from-fake-workers-to-account-recovery-the-growing-identity-verification-risk/
-
From Fake Workers to Account Recovery: The Growing Identity Verification Risk
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and social engineering attacks from gaining legitimate access. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/from-fake-workers-to-account-recovery-the-growing-identity-verification-risk/
-
ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack
Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/25/reliaquest-breach-social-engineering/
-
ReliaQuest Rejects Compromise Claims After ShinyHunters Incident
ReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systems First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/reliaquest-not-compromised-by/
-
ReliaQuest confirms failed data-theft attack after ShinyHunters breach
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/
-
Hackers Impersonate Security Staff to Steal Credentials in ReliaQuest Social Engineering Attack
Tags: access, attack, authentication, credentials, cyber, hacker, identity, malicious, mfa, social-engineering, threatReliaQuest has reported a targeted social engineering attack in which threat actors impersonated company security personnel, used a spoofed domain, and successfully persuaded one employee to approve a malicious multi-factor authentication (MFA) request. The incident, detected on August 22, 2026, resulted in the temporary exposure of a single identity session with view-only access to ReliaQuest’s…
-
New macOS Malware Clones Your Logged-In Browser and Gives Hackers Remote Control.
AmnesiaStealer, a multi-stage macOS infostealer written in Rust that moves beyond conventional credential theft by giving attackers covert, interactive control over a victim’s authenticated Chromium browser sessions. The malware is being distributed through a ClickFix social-engineering campaign that directs users to counterfeit GitHub download pages. Instead of delivering a legitimate application, the sites instruct visitors…
-
macOS ClickFix Crimekit Uses Polygon Smart Contracts to Deploy AMOS Stealer and XMRig Miner
A macOS-focused ClickFix campaign is abusing Polygon smart contracts to conceal its live command-and-control infrastructure while deploying an Atomic macOS Stealer (AMOS) variant, a persistent backdoor, and an XMRig cryptominer. The operation combines fake CAPTCHA social engineering with EtherHiding, making infrastructure rotation far more resilient than traditional hardcoded C2 schemes. The command decodes to a…
-
Apollo Global Management Data Breach Exposes Social Security Numbers and Personal Data
Tags: access, breach, cloud, cyber, data, data-breach, incident, social-engineering, threat, unauthorizedApollo Global Management has disclosed a cyber incident in which attackers gained unauthorized access to cloud platforms and may have acquired highly sensitive personal information. The alternative asset manager said the intrusion occurred between July 6 and July 10 after threat actors used social engineering techniques to compromise its cloud environment. The company has not…
-
New malware campaign combines social engineering with defense evasion
First seen on scworld.com Jump to article: www.scworld.com/brief/new-malware-campaign-combines-social-engineering-with-defense-evasion
-
Drei Mitarbeiterkonten betroffen – Levi Strauss meldet Datenabfluss nach Social-Engineering-Angriff
First seen on security-insider.de Jump to article: www.security-insider.de/levi-strauss-cyberangriff-social-engineering-unternehmensdaten-a-ba2a5940a4ce9e231ac320e9b5d62d23/
-
ClearFake Fake CAPTCHA Campaigns Use New WordlistLoader to Deploy Amatera Stealer
A new ClearFake infection chain using a previously undocumented intermediate payload dubbed WordlistLoader to deploy Amatera Stealer. The campaign combines compromised websites, fake CAPTCHA overlays, ClickFix social engineering, WebDAV-hosted DLLs and advanced anti-analysis mechanisms to deliver one of the more actively evolving information stealers currently tracked. Clicking the “I’m not a robot” control triggers a…
-
No-Filter ‘Kriminal’ AI Platform Raises Cybercrime Concerns
The AI company officially forbids illicit use, while offering guardrail-free social engineering, offensive cybercrime, and OSINT scanning to anyone with a bit of cryptocurrency. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/no-filter-kriminal-ai-platform-cybercrime-concerns
-
AI Cybersecurity Platform
Tags: ai, attack, automation, cloud, credentials, cybercrime, cybersecurity, data, endpoint, iot, malware, network, ransomware, saas, social-engineering, theft, toolOrganizations are generating unprecedented amounts of digital data from endpoints, networks, cloud workloads, applications, identities, IoT devices, SaaS platforms, and operational technology. At the same time, cybercriminals are becoming more sophisticated, using automation, credential theft, social engineering, malware, ransomware, living-off-the-land techniques, and increasingly AI-assisted attack methods. Traditional cybersecurity tools remain important, but security teams can…
-
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
esearch by: JaromÃr HoÅ™ejšà (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique, which prompts victims to execute a PowerShell command. This leads to two stages of additional downloaders and…
-
Kimsuky Uses Local AI Development Environment to Expand Cyber Espionage Tooling in Operation GitPower
Tags: ai, cyber, data, espionage, intelligence, malware, north-korea, phishing, social-engineering, threatNorth Korean state-backed threat actor Kimsuky is extending its established espionage playbook with locally hosted artificial intelligence tooling, according to new research into an activity cluster tracked as Operation GitPower. The campaign retains familiar phishing-led intrusion chains but shows the operators preparing AI-assisted capabilities for malware development, data analysis, social engineering, and operational automation. The…
-
AI Gives Defenders an Edge in the Vulnerability Race
Tags: ai, attack, breach, data, exploit, extortion, mandiant, phone, risk, scam, social-engineering, software, supply-chain, tool, vulnerabilityMandiant Consulting’s Charles Carmakal on AI, Social Engineering and Extortion. Attackers are using AI to find vulnerabilities, build exploit tools and analyze stolen data, but defenders still hold an advantage. The greater risks now come from human-sounding phone scams, AI-assisted extortion and software supply chain attacks, said Charles Carmakal, CTO at Mandiant Consulting. First seen…
-
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware.CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within…
-
Levi Strauss Breach Began With Social Engineering of 3 Employees
Levi Strauss says hackers socially engineered three employees and stole corporate data, highlighting the growing threat of identity-based attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity-threats/news-levi-strauss-social-engineering-data-breach/
-
When Credentials Are No Longer Enough: Device Trust in the AI Era
AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation, and geolocation become easier to bypass. Specops explains why organizations are increasingly adding device trust to their Zero Trust strategies. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/when-credentials-are-no-longer-enough-device-trust-in-the-ai-era/
-
Levi Strauss Hit by Cyberattack, Hackers Use Social Engineering to Steal Corporate Data
Tags: business, computer, corporate, cyber, cyberattack, cybersecurity, data, hacker, social-engineering, unauthorizedLevi Strauss & Co. has reported a cybersecurity incident in which an unauthorized third party used social engineering techniques to compromise three employee-issued computers and exfiltrate unspecified corporate information. According to the apparel maker, the intrusion was contained, with no evidence that consumer data was affected or that business operations were disrupted. Levi Strauss Cyberattack…
-
Cyberkriminalität ist zu einer industrialisierten Wirtschaft geworden
Cyberkriminalität hat sich von isolierten Angriffen zu einer ausgefeilten, industrialisierten Wirtschaft entwickelt, die von fortschrittlicher KI, Automatisierung und spezialisierten kriminellen Dienstleistungen angetrieben wird. Heutige Angreifer agieren weniger wie opportunistische Hacker und mehr wie Unternehmen sie mieten Infrastruktur, kaufen Phishing-Kits, lagern Geldwäsche aus und nutzen KI, um überzeugende Social-Engineering-Kampagnen mit beispielloser Geschwindigkeit und Größe zu… First…
-
Levi Strauss & Co. says hackers stole corporate data in cyberattack
Levi Strauss & Co. (Levi’s) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/levi-strauss-and-co-says-hackers-stole-corporate-data-in-cyberattack/
-
Levi Strauss says hackers breached employee computers, accessed corporate data
Intruders exfiltrated certain corporate information after gaining access to three company-issued computers through a social engineering attack, Levi Strauss reported. First seen on therecord.media Jump to article: therecord.media/levis-data-breach-social-engineering
-
Social-Engineering mit Real-Time-Coaching im entscheidenden Moment verhindern
KnowBe4 führt die Lösung Real-Time Coaching ein. Sie stellt genau in dem Moment, in dem riskantes Verhalten auftritt, einen sofort verfügbaren, kurz und prägnant formulierten Sicherheitstipp bereit. Social-Engineering-Angriffe gehören nach wie vor zu den effektivsten Methoden, mit denen Angreifer technische Abwehrmaßnahmen umgehen, und sie lassen sich immer schwerer aufdecken. Laut dem Verizon-Data-Breach-Investigations-Report 2026 spielt der menschliche Faktor…
-
Who Recruits Young Hackers First?
Ricky Handschumacher on Redirecting Talent Before Cybercrime Takes Hold. Young hackers may enter cybercrime through gaming, status-seeking and online communities before they understand the consequences. Reformed criminal hacker Ricky Handschumacher explains why the industry must reach them early, offer credible pathways and take social engineering more seriously. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/who-recruits-young-hackers-first-a-32441
-
Social-Engineering-Day KI beflügelt Social-Engineering
In diesem Jahr fällt der Social-Engineering-Day auf den 6. August, dieser Aktionstag soll Menschen über die IT-Branche hinaus für die Gefahren rund um die digitale Einflussnahme durch Cyberkriminelle sensibilisieren. Social-Engineering gab es schon lange vor der Digitalisierung. Betrugsmaschen, Identitätsdiebstahl, vorgetäuschte Autorität und das Ausnutzen von Gefühlen wie Gier oder Angst werden seit Jahren eingesetzt. E-Mail,…
-
Anthropic’s Mythos AI used social engineering to target real people
Testers found that Anthropic’s AI agent Mythos attempted to social engineer Github developers into accepting malicious code. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/anthropics-mythos-ai-used-social-engineering-to-target-real-people/

