Tag: social-engineering
-
AI agents caught using social engineering in UK security tests
First seen on scworld.com Jump to article: www.scworld.com/news/ai-agents-caught-using-social-engineering-in-uk-security-tests
-
AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems
AISI found AI agents taking unsanctioned online actions, including social engineering and code attacks, during controlled cyber tests. The UK’s AI Security Institute (AISI) has put something uncomfortable on the table: during cyber testing, frontier models didn’t just follow instructions badly. In some runs, they crossed into real-world actions, touched real people and organisations, and…
-
Mythos ran real-life supply chain attack in AI safety body test
Anthropic’s Mythos 5 has been caught orchestrating a real-world open source supply chain attack using social engineering techniques during a test run by the UK’s AI Security Institute. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366647165/Mythos-ran-real-life-supply-chain-attack-in-AI-safety-body-test
-
SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access
SMOKE#SCREEN uses fake Zoom updates to install ScreenConnect RMM, giving attackers persistent remote access while bypassing defenses. Securonix Threat Research has been tracking an active multi-wave campaign they’ve named SMOKE#SCREEN, in which unknown attackers use rotating social engineering lures, fake Zoom updates, Adobe software notices, business document reviews, system maintenance utilities, to silently install ConnectWise…
-
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
The attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/latest-rmm-fueled-phishing-attack-exposes-threat-actor-playbook
-
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Tags: access, adobe, business, cybersecurity, monitoring, social-engineering, software, threat, updateCybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect.The campaign has been codenamed SMOKE#SCREEN by Securonix Threat First seen on thehackernews.com Jump to…
-
Fake AI Tools Target Developers With Infostealers to Steal Credentials and Cloud Secrets
A large-scale malware campaign targeting developers and AI users has been uncovered ,revealing how attackers are weaponizing fake AI tools and cloned GitHub repositories to distribute infostealers and exfiltrate sensitive data. The latest evolution shows a clear tactical shift. Instead of relying solely on social engineering prompts, threat actors are now impersonating legitimate GitHub repositories…
-
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles
-
The $5 million threat: AI Is supercharging phishing attacks
According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. First seen on fortra.com Jump to article: www.fortra.com/blog/5-million-threat-ai-supercharging-phishing-attacks
-
Rund ein Drittel aller Mitarbeiter europäischer Unternehmen fällt immer noch auf Phishing-Angriffe herein
Nach wie vor sind Phishing-, Spear-Phishing und Social-Engineering-Angriffe der häufigste Ausgangspunkt erfolgreicher Cyberangriffe auf europäische Unternehmen. Anfang Juli hat KnowBe4 die Ergebnisse seines neuesten <> vorgestellt. Eine Auswertung der Ergebnisse zeigt: die Erfolgsquote von Phishing-, Spear Phishing und Social Engineering-Angriffen ist nach wie vor außergewöhnlich hoch. Rund ein Drittel aller Arbeitnehmer fällt […] First seen on…
-
Zero-Day-Schwachstelle in Zimbra – Russische Hacker stehlen E-Mails ohne Social Engineering
First seen on security-insider.de Jump to article: www.security-insider.de/laundry-bear-zimbra-half-click-exploit-cve-2025-66376-a-9e40cf73484d8a287196597419348dfd/
-
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware.”BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet First seen on thehackernews.com…
-
Clover Health Reports Social Engineering Attack to SEC
Experts Warn AI Will Make Phishing, Related Threats Even Worse for Healthcare. Clover Health, a provider of Medicare Advantage health plans and a vendor of AI-enabled clinical decision support tools for physicians, has fallen victim to a social engineering attack, according to an SEC filing. Experts warn that AI tools could make such evolving attack…
-
Wenn geteilte KI-Chats zur Malware-Falle werden
Das Threat-Hunting-Team von Zscaler analysierte eine neue Malware-Kampagne, die unter dem Namen ‘ClaudeFix” verfolgt wurde. Cyberkriminelle kombinieren dabei die bewährte Social-Engineering-Taktik ‘ClickFix” mit dem Missbrauch legitimer Funktionen des KI-Assistenten Claude von Anthropic. Das primäre Ziel der aufgedeckten Kampagne sind Softwareentwickler und IT-Experten, welchen über vermeintlich harmlose, geteilte KI-Chats heimlich der MacSync-Stealer zugespielt wird. Vom Fake-Portal…
-
Warum traditionelles Trainings zur Cybersicherheit im KI-Zeitalter nicht mehr greifen
Traditionelle Schulungen und Trainings zum Bewusstsein für Cybersicherheit basieren auf standardisierten Lehrinhalten und -formaten, die sporadisch meist nur einmal im Jahr unterrichtet werden. Ihr Ziel: die Anhebung des Cybersicherheits-Bewusstseins der menschlichen Mitarbeiter eines Unternehmens. Das Problem: ihr erhoffter Effekt bleibt immer häufiger aus. Angreifer setzen zur Unterstützung ihrer Social-Engineering-, Phishing- und Spear-Phishing-Angriffe immer […] First…
-
Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials
Tags: access, ai, backdoor, cloud, cyber, defense, detection, espionage, government, iran, phishing, powershell, social-engineeringIran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather than just endpoints. Recent activity shows tightly integrated social engineering, cloud abuse, and fileless PowerShell tradecraft that significantly complicate detection and response. APT42, also tracked as TA453 in some reporting, is…
-
TELEPUZ Web Injector Can Steal Cookies, Execute JavaScript, and Replace IBAN Details
A rapidly evolving malware family dubbed TELEPUZ, a modular and lightweight threat that is gaining traction through a ClickFixVIDAR infection chain. Despite a relatively small command-and-control (C2) footprint, the pace of development and distribution suggests an emerging large-scale operation. The infection begins with ClickFix social engineering, where victims are tricked into executing a malicious PowerShell…
-
6 Empfehlungen für Unternehmen im Umgang mit KI-Risiken
Künstliche Intelligenz verändert die Cybersicherheit-Landschaft grundlegend. KI-gestützte Phishing-Angriffe, Deepfakes und automatisierte Social-Engineering-Kampagnen zählen inzwischen zu den größten Sorgen deutscher Unternehmen. Der aktuelle AI-Security-Report 2026 von Hornetsecurity by Proofpoint zeigt jedoch: Während die Bedrohungslage zunehmend erkannt wird, bleibt die praktische Umsetzung vielerorts hinter den Erwartungen zurück. Die Ergebnisse der Studie verdeutlichen, dass die Herausforderung heute weniger…
-
Forescout analysiert Phishing-Kampagne mit missbrauchten RMM-Tools
SeasonalInvite zeigt, wie wirkungsvoll Angreifer Social Engineering, legitime Verwaltungssoftware und skalierbare Webinfrastrukturen miteinander kombinieren können. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/forescout-analysiert-phishing-kampagne-mit-missbrauchten-rmm-tools/a45806/
-
KnowBe4 und AWS bündeln Kräfte gegen Social Engineering, Deepfakes und Schatten-KI
KnowBe4 und AWS vertiefen ihre Zusammenarbeit, um Unternehmen schneller gegen Social Engineering, Deepfakes, menschliche Risiken und Schatten-KI abzusichern. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/knowbe4-und-aws-buendeln-kraefte-gegen-social-engineering-deepfakes-und-schatten-ki/a45794/
-
Hackers Use PasteRun Commands to Deploy ClickLock Stealer Against Mac Users
Hackers are actively targeting macOS users with a newly identified infostealer dubbed “ClickLock Stealer,” leveraging paste-and-run social engineering techniques to bypass Apple’s native security protections without requiring exploits or elevated privileges. Despite macOS protections such as Gatekeeper, Transparency, Consent, and Control (TCC), System Integrity Protection (SIP), and mandatory code signing, threat actors are increasingly deploying…
-
ACR Stealer Uses ClickFix, WebDAV, and Steganography to Steal Browser Credentials and Tokens
A surge in ACR Stealer activity from late April through mid-June 2026, with operators combining ClickFix social engineering, WebDAV-hosted payloads, PowerShell obfuscation, and steganography to compromise enterprise users. The malware operations rely on ClickFix social-engineering lures to trick victims into pasting attacker-supplied commands into Windows Run dialogs or command prompts, ultimately stealing browser credentials, session…
-
Now, even Russia’s most elite hackers are using Clickfix to infect devices
The social-engineering technique has primarily been a tool of financially motivated criminals. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/now-even-russias-most-elite-hackers-are-using-clickfix-to-infect-devices/
-
5,811 arrests, $293 million seized over social engineering scams
Criminals who pose as police officers, romantic partners, and business suppliers have built fraud operations that reach across continents. A four-month enforcement campaign … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/interpol-fraud-bust-social-engineering-scams/
-
Microsoft Entra Passkey Enrollment Abused in Operator-Controlled Vishing Campaign
A focused vishing campaign that weaponizes Microsoft Entra passkey enrollment as a social-engineering vector to enable account takeover and downstream data extortion. The threat actor begins by registering domains that include the term “passkey” (for example, assignpasskey[.]com, deploypasskey[.]com, passkeydeploy[.]com, passkeyadd[.]com, setpasskey[.]com) and creating per-target subdomains. Microsoft Entra ID login pages. Pages load generic Microsoft styling…
-
Umbrij Malware Lets ToddyCat Hackers Hijack Gmail Accounts Through Google API Abuse
A targeted campaign in which the ToddyCat (aka APT-style) group leverages a previously observed loader family, Umbrij, to hijack Gmail accounts by abusing Google APIs. Chaining that capability to broad remote access achieved through a malicious MSI installer masquerading as the Kuailian/LetsVPN client. The operation blends social engineering with a sophisticated in-memory loader and a…
-
The fake report message that ends with a stolen Reddit account
A direct message arrives on Reddit from a stranger, and it invites a reply. That reply is the point. This scheme runs on social engineering, with no malware and no malicious … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/reddit-false-report-scam-direct-message/
-
ESET Threat Report H1 2026 Highlights Malicious AI Skills, ClickFix Surge, and EDR Killers
ESET’s H1 2026 threat report shows attackers accelerating the use of familiar playbooks with AI-flavored lures, social engineering, and defense evasion rather than inventing entirely new ones. The clearest signals are the rise of malicious AI skills, a doubled ClickFix footprint, first-wave AI-powered Android malware, record QR-code phishing, and a growing ecosystem of EDR killers.…
-
REF6045 Uses SCMBANKER PowerShell Toolkit to Target Mexican Banking Customers
A human-operated Mexican banking fraud campaign tracked as REF6045 has been observed using a bespoke PowerShell toolkit SCMBANKER to turn commodity click-fraud lures into operator-assisted account takeovers and payment diversion. The operation relies on social engineering through fake CAPTCHA/verification pages that trick victims into running a single command from the Windows Run dialog. That command…
-
Hackers Abuse Cross-Tenant Teams Chat to Deliver EtherRAT Through Malicious MSI Loader
A coordinated social-engineering campaign observed in late June 2026 combined email phishing with an abused Microsoft Teams cross”‘tenant chat to deliver a sophisticated EtherRAT implant via a malicious MSI loader. Initial access began with a targeted email masquerading as internal communication: an “Employee Survey” HTML message containing a PDF lure. When the victim opened the…

