Tagged: Social Engineering
A new tool has emerged on the cybercriminal marketplace—one that has swiftly become a weapon of choice for dozens of groups. This is HeartCrypt, a malware-packing service that disguises malicious code as familiar, legitimate...
The U.S. Department of Justice and British police have brought charges against 19-year-old East London resident Talha Jubair, identified by investigators as one of the key figures in Scattered Spider—the group behind a series...
The story of Noah Urban is one of the clearest illustrations of how teenage socializing and a simple phone call can transform into an instrument of cybercrime. According to an investigation drawing on Discord...
Acronis researchers have reported a fresh campaign that employs a modified FileFix technique to deliver the StealC data stealer. The attackers staged a convincing, multilingual phishing operation that forges pages for various services —...
Cybersecurity researcher Jeremiah Fowler has reported a major data breach linked to Hello Gym, a company that provides telephony services for the fitness industry in the United States and Canada. The exposed dataset contained...
On July 24, 2025, the cryptocurrency platform WOO X suffered a sophisticated targeted attack in which $14 million was siphoned from nine user accounts. All evidence points to the operation being orchestrated by the...
In August of this year, specialists from Israel’s National Digital Agency uncovered a large-scale campaign known as ShadowCaptcha, designed to compromise users through more than a hundred hacked WordPress websites. These sites had been...
Researchers at Check Point Research have uncovered a new targeted campaign, dubbed ZipLine, which leverages the malicious tool MixShell against industrial and high-tech companies. The hallmark of this operation lies in its unorthodox delivery...
Microsoft has issued a warning over the growing surge of large-scale ClickFix phishing attacks and has recommended that system administrators restrict the use of command-line tools and disable the Run dialog in Windows. This...
An attack on Google Classroom has escalated into one of the largest phishing campaigns in recent months. According to Check Point, between August 6 and 12, attackers launched five coordinated waves of distribution, sending...
CloudSEK researchers have uncovered a new attack vector, dubbed ClickFix, which exploits invisible prompt injection and the prompt overdose technique to compromise automated AI summarization systems. The essence of the method lies in concealing...
A massive cryptocurrency theft has once again revealed how vulnerable users remain to the manipulations of social engineering. On August 19, an anonymous Bitcoin holder was stripped of 783 BTC — roughly $89 million...