Social Engineering & Phishing

Stories 127
Sources 264
Updated 2026.07.25
Steam forum posts use ClickFix tricks to infect gamers with XMRig cryptomining malware
Attackers are posting fake troubleshooting replies on Steam discussion forums that trick gamers into infecting their own Windows PCs with cryptocurrency-mining malware. The campaign uses ClickFix social engineering, telling users to open PowerShell as an administrator and run a command that installs XMRig from msfconfig[.]icu, adds Microsoft Defender exclusions, creates a scheduled task named "XMRig-[computer name]," and persists as C:\Windows\Background\system.exe. — Steam users and home PC owners can be compromised just by following what looks like a helpful forum fix, leading to slowed systems, higher power use, and weakened defenses. People should avoid running PowerShell commands from forum posts, and anyone who did should check for XMRig processes, scheduled tasks, Defender exclusions, and the C:\Windows\Background\system.exe file.
Sources: Steam forum ClickFix attacks infect gamers with XMRig cryptominers
SourTrade malvertising campaign uses fake Solana, Luno, and TradingView sites to assemble malware inside victims’ browsers
A large online ad scam is sending retail traders and cryptocurrency users to fake Solana, Luno, and TradingView pages that build malware directly inside the victim’s browser before download. Confiant says the SourTrade campaign has run since late 2024 across 25 languages in 12 countries, mainly in Asia Pacific and Latin America, using JavaScript, SharedWorker, and Service Worker features to assemble a unique malicious executable in memory from a clean Bun binary and remote components so no finished file crosses the network. — People looking for trading or crypto software through ads or sponsored search results could end up downloading malware that steals passwords, wallet data, and other sensitive information. Users should avoid ad-linked downloads and get software only from official vendor sites, while defenders should watch for this same-origin browser download technique and fake finance-brand pages.
Sources: Malicious sites use JavaScript to build malware in browser memory, Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
Sextortion scammers use ShinyHunters breach data from Amtrak, Hallmark, Substack and others to demand $2,000 in Bitcoin
Scammers are using email addresses exposed in past ShinyHunters-linked breaches to send sextortion emails that demand $2,000 in Bitcoin. BleepingComputer says the campaign cites real breached companies including Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill to make the threats look credible, but there is no evidence the sender actually hacked recipients' devices or recorded them. — People whose email addresses were exposed in earlier breaches may now face more believable extortion emails, even if their devices were never compromised. Affected users should not pay, should treat messages claiming webcam compromise with skepticism, and should secure accounts exposed in prior breaches with password changes and phishing awareness.
Sources: ShinyHunters data leaks fuel $2,000 sextortion email scam
Pope’s Click To Pray app exposed data for more than 719,000 users through an API authorization flaw
The Vatican-backed Click To Pray app exposed personal data tied to more than 719,000 user accounts, potentially putting users at risk of phishing and account abuse. A researcher says an insecure direct object reference (IDOR) flaw in the app’s API let anyone enumerate sequential user IDs and retrieve names, email addresses, countries, birth dates, and account status, while the sign-up flow also returned the email-verification token directly in the response. — This affects a large global user base, including many potentially vulnerable non-technical users who could now be targeted with convincing scam or phishing emails. Users should be cautious of messages claiming to come from the Vatican or the app, and the operator should urgently fix the API, invalidate exposed verification tokens, and review whether data was accessed.
Sources: Pope's official prayer app commits cardinal sin, leaks 700K+ users' info
Europol flags 4,340 URLs tied to The Com extremist network in June-July 2026 crackdown
Europol says it flagged 4,340 URLs for removal during a June-July 2026 operation targeting online content linked to The Com, a decentralized extremist network that recruits and abuses young people online. The action was run by Europol's EU Internet Referral Unit and Spain's CITCO with investigators from nine countries, and focused on content tied to self-harm, child sexual abuse material, violent attacks, grooming, doxing, swatting, and attack manuals; Europol says The Com includes subgroups involved in cyber intrusions and ransomware. — This matters because The Com blends violent extremism with cyber-enabled abuse such as sextortion, doxing, swatting, and ransomware, often targeting minors through mainstream online platforms. Platforms, investigators, schools, and families should watch for coded recruitment content and coercion tactics, while defenders should note the group’s overlap with cybercrime activity.
Sources: Europol flags 4,340 URLs for removal in 'The Com' crackdown, Europol flags 4,340 'horrific' URLs linked to The Com
Hackers hijack hotel and conference Wi-Fi DNS settings to steal Microsoft 365 accounts
Hackers are compromising Wi-Fi gateways at hotels and conference centers and changing their internet settings so travelers are sent to fake Microsoft 365 login pages. ReliaQuest says the campaign has been active since at least June 2026 and has affected organizations across finance, legal, healthcare, energy, retail, and professional services in the U.S., India, Saudi Arabia, and elsewhere. The attackers altered DNS settings, used fake domains including m365-owa[.]com and owa-ms365[.]com, and in some cases abused Microsoft device-code sign-in flows to obtain legitimate OAuth session tokens that can bypass multi-factor authentication. — Traveling employees and conference attendees can have work accounts stolen just by using a compromised venue Wi-Fi network. Organizations should push always-on full-tunnel VPN use, disable device-code authentication where unnecessary, review Microsoft Entra ID logs, and treat hotel or event Wi-Fi as hostile until proven otherwise.
Sources: Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Abbott investigates ShinyHunters-linked breach of Cancer Diagnostics systems and a separate claimed LabCentral portal intrusion
Abbott says attackers got into a limited number of internal systems in its Cancer Diagnostics business, and it is separately investigating a claimed breach of its LabCentral customer portal. The confirmed incident followed extortion claims by ShinyHunters, which said it used a vishing attack and a compromised Microsoft Entra single sign-on account to access legacy Exact Sciences systems and steal data from services including SharePoint, ServiceNow, Databricks, and Coupa; Abbott said the LabCentral claim is unrelated. — This could affect patients, customers, and healthcare partners if the claimed theft of personal, medical, or contract data is confirmed. Healthcare organizations and Abbott customers should watch for notifications, review account security around Microsoft Entra and portal access, and be alert to follow-on phishing or fraud.
Sources: Abbott Laboratories probes two cyber incidents amid extortion claims, In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
German-led operation dismantles Kratos phishing kit infrastructure and arrests alleged developer in Indonesia
German and Indonesian authorities say they dismantled the Kratos phishing-as-a-service platform, which was used to steal Microsoft account logins and session cookies from victims in more than 30 countries. Prosecutors and the BKA said the operation neutralized more than 200 servers and led to the arrest in Indonesia of the alleged developer and technical administrator. Authorities estimate more than 1,800 criminal customers used Kratos for roughly 15,000 phishing campaigns a month since 2024. — Kratos helped low-skill criminals run convincing Microsoft-themed phishing campaigns at scale, including attacks that could bypass multi-factor authentication by stealing session cookies. Organizations should review Microsoft 365 phishing defenses, hunt for token and session theft, and warn users about fake login pages and document lures.
Sources: Kratos phishing-as-a-service kit loses its battle with international law enforcement, Police dismantle Kratos phishing platform, arrest developer, Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA (+1 more)
Chick-fil-A says credential stuffing attacks breached customer loyalty accounts in June 2026
Chick-fil-A says attackers broke into some customer loyalty accounts after using stolen passwords from other sources, exposing personal and account data. The automated credential-stuffing attacks targeted the Chick-fil-A website and mobile app between June 17 and June 19, 2026 and affected Chick-fil-A One accounts. Exposed data can include names, email addresses, membership numbers, mobile pay numbers, QR codes, reward balances, card last four digits, and in some cases birth dates, phone numbers, and addresses. — Affected customers could face account takeover, fraud involving stored balances, and follow-on phishing or identity misuse. Users should reset reused passwords and review linked payment and loyalty accounts, while defenders should watch for credential-stuffing activity and strengthen login protections.
Sources: Chick-fil-A discloses data breach after credential stuffing attacks, Chick-fil-A Accounts Get Fried in Credential Stuffing Attack, Chick-fil-A data breach affects more than 13,000 customers
Illinois man gets prison sentence for phishing and hijacking more than 750 women’s Snapchat accounts
A U.S. court sentenced an Illinois man to 76 months in prison for using social engineering to break into hundreds of women’s Snapchat accounts and steal intimate photos. Prosecutors said Kyle Svara posed as Snap support between May 2020 and February 2021, used anonymized phone numbers to phish Snapchat access codes from more than 750 women, accessed about 517 accounts, and then enabled two-factor authentication to lock victims out. Court records also say he traded or sold stolen images online and advertised account-hacking services through Kik. — This shows how simple impersonation and one-time-code phishing can turn into large-scale account takeover and extortion-style abuse even without malware or software exploits. Snapchat users should be wary of messages claiming to be from support, never share login codes, and review account recovery and two-factor settings if they suspect compromise.
Sources: Man gets six years for hacking 750 women's Snapchat accounts
Fake Claude desktop app in Bing ads delivers SectopRAT malware through Anthropic-hosted page
Attackers used sponsored Bing search results and a fake Claude desktop app to infect organizations with remote-access and info-stealing malware. Huntress says the campaign, dubbed FakeAgent, compromised at least 29 organizations on July 21-22, 2026. The lure used a malicious Claude Artifact hosted on a legitimate Claude.ai domain, then delivered a fake ClaudeDesktop.exe that sideloaded a malicious libcef.dll to install SectopRAT, also known as ArechClient2, and set persistence via a scheduled task created by DockerDesktop.exe. — People searching for trusted software can be infected even when the lure appears on a real vendor domain. Organizations should block or scrutinize sponsored search results, hunt for SectopRAT indicators, and remind users to verify downloads through known-good vendor paths.
Sources: Fake Claude app promoted by Bing ads pushes SectopRAT malware
CISA says Russian group Laundry Bear exploited Zimbra zero-click flaw CVE-2025-66376 to steal email and bypass MFA
CISA says a Russian espionage group stole email and account data from organizations running Zimbra mail servers by abusing a flaw that could trigger just by opening a malicious email. The group, tracked as Laundry Bear or Void Blizzard, exploited Zimbra Collaboration Classic UI XSS flaw CVE-2025-66376 as a zero-day before its November 2025 patch, then used it to exfiltrate 90 days of mail, credentials, Global Address List data, 2FA tokens, and create Zimbra application passcodes for continued access; CISA also says the campaign used adversary-in-the-middle phishing pages impersonating Zimbra logins. — Organizations using Zimbra, especially in government, defense-related, education, energy, media, and NGO sectors, should treat this as urgent because opening a single email could have exposed mailbox contents and long-term account access. Patch Zimbra, hunt for the listed indicators, revoke unauthorized app passcodes, review mailbox access, and reset affected credentials.
Sources: Russian hackers exploit Zimbra zero-click flaw for email theft, Year-long Russian attacks infect users as soon as they look at an email, International alert spotlights Russia-linked attacks on Zimbra webmail (+1 more)
Ukraine says UAC-0099 is abusing Notepad++ plugin loading to install LunchPoke and BurnyBear malware
Ukraine’s cyber defenders say a threat group linked to earlier Sandworm initial-access activity is disguising malware as a Notepad++ plugin to infect organizations in Ukraine. CERT-UA says UAC-0099 delivers a VBS script disguised as a PDF, which fetches a ZIP containing legitimate Notepad++ 8.8.3 plus a malicious NppExport.dll that installs LunchPoke persistence, then extracts BurnyBear and the MatchBoil V2 loader. CERT-UA also referenced disputed Notepad++ issue CVE-2025-56383 and urged updates to Notepad++ 8.9.7, 7-Zip 26.02, and WinRAR 7.23. — This is a stealthy malware delivery technique that hides inside normal application behavior, making it relevant to defenders and users in Ukraine now. Organizations should review Notepad++ plugin use, hunt for the named files and scheduled tasks, and update the listed software promptly.
Sources: Hackers abuse Notepad++ plugins to stealthily install malware
OpenAI patched 'AgentForger' ChatGPT workspace flaw that let one link create a malicious AI agent inside company accounts
Researchers say a single malicious ChatGPT link could plant an attacker-controlled AI agent inside a company’s ChatGPT workspace and make it act with an employee’s access. Zenity Labs said the flaw, dubbed AgentForger, affected OpenAI’s workspace agent builder and let a crafted URL silently create, configure, publish, and schedule a rogue agent that could use approved connectors such as Outlook, Teams, Slack, SharePoint, and Google Drive. OpenAI reportedly fixed the issue in June 2026 by removing the vulnerable URL parameter. — This matters because it turns a normal phishing click into a persistent insider-style foothold that can search company data, send messages as an employee, and continue operating after the initial lure. Organizations using ChatGPT workspace agents should review agent-creation permissions, connected app access, and logs for unexpected agents or scheduled tasks.
Sources: One ChatGPT link could smuggle a rogue AI agent into your company, OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider
Chaos ransomware uses new msaRAT malware that hides command traffic inside Chrome and Edge
Cisco Talos says the Chaos ransomware group is deploying a new Rust-based backdoor called msaRAT that hides its command traffic by sending it through Google Chrome or Microsoft Edge instead of connecting directly to attacker servers. The malware is loaded in memory from an MSI installer posing as a Windows update, then uses the Chrome DevTools Protocol to control a headless browser, reach a Cloudflare Workers endpoint, and relay encrypted WebRTC traffic through Twilio TURN servers to obscure the attackers’ infrastructure. — This gives attackers a stealthier way to stay in networks and evade security tools because the malware blends into normal browser traffic. Organizations should hunt for the reported indicators, watch for suspicious headless browser activity and remote debugging use, and harden defenses against the email, voice-phishing, and fake IT/software-update lures used to start these intrusions.
Sources: New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
North Korea’s Kimsuky breached South Korean groupware vendors and used them to reach customer networks
North Korean hackers broke into South Korean collaborative-work software vendors and then used that access to target the vendors’ customers. ENKI WhiteHat said the 2025 to early-2026 campaign hit at least two unnamed groupware suppliers: one was compromised via a remote-code-execution flaw in an internet-exposed mail server, and another via social engineering of an employee. The attackers deployed Gomir and new malware variants, moved laterally, stole customer server information, tampered with login pages to harvest credentials, and then compromised at least one SaaS customer server. — This is a supply-chain style espionage campaign: organizations can be exposed through trusted software providers even if they were not the initial target. South Korean firms using affected collaboration or SaaS platforms should urgently review vendor access, check for credential theft, enforce multi-factor authentication, and hunt for Gomir and related persistence on servers and employee accounts.
Sources: New Kimsuky campaign compromised South Korean software vendors
ClickLock Stealer targets macOS users with fake Cloudflare checks to steal passwords and cryptocurrency
A newly reported macOS malware campaign is tricking users into infecting their own Macs and then stealing passwords, browser data, and cryptocurrency wallet information. Group-IB says ClickLock Stealer has targeted at least 100 users in 33 countries since late May 2026, likely via ClickFix-style fake Cloudflare verification pages that tell victims to paste a bash command into Terminal. The malware kills visible processes and NotificationCenter to suppress warnings, uses fake password prompts to capture credentials, steals Keychain and browser secrets, and exfiltrates data to a Telegram bot. — Mac users are affected even without a software exploit because the attack relies on social engineering and abuse of built-in tools. Organizations should warn users not to paste commands from websites into Terminal, review macOS detections and process-killing behavior, and treat exposed passwords, wallet secrets, and browser data as compromised.
Sources: ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing, New ClickLock macOS malware traps users into revealing login password
OkoBot malware framework uses ClickFix and fake GitHub software repos to steal credentials and cryptocurrency seed phrases
A malware framework called OkoBot is being used to steal passwords, browser cookies, cryptocurrency wallet files, and wallet recovery phrases from victims worldwide. Kaspersky says the campaign evolved from the TookPS activity seen since March 2025 and now uses multi-stage delivery through ClickFix social-engineering lures and trojanized GitHub repositories, including fake software offerings. More than 20 payloads are involved, including modules that inject into Chrome, Trezor Suite, Ledger Wallet, and Ledger Live, install malicious extensions, log keystrokes, and record activity in crypto wallets and password managers. — This can directly lead to drained crypto wallets and stolen accounts, and recovery may be impossible if seed phrases are captured. Organizations and users should avoid running code from untrusted GitHub repositories, treat ClickFix-style prompts as hostile, and hunt for the published indicators of compromise.
Sources: New OkoBot framework deploys 20 payloads to steal data, crypto
Two alleged Scattered Spider members plead guilty over 2024 Transport for London cyberattack
Two alleged Scattered Spider members pleaded guilty to carrying out the September 2024 cyberattack on Transport for London, which disrupted transit-related services for months and exposed customer data tied to Oyster refund systems. The U.K. National Crime Agency said the pair infiltrated TfL's network, forcing 28,000 employees to reset passwords in person and contributing to about £29 million in losses and recovery costs; investigators also cited evidence of Telegram coordination and access to stolen-credential marketplaces. — This was a real-world, high-impact intrusion against a major public transport system, with costs, service disruption, and customer-data exposure. Transit agencies and other large organizations should treat it as another concrete Scattered Spider case and review identity controls, help-desk processes, credential exposure, and incident-response readiness.
Sources: Two Scattered Spider members plead guilty over cyberattack that crippled London transit, Scattered Spider members plead guilty to hacking Transport for London, Scattered Spider Hackers Plead Guilty on Day 1 of Trial (+6 more)
ClickFix campaign targets macOS users with Atomic macOS Stealer through silent DMG mounting
A new scam-style malware campaign is tricking Mac users into pasting a Terminal command that silently installs a password and crypto-stealing program. Palo Alto Networks says the ClickFix attack uses a fake CAPTCHA to get victims to run a command that downloads a malicious DMG disk image, mounts it with macOS hdiutil without showing it in Finder, and launches Atomic macOS Stealer (AMOS). The malware steals browser credentials, cookies, Keychain data, Telegram and Discord data, documents, and cryptocurrency wallet information, and can replace Ledger Live and Trezor Suite with trojanized versions. — This can lead directly to stolen passwords, drained crypto wallets, and account takeover for Mac users who follow the fake verification prompt. Users should never paste commands into Terminal from websites, and organizations should warn users about ClickFix lures and watch for AMOS-related activity.
Sources: New macOS ClickFix attack silently mounts DMGs to push infostealer, C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest
CERT-UA says Russia’s Sandworm is using fake CAPTCHA prompts to trick Ukrainians into running PowerShell malware
Ukraine’s cyber agency says Russian military hackers are using fake CAPTCHA checks on compromised websites to trick Ukrainian targets into infecting their own Windows PCs. CERT-UA said Sandworm has increasingly used the ClickFix social-engineering technique in June and July 2026, directing victims to paste PowerShell commands that install malware including GhettoVibe, ScoutCurl, FluidLeech, and LoadLoop; the agency also said the group continues related Android lures and Signal-based social engineering. — This is an active intrusion method aimed at Ukrainian users, including government and military-linked targets, and it can lead to persistent compromise and follow-on destructive attacks. Organizations and individuals in Ukraine should treat CAPTCHA pages asking them to paste commands as malicious, block PowerShell abuse where possible, and warn staff about Signal and fake security-tool lures.
Sources: Sandworm hackers have a CAPTCHA trick for Ukrainians
Russian threat actor UAT-11795 uses trojanized Zoom, Webex, and other software installers to deploy Starland RAT
A Russian cybercrime group is spreading fake installers for popular software such as Zoom, Webex, MobaXterm, DBeaver, and FaceIT to infect Windows users with a new backdoor called Starland RAT. Cisco Talos says UAT-11795 has run the campaign since at least June 2025, mainly against U.S. users, using an HTA file and a trojanized NSIS installer to load Starland, persist via Registry and scheduled tasks, and in some cases deliver CastleStealer and Remcos. The malware steals browser and cryptocurrency-wallet data, gathers Active Directory information, and uses a fallback command-and-control method via a Polygon smart contract. — People and organizations can be compromised simply by installing what looks like legitimate remote-work or developer software, leading to stolen passwords, wallet theft, and deeper network access. Defenders should hunt for Talos indicators of compromise, restrict software downloads to verified vendor sources, and warn users against running pasted commands or unofficial installers.
Sources: Russian hackers trojanize WebEx, Zoom apps to push Starland malware
Australian regulator says Qantas 2025 customer-data breach was caused by a fake IT support call to a contact center
Australia’s privacy regulator said the 2025 Qantas breach that exposed personal data for 5.7 million customers began with a fake IT support call to a contact center. According to the report, the caller posed as “Qantas IT help” and tricked an agent into using the airline’s customer relationship management system in a way that linked it to a data-extraction tool, allowing customer records to be siphoned out. The regulator said Qantas had role-based access controls, audits, and recurring staff training in place and decided not to open a formal privacy investigation. — This gives both travelers and defenders a clearer picture of how a large airline breach happened: a voice-based social engineering attack, not a software flaw. Organizations should review help-desk and contact-center procedures, especially any workflow that lets staff connect business systems to external tools or act on unsolicited support calls.
Sources: Tech support scam caused massive data breach at Australian airline Qantas
Dutch police arrest suspects tied to international investment fraud ring that used fake crypto platforms and call centers
Dutch police say they arrested multiple suspects tied to an international investment fraud network that allegedly stole from tens of thousands of victims through fake investment platforms. Investigators say the group ran about 20 call centers with more than 700 people posing as financial advisers, showed victims bogus profit dashboards, and pushed them to send more money, often in cryptocurrency. Police linked at least 550 reports and $28.6 million in reported losses to the ring, while estimating the broader operation made more than €100 million per month and had been active since at least 2021. — This is a large, organized social-engineering and investment-scam operation with worldwide victims, showing how convincing fake trading sites and phone-based pressure can drive major financial losses. Consumers should treat unsolicited investment pitches and crypto-transfer requests as high risk, and defenders at financial and telecom organizations should watch for fraud infrastructure and impersonation activity.
Sources: Dutch police bust investment fraud ring stealing over €100 million
U.S. unseals charges against alleged operators of Media Land and ML Cloud Russian bulletproof hosting service
The U.S. unsealed an indictment against three Russians accused of running Media Land and ML Cloud, hosting services that allegedly helped cybercriminals carry out attacks against victims in the United States and elsewhere. Prosecutors say Aleksandr Volosovik, Yulia Pankova, and Kirill Zatolokin provided infrastructure and technical support designed to shield criminal customers from law enforcement, enabling ransomware groups including LockBit, BlackSuit, and Play as well as stolen-card marketplaces such as Briansclub and Bidencash; the indictment cites 44 victims and about $62 million in losses. — Bulletproof hosting is a key enabler for ransomware, fraud, and stolen-data markets, so this case matters beyond the named defendants. Defenders should note the specific infrastructure and actor links, while affected organizations and the public should expect continued law-enforcement disruption efforts rather than an immediate end to related threats.
Sources: US unseals indictment against alleged operators of Russian bulletproof hosting service, US charges alleged operators of Russian bulletproof hosting service, US Charges Russian Individuals and Firms for Running Cybercrime Services
Spanish police dismantle €140 million cyber-fraud and BEC money-laundering network
Spanish police say they broke up a criminal network that made about €140 million from investment scams and business email compromise, a fraud in which attackers impersonate executives or vendors to divert payments. Authorities arrested four suspects in Spain, Portugal, and Panama and say the group used more than 800 bank accounts, 120 business accounts, and 67 money mules to move and hide proceeds; investigators linked €61 million specifically to 2024 BEC activity and froze €3 million for victim recovery. — This shows the scale and persistence of BEC and investment-fraud operations, which can drain businesses and individuals without using malware at all. Organizations should tighten payment-verification controls and train staff to independently verify invoice changes and executive payment requests.
Sources: Spanish Police take down €140 million cyber fraud ring, arrest four
Fake GitHub pages impersonating Arctic Wolf and other software vendors are spreading BoryptGrab stealer malware
Attackers created fake GitHub pages that impersonate Arctic Wolf and many other software brands to trick people into downloading malware. Arctic Wolf says one bogus repository used an 'Official Page' link to deliver a ZIP file containing a trojanized installer, 'Arctic-Wolf-3.9.7.exe,' which side-loaded a fake libcurl.dll to decrypt and launch BoryptGrab Stealer, an information-stealing malware family. The company says it found nearly 300 similar repositories using search-engine bait and branding from vendors including Malwarebytes, Bitdefender, and 360 Total Security. — This is a broad social-engineering and malware campaign that can hit employees and consumers who trust GitHub pages and software downloads that look official. Organizations should warn users, block known indicators, and tell staff to download tools only from verified vendor sites or trusted repositories.
Sources: Security Bulletin: GitHub Impersonation Deploys Information Stealer, Nearly 300 GitHub repos pose as legit software to push malware
Welsh Doxbin administrator jailed for helping coordinate and promote swatting attacks in the UK, US, and Canada
A Welsh man was jailed after investigators said he helped encourage and support swatting attacks linked to the doxing platform Doxbin. Authorities said Callum Dare, an administrator on Doxbin, used the platform’s #deadnet channel to assist and incite hoax emergency calls, shared montage videos of armed-police responses to encourage copycats, and was tied through seized chat logs, a PayPal account, and device forensics to multiple incidents including threats against a Cardiff hotel, a University of California lecture theater, and victims in Canada. — Swatting can get armed police sent to innocent people’s homes or workplaces and has caused real injuries and deaths. The case highlights how doxing forums can enable harassment and violent hoaxes at scale, so organizations and individuals targeted by online harassment should treat leaked personal data and threat escalation as an immediate safety issue.
Sources: Welsh Doxbin admin jailed for egging on swatters from behind a screen
Fake LastPass and Bitwarden security-policy emails send users to phishing sites posing as DocuSign
LastPass and Bitwarden users are being targeted by phishing emails that pretend to announce security-policy changes and send people to fake DocuSign-style websites. The messages came from lookalike sender addresses such as hello@lastpassnewsletter.com and hello@bitwardennewsletter.com and linked to domains including lastpasscompliance.com and bitwardencompliance.com. LastPass said its own systems were not breached; the sites reportedly offered a file download for Windows and macOS, suggesting credential theft or malware delivery. — Password-manager users are high-value targets because one stolen master password can expose many other accounts. Users should avoid these messages, verify any alerts directly in the official app or website, and immediately change their master password from a trusted device if they entered it on a phishing page.
Sources: LastPass, Bitwarden users targeted with fake security alerts
Jalisco and OmegaLord phishing kits target Microsoft 365 accounts and try to bypass MFA
Researchers found two phishing kits that target Microsoft 365 users and are designed to get around multi-factor authentication protections. Jalisco abuses the OAuth 2.0 device authorization flow, also called device-code phishing, by generating fresh Microsoft device codes in real time and registering attacker-controlled devices on victim accounts. OmegaLord uses a fake PDF reader login page to steal Microsoft account credentials and victims’ phone numbers, which can help attackers intercept or hijack MFA challenges and quickly loot SharePoint and other SaaS data. — Organizations using Microsoft 365 should treat this as an active account-takeover risk, especially where device-code sign-ins are allowed. Defenders should review Entra ID device registrations, restrict or block device-code authentication where possible, tighten app registration policies, and warn users not to enter login codes or phone numbers into unsolicited prompts.
Sources: New phishing kits target Microsoft 365 accounts, evade MFA
TrendAI says Russian-speaking scammer used jailbroken Gemini to target QAnon and MAGA users with wallet theft and WordPress credential attacks
A Russian-speaking threat actor allegedly used a jailbroken Google Gemini account to run a months-long scam and theft campaign aimed at QAnon and MAGA communities, stealing WordPress admin credentials and draining at least one victim's cryptocurrency wallets. TrendAI says the operation ran from September 2025 to May 2026 through a Telegram channel with about 17,000 subscribers, used 73 likely stolen Gemini API keys, pushed a fake StellarMonster wallet app that actually installed the GoToResolve remote access tool, and captured victims' seed phrases through a bogus wallet-import screen. — This matters because it blends political-community targeting, AI-assisted social engineering, malware, and direct crypto theft in a way ordinary users can fall for and defenders may miss. Users should avoid wallet apps and recovery prompts promoted in Telegram channels, while organizations should investigate exposed WordPress credentials and watch for abuse of stolen API keys.
Sources: A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets, 'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes
Infinite Campus says ShinyHunters stole data from 137,100 school staff accounts in Salesforce breach
Infinite Campus says a March breach of its Salesforce environment exposed data from 137,100 school staff accounts tied to U.S. K-12 districts. The company said the attacker accessed its Salesforce instance rather than customer student databases; leaked records analyzed by Have I Been Pwned reportedly include names, email addresses, employers, job titles, phone numbers, physical addresses, usernames, and support tickets. ShinyHunters claimed responsibility and published a 1.2GB archive of alleged stolen data. — Schools and staff may face targeted phishing, impersonation, and follow-on fraud using exposed contact and support data. Districts using Infinite Campus should warn employees, watch for suspicious messages or password-reset attempts, and review any Salesforce-connected access and monitoring.
Sources: Infinite Campus data breach affects 137,000 school staff accounts, Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Klue OAuth breach let Icarus extortion group steal Salesforce customer data from multiple organizations
Klue says attackers abused its Salesforce-connected Battlecards app to steal CRM data from multiple customer organizations, and victims are now receiving extortion demands from the Icarus group. According to ReliaQuest, Huntress, and BleepingComputer, the attackers used compromised Klue service accounts and associated OAuth tokens to access customer Salesforce instances, enumerate objects through Salesforce REST API endpoints, and exfiltrate records over hours; Salesforce has disabled the Klue Battlecards integration while the incident is investigated. — Organizations that connected Klue Battlecards to Salesforce may have had sensitive sales, customer, or internal business data stolen without a malware outbreak or password spray. Affected teams should urgently review Salesforce OAuth-connected apps and token activity, check for unusual API queries, and prepare for extortion emails tied to this campaign.
Sources: Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks, Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data, Cybersecurity Firms Impacted by Klue Supply Chain Attack (+7 more)
Dutch police say Odido customer-data breach involved a fake IT call that helped hackers access telecom systems
Dutch police say the cyberattack on telecom provider Odido that exposed personal data from more than 6 million customers was helped by a Dutch-speaking man who posed as an Odido IT employee. Authorities say the February breach involved social engineering against customer service staff and access to a compromised customer contact system, which attackers then used to download customer records; police also said they took servers used to distribute the stolen data offline. — This matters for millions of telecom customers whose personal information was exposed and for organizations that rely on call-center staff to gate access to internal systems. Odido customers should watch for follow-on phishing or impersonation attempts, and defenders should review help-desk verification and call-back procedures.
Sources: Dutch police trace Odido telco cyberattack to suspected local accomplice, Police suspects Dutch hackers were involved in Odido breach
AssuranceAmerica says data breach exposed records of 6.9 million insurance customers and drivers
AssuranceAmerica disclosed that attackers broke into its systems in March 2026 and stole data tied to 6,998,886 people. The insurer says the intrusion followed malicious activity targeting one employee on March 16, with suspicious activity detected March 17. Stolen files contained names, contact details, insurance policy and account information, driver and vehicle information, claims-related data, and driver's license numbers. — This is a major breach affecting drivers and insurance customers whose identity and account data could now be misused for fraud or impersonation. Affected people should watch financial and insurance accounts closely, and defenders should treat employee-targeted attacks as a likely entry point.
Sources: AssuranceAmerica data breach exposes records of 6.9 million drivers, In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops
Miinto says attackers accessed its order management system and exposed customer order data
Fashion marketplace Miinto told customers that an unauthorized party got into its internal order management system and may have retrieved their order data. The company said exposed data includes names, email addresses, physical addresses, phone numbers, and payment-method information such as card type or Klarna use, but not full card numbers or card verification codes. Miinto did not disclose the scale of the breach or the intrusion method. — Affected shoppers should be alert for phishing messages that use real order details to look convincing. Users should watch for fake Miinto emails, texts, or calls, and the company still needs to clarify how many people were affected and how the intrusion happened.
Sources: Fashion mart Miinto unzips breach details, warns shoppers to watch for phisherfolk
Pink extortion group uses fake help-desk calls and MFA phishing to steal Microsoft 365 and cloud data
A newly identified extortion group called Pink is calling employees while pretending to be IT support, then stealing account credentials and company data to demand payment. Palo Alto Networks Unit 42 says the group, tracked as CL-CRI-1147 and likely linked to the criminal network known as The Com, uses voice phishing and fake help-desk interactions to capture passwords and multifactor authentication (MFA) approvals, then raids services such as SharePoint, OneDrive, and Microsoft Teams. Unit 42 said Pink's leak site went live on May 31 and published domains and IP addresses tied to the campaign as indicators of compromise. — This matters to organizations that rely on cloud productivity tools because attackers do not need malware or software flaws if they can talk staff into handing over access. Companies should warn staff about unsolicited help-desk calls, tighten help-desk identity checks, review Microsoft 365 logs, and block or investigate the listed phishing infrastructure immediately.
Sources: Pink is the latest goon squad to use fake helpdesk calls to steal creds, Entra passkey enrollment vishing targets Microsoft 365 users, Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
Helix vishing group steals Microsoft SharePoint data through fake manager calls, device-code phishing, and MFA app enrollment
A newly identified extortion group called Helix is tricking employees into giving attackers access to Microsoft 365 accounts, then stealing files from SharePoint to extort victim organizations. ReliaQuest says the group uses voice phishing (phone calls pretending to be a manager), device-code phishing to capture account access, and multi-factor authentication abuse by enrolling a rogue authenticator app for persistence. After access, Helix enumerates SharePoint content and bulk-downloads files, with infrastructure and tradecraft suggesting possible overlap with the now-defunct BlackFile group and similarities to ShinyHunters campaigns. — Organizations using Microsoft 365 and SharePoint should treat this as an active account-takeover and data-theft threat, especially if staff can be reached by phone or Teams and device-code login flows are enabled. The concrete action is to disable device-code authentication where possible, restrict SharePoint access to managed devices, harden MFA enrollment, and warn employees about calls claiming to be managers or IT staff.
Sources: New Helix vishing group emerges in SharePoint data theft attacks
Forg365 phishing service targets Microsoft 365 accounts with device-code login tricks and cookie-stealing browser extension
Researchers identified a phishing-as-a-service platform called Forg365 that is built to steal Microsoft 365 accounts and keep access to them after login. The service combines OAuth device-code phishing and adversary-in-the-middle (a login proxy that captures session tokens), uses AI inside its operator dashboard to generate lures, and includes a Chrome-, Edge-, and Brave-compatible extension called ForgCookie that refreshes stolen Microsoft single sign-on cookies for persistent access. — Microsoft 365 users and administrators should treat this as an active account-takeover threat, especially because it abuses legitimate Microsoft authentication flows instead of only stealing passwords. Organizations should harden device-code and OAuth app controls, review suspicious consent grants and session tokens, and warn users not to enter Microsoft verification codes from unsolicited emails.
Sources: New Forg365 phishing platform uses AI to target Microsoft 365 accounts
INTERPOL says Operation First Light 2026 led to 5,811 arrests and $293 million seized in global anti-fraud crackdown
INTERPOL says police in 97 countries arrested 5,811 suspects and seized $293 million in a coordinated crackdown on online fraud and related money laundering. Operation First Light 2026 ran from January 15 to April 30 and targeted business email compromise, sextortion, impersonation, romance, and investment scams; authorities said they identified more than 142,000 victims, blocked 31,014 bank accounts, reviewed 152,808 cases, and identified 15,606 additional suspects. — This shows the scale of social-engineering fraud hitting consumers, businesses, and governments worldwide. People and organizations should treat unsolicited payment requests, investment pitches, romance approaches, and account-verification messages with caution, and strengthen payment verification and anti-fraud controls.
Sources: Police arrests 5,800 suspects in global anti-fraud crackdown
China-linked hackers exploit Roundcube flaws CVE-2024-42009 and CVE-2025-49113 to spy on U.S. and Canadian researchers
A suspected China-aligned hacking group has been breaking into vulnerable Roundcube webmail servers at U.S. and Canadian universities to steal logins and plant backdoors. Proofpoint says the campaign, tracked as UNK_MassTraction, has run since May and targets physics, engineering, astrophysics, particle-physics, and national-security-related research organizations. Attackers use emails that trigger Roundcube cross-site scripting flaw CVE-2024-42009 to load the IceCube stealer, then abuse deserialization flaw CVE-2025-49113 to try to install the SquareShell PHP web shell or the VShell backdoor. — Universities and research groups handling sensitive science and national-security work may have had email accounts and mail servers compromised. Organizations using Roundcube should patch immediately, review mail-server logs for exploitation, and reset credentials and session cookies for potentially affected users.
Sources: Hackers exploit Roundcube flaw to spy on academic researchers, Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
Taiwan charges two businessmen over LINE account rentals tied to a Chinese espionage phishing campaign
Taiwan says two local businessmen helped a China-linked espionage campaign by leasing LINE accounts that were used to trick politicians, journalists, academics, and civil society targets. Taiwan's Ministry of Justice Investigation Bureau alleges the accounts were supplied to Xiamen Empress Information Technology, then used to impersonate reporters, including people tied to ICIJ, and push malware disguised as encrypted communications software in interview and article-invitation lures. — This shows a real-world supply chain for state-linked social-engineering attacks: attackers bought trusted local messaging accounts to make their phishing look legitimate. People in government, media, academia, and NGOs in Taiwan and diaspora communities should be wary of unsolicited interview requests and software downloads sent over messaging apps.
Sources: Taiwan charges two businessmen over alleged role in Chinese espionage campaign
U.S. extradites alleged Scattered Spider member over social-engineering breach and $8 million extortion attempt against jewelry retailer
A 19-year-old accused Scattered Spider member was extradited from Finland to the United States to face charges tied to hacking and extortion. The FBI says Peter Stokes helped breach an unnamed luxury jewelry retailer around May 12, 2025 by calling the IT help desk from Google Voice numbers, posing as employees, and getting password and multifactor authentication resets; the attackers allegedly compromised three accounts, including two IT administrator accounts, used ngrok for persistent access, stole data, and demanded $8 million in cryptocurrency. — This matters because it gives defenders a concrete look at how Scattered Spider is still using help-desk impersonation to break into companies without exploiting software flaws. Organizations, especially those with privileged IT accounts, should harden help-desk identity checks, review MFA reset procedures, and monitor for unauthorized remote-access tools such as ngrok.
Sources: Teen suspect in Scattered Spider hacks is extradited to US, Alleged Scattered Spider hacker extradited to the United States, Alleged Scattered Spider Hacker Extradited to US (+1 more)
Attackers use fake Microsoft Teams IT support calls to install EtherRAT on employee computers
Attackers are calling employees on Microsoft Teams while pretending to be corporate IT staff and tricking them into installing malware that gives remote control of their computers. According to Palo Alto Networks' Unit 42, the campaign starts with an 'Employee Survey' phishing email and PDF, then a Teams voice call from an external Microsoft 365 tenant, followed by abuse of Teams screen sharing and remote tools including HopToDesk and AnyDesk. The attackers then run a malicious MSI installer that fetches Node.js and launches EtherRAT, a cross-platform remote access trojan that can execute commands, steal data, persist, and use Ethereum smart contracts to locate command-and-control servers. — Organizations using Microsoft Teams are at risk of employees being talked into giving attackers direct access to their devices. Defenders should warn staff not to trust unsolicited Teams support calls, restrict external Teams communications and remote-control features where possible, and review logs for suspicious external tenants, remote tool installs, and the listed infrastructure.
Sources: Fake IT support calls on Microsoft Teams push EtherRAT malware, Fake IT bods on Microsoft Teams coax workers into installing malware
Google sues alleged China-based 'Outsider Enterprise' over mass phishing texts and fake brand websites
Google says a China-based fraud network used phishing kits and automated content generation to send millions of scam text messages and steer people to fake websites that stole passwords, payment-card data, and other sensitive information. In a civil complaint, Google linked the Telegram-based 'Outsider Enterprise' to more than 9,000 fraudulent sites and over 1 million malicious URLs, and said Android telemetry saw about 2.5 million related messages in a two-week period in May. — This is a high-volume smishing and credential-theft operation affecting everyday phone users, not just a niche enterprise target set. People should be wary of text messages claiming to be from trusted brands, avoid logging in through SMS links, and carriers and mobile defenders should watch for the cited infrastructure and lures.
Sources: Google fires sueball at alleged Chinese phishers over AI-powered fraud ops, FBI disrupts massive AI-powered phishing service using a million URLs, FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service (+1 more)
Fake job interview phishing campaign impersonates Adobe, OpenAI, Netflix and other brands to steal Google accounts
A phishing campaign is posing as recruiters from more than 30 well-known companies to steal Google account credentials from marketing professionals and job seekers. The operation abuses legitimate services including PeopleForce, Salesforce Marketing Cloud infrastructure on exct.net, and Wise Agent in a redirect chain before sending victims to attacker-controlled domains, where a browser-in-the-browser fake Google sign-in window captures passwords. Researchers say the activity has run for at least five months. — Anyone contacted about a job interview from a major brand could be targeted, especially people in marketing roles. Treat interview scheduling links with caution, verify recruiters through official company channels, and use phishing-resistant multifactor authentication where possible because the campaign is designed to look unusually legitimate.
Sources: Phishing poses as big-brand job interview to steal Google accounts
Kaspersky says Armored Likho is targeting government and electric power organizations in Russia, Brazil, and Kazakhstan
A newly identified hacking group called Armored Likho has been targeting government and electric power organizations in multiple countries, while also running financially motivated attacks against individuals. Kaspersky says the actor uses spear-phishing emails with executable or shortcut (LNK) files to install malware including the Python-based BusySnake Stealer and Go2Tunnel, enabling credential theft, browser cookie and password extraction, Telegram session theft, screenshot capture, reverse SSH tunnels, and persistent remote access. — Government and energy organizations are high-value targets, and the campaign uses common email lures that can reach many users. Defenders should harden email filtering, block malicious LNK/executable attachments, monitor for GitHub-hosted payload retrieval and reverse SSH activity, and hunt for BusySnake, Go2Tunnel, and related persistence mechanisms.
Sources: Armored Likho APT Targeting Government, Electric Power Entities
Ukraine says Russian hackers made media outlets a priority target after attacks on television broadcasters
Ukraine’s security agency says Russian hackers are increasingly targeting Ukrainian media organizations, including two previously undisclosed attacks on television broadcasters. The SBU said one incident this year was a large distributed denial-of-service, or DDoS, attack against a nationwide TV channel, while another last year combined phishing with attempts to access connected infrastructure to seize a major broadcaster’s platform and publish Russian propaganda as if it came from Ukrainian media. — This is a direct threat to news delivery and public trust during wartime, especially for broadcasters and media operations in Ukraine. Media organizations should urgently harden phishing defenses, review access to broadcast and publishing systems, and prepare for DDoS and account-takeover attempts.
Sources: Ukrainian media outlets now among 'priority targets' for Russian hackers
Zscaler says prompt-injection websites trick some AI agents into making crypto payments and trusting fake DeBank pages
Researchers found two live scam campaigns that hide instructions in web pages to manipulate autonomous AI agents, including one that got some agents to initiate cryptocurrency payments and another that made some models trust a fake DeBank site. Zscaler says the first campaign used search-result poisoning and fake API documentation for a bogus Python package, with hidden prompts in schema markup and HTML telling agents to pay for an API key; the second used typosquatting and search optimization to impersonate DeBank. In tests across 26 large language models, four executed a payment and two misidentified the fake site as legitimate. — Organizations experimenting with AI agents that can browse the web or make transactions could have those agents manipulated by hostile content. Treat web content as untrusted input for AI agents, restrict payment and external-action permissions, and add human approval before any financial or account-trust decision.
Sources: Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments
Attackers use fake OpenAI organization invites to impersonate companies and target employees
Attackers are creating fraudulent OpenAI ChatGPT organizations that look like real companies and inviting employees to join them through legitimate OpenAI emails. Push Security said the campaign targeted employees in cybersecurity and technology firms using work addresses, with fake tenants named after the victim company and attacker-controlled Gmail accounts inside posing as company staff. The apparent goal is to get victims to use the workspace and paste in sensitive data such as source code, internal documents, customer information, or research. — This matters because the emails are sent by OpenAI itself, so they can bypass normal phishing suspicion and email defenses. Organizations using ChatGPT Enterprise or shared AI workspaces should warn staff to verify who created tenant invites and avoid joining unexpected workspaces or sharing sensitive data in them.
Sources: Cybersecurity firms targeted by fraudulent OpenAI organization invites, In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting
AdaptHealth says social engineering of a contractor led to theft of patient data from cloud systems
AdaptHealth says attackers tricked a third-party contractor and then got into the company's cloud systems, stealing patient data. In its SEC filing, the home medical equipment provider said the intrusion exposed internal patient management systems, document storage platforms, external electronic health record portals, a password file tied to insurance billing, and some personally identifiable information and protected health information. The company said Social Security numbers and payment data are not currently believed to be affected, and it has not yet disclosed the full scope. — This affects healthcare patients whose medical and personal data may now be exposed, and it shows how one manipulated contractor account can open access to sensitive cloud systems. Organizations using contractors should review third-party access, reset exposed credentials, and watch for follow-on fraud or extortion.
Sources: AdaptHealth says attackers sweet-talked their way into cloud systems and stole patient data
ARToken phishing service tied to EvilTokens expands Microsoft 365 token theft and business email compromise attacks
Researchers say a phishing service called ARToken is tied to the EvilTokens platform and is being used to break into Microsoft 365 accounts and steal long-lived access tokens. Cisco Talos found a React-based ARToken management panel with more than 80 API endpoints, including the same Microsoft OAuth 2.0 device-code phishing and Primary Refresh Token (PRT) workflows previously linked to EvilTokens. The toolkit can access Outlook, SharePoint, and OneDrive, create inbox rules, send mail from victim accounts, and deploy phishing infrastructure through Cloudflare Workers. — This matters because the attacks use Microsoft's legitimate device login flow, which can trick users into handing over access even when multi-factor authentication is enabled. Organizations using Microsoft 365 should urgently review device-code sign-in activity, tighten controls around OAuth and token use, monitor for suspicious inbox rules and mail forwarding, and warn users about unexpected prompts to enter device codes.
Sources: ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit
FortiBleed campaign compromised more than 30,000 Fortinet firewalls and VPN gateways worldwide
Researchers say more than 30,000 Fortinet firewalls and virtual private network gateways were compromised and can expose the organizations behind them to further hacking. SOCRadar said a campaign it calls FortiBleed systematically tried known passwords against internet-exposed Fortinet devices, harvested working credentials, then monitored traffic and reused newly captured passwords to spread further; victims span companies and government bodies in more than 190 countries. — Organizations using Fortinet edge devices may already have attackers inside even without a new software flaw. This is urgent for network defenders: audit Fortinet logins, rotate passwords and tokens, review device configurations, and check for signs of credential harvesting or unauthorized access.
Sources: 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs, FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices., Massive password-stealing attack hits 75k Fortinet firewalls (+11 more)
ConsentFix phishing trick steals Microsoft 365 session tokens through fake OAuth sign-in steps
Attackers are using a new phishing technique called ConsentFix to hijack Microsoft 365 accounts by tricking users into completing what looks like a normal sign-in step. The lure often arrives through services such as Dropbox or DocSend and asks the victim to drag a localhost callback link into the browser during a Microsoft OAuth consent flow; doing so exposes OAuth session tokens, giving attackers access to email and other Microsoft 365 services without needing the user's password and effectively bypassing multi-factor authentication for that session. The article also says a full how-to guide, code, screenshots, and a video tutorial were posted on a Russian cybercrime forum in March 2026. — Microsoft 365 users and organizations can lose account access in seconds even when users do not type passwords into a fake page. Defenders should review OAuth app-consent controls, train users about drag-and-drop and fake verification prompts, and monitor for suspicious token issuance and cloud-session abuse.
Sources: ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
India temporarily blocks Telegram and disables message editing over NEET medical exam cheating scams
India temporarily restricted Telegram nationwide ahead of the rerun of its medical entrance exam after authorities said scammers were using the app to sell fake leaked test papers. The National Testing Agency said access would be blocked until June 22 and Telegram's message-editing feature disabled in India until June 30; officials said fraudsters used edited posts to make it appear they had advance access to real NEET-UG questions, and police in Ahmedabad arrested suspects tied to eight Telegram channels in a scheme that moved about 15 million rupees. — This affects millions of Telegram users in India and shows how governments may impose platform-level restrictions in response to fraud and rumor campaigns. Students and families should be wary of Telegram channels offering leaked exam papers, while defenders and rights groups should track the censorship and platform-governance implications of disabling communications tools to address scams.
Sources: India temporarily blocks Telegram over medical exam cheating fears, India's Telegram ban draws criticism from Durov as company challenges order in court, India's Telegram ban hit the UAE too. Here's how to get around it (+2 more)
India orders WhatsApp to explain and pause username rollout over impersonation and scam fears
India told WhatsApp to justify its planned username feature within three days and asked the company to halt the rollout until regulators review it. The Ministry of Electronics and Information Technology said letting people contact others by username instead of phone number could increase impersonation, phishing, and 'digital arrest' scams, especially by attackers posing as officials, banks, or government departments; WhatsApp said the feature is not yet live and will roll out later this year with account-age, shared-group, and country signals plus reserved high-profile names. — This could affect WhatsApp users in its biggest market and signals a direct government intervention in a messaging platform feature over fraud and account-trust concerns. Users should be cautious about new first-contact messages when usernames launch, and defenders should watch for impersonation scams that exploit name-based discovery.
Sources: India gives WhatsApp three days to defend username rollout amid security fears
LayerX says BioShocking prompt-injection attack can make AI browsers copy passwords and other sensitive data
Researchers say a malicious web page can trick several AI-powered browsers into ignoring safety rules and stealing sensitive data from other sites the user can access. LayerX tested a proof of concept against ChatGPT Atlas, Comet, Fellou, Genspark Browser, Sigma Browser, and Anthropic’s Claude Chrome plugin, using a fictional game scenario to push the browser agent into copying secrets from a GitHub repository; OpenAI reportedly fixed the issue in ChatGPT Atlas, while other products remained vulnerable or unresponsive. — People using AI browsers or browser agents could be tricked into letting them exfiltrate passwords or other sensitive information through normal browsing sessions. Vendors need stronger guardrails and user-confirmation checks, and users should limit these tools’ access to sensitive sites and data.
Sources: New BioShocking attack manipulates AI browser into data theft, ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials
Trojanized GitHub exploit repositories used malicious PyPI packages to install ChocoPoC remote-access malware
Attackers hid malware in GitHub proof-of-concept exploit repositories and infected people who cloned and ran them. Sekoia says at least seven repositories for exploits tied to FortiWeb CVE-2025-64446, React2Shell CVE-2025-55182, MongoBleed CVE-2025-14847, PAN-OS CVE-2026-0257, Ivanti Sentry CVE-2026-10520, Check Point VPN CVE-2026-50751, and Joomla SP Page Builder CVE-2026-48908 pulled malicious PyPI packages including frint and skytext, which installed the ChocoPoC RAT, a remote-access trojan that can run commands and steal credentials and files. — This targets the very people trying to test or defend against vulnerabilities, and it can silently hand over passwords, browser sessions, files, and system access. Anyone who cloned untrusted exploit code from GitHub should review systems for the listed packages and treat such testing as high-risk unless done in isolated environments.
Sources: ChocoPoc malware delivered via trojanized exploits on GitHub, New ChocoPoC malware targets researchers via trojanized PoC exploits, New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
FBI warns Kali365 phishing service is hijacking Microsoft 365 accounts through OAuth device-code logins
The FBI says criminals are using a Telegram-based service called Kali365 to trick people into granting access to their Microsoft 365 accounts. The phishing-as-a-service platform, first seen in April 2026, abuses Microsoft's legitimate device-code login flow so victims authorize attacker-initiated sessions; the stolen OAuth access and refresh tokens can then be reused to access Outlook, Teams and OneDrive without needing the victim's password or another multi-factor authentication prompt. — This matters because victims can lose control of email, files and collaboration accounts even if multi-factor authentication is enabled. Organizations using Microsoft 365 should urgently review device-code login controls and token protections, monitor for suspicious inbox rules and token use, and warn users not to enter login codes from unsolicited emails.
Sources: FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks, FBI warns of Kali365 phishing service targeting Microsoft 365 accounts, From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services (+2 more)
Check Point says DeepSeek-generated browser ransomware sample can be turned into a working Chrome-based file-encryption attack
Check Point says code generated by DeepSeek can be adapted into a working browser-based ransomware attack that encrypts a victim’s local files after they approve a browser permission prompt. The sample, dubbed "InfernoGrabber 9000," is a Python Flask web app targeting Android users and abuses Chrome and Chromium-based browsers’ File System Access API to read and write local files without a traditional malware install, relying on phishing-style social engineering rather than a browser exploit or CVE. — This lowers the barrier for criminals to build ransomware-like attacks that run in the browser, where users may trust the prompt because it comes from a legitimate browser feature. Defenders should review controls around Chromium-based browsers and file-access permissions, and users should be wary of websites asking for broad local file access.
Sources: Somebody told DeepSeek to build in-browser ransomware and it gleefully complied
Researchers show Anthropic Claude Desktop can be abused through synced instructions to run commands on a developer’s computer
Pentera Labs says it turned Anthropic's Claude Desktop into a malicious intermediary that helped achieve remote code execution on a developer workstation. The attack required control of the victim's email inbox and the victim's use of Claude Desktop, then abused account-wide synced personalization and project instructions to make the AI look for command-capable tools and execute attacker-influenced actions across sessions and devices; no CVE is cited in the article. — People may trust AI assistants more than ordinary prompts or attachments, so this kind of abuse could quietly turn a synced desktop agent into an attack path to a user’s computer. Organizations using Claude Desktop or similar agentic tools should review local command-execution permissions, account sync behavior, inbox security, and user approval controls for AI-run actions.
Sources: Red teamers turned Claude Desktop into a double agent to do their evil bidding
Mass password-spray campaign uses Azure CLI and OAuth ROPC to break into Microsoft 365 accounts
Attackers made more than 81 million login attempts and successfully compromised Microsoft 365 accounts at dozens of organizations by abusing Azure CLI sign-ins. Huntress says 78 accounts at 64 organizations were breached between June 12 and 21, 2026, using password spraying and the OAuth Resource Owner Password Credentials (ROPC) flow, which can mint tokens without an interactive multi-factor authentication prompt if MFA policies are not enforced for that flow or all cloud apps. Most activity came from infrastructure tied to LSHIY. — Organizations using Microsoft 365 could be exposed even if they believe MFA is enabled, because gaps in conditional access or legacy auth coverage can still let attackers in. Defenders should review Azure and Entra sign-in logs, disable or restrict ROPC where possible, enforce MFA for all cloud applications and users, and reset compromised accounts.
Sources: Massive Password Spray Campaign Targeting Azure CLI, Hackers target Microsoft 365 accounts with 81 million login attempts
Adversa says Bash guard bypasses in open-source AI coding agents can turn malicious repositories into code-execution attacks
Researchers say most tested open-source AI coding agents can be tricked by malicious repositories into generating and running dangerous shell commands. Adversa calls the issue "GuardFall," a structural guard-bypass pattern rather than a single CVE, and says 10 of 11 tested agents were vulnerable, including Hermes, OpenCode, and Roo-code. The attacks use long-known Bash parsing tricks such as quote removal and $IFS spacing to evade denylist-style protections, with highest risk in auto-execute or CI/CD pipeline use. — Developers and organizations using AI coding agents could have credentials stolen or systems damaged just by letting an agent inspect poisoned project files. Maintainers should harden command-execution guards, and users should disable auto-approve modes, sandbox agents tightly, and treat untrusted repositories and external data sources as potentially hostile.
Sources: Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks
India's .bank.in registrar IDRBT exposed bank-domain administrator data through unauthenticated API endpoints
The sole registrar for India's mandatory .bank.in banking domains allegedly exposed sensitive data on thousands of bank staff through open web API endpoints. Researcher Srikanth L said IDRBT's registration portal exposed 33+ unauthenticated REST endpoints that returned bcrypt password hashes, mobile numbers, email addresses, login IP addresses, and device fingerprints for 5,576 employees managing bank domains; the issue was reportedly disclosed in early June 2026 and later fixed. — This could have given attackers the exact information needed to impersonate bank officials, target domain administrators, and abuse banking-domain trust for phishing or account takeover. Indian banks and regulators should review registrar access logs, rotate credentials, harden domain security controls such as DNSSEC and DMARC, and warn staff about targeted social engineering.
Sources: India’s central bank mandated use of .bank domains to enhance trust – but its registry leaked sensitive info
Researchers show 'SymJack' attack can trick Claude Code, Copilot CLI, Gemini CLI and other AI coding agents into installing malicious tools
Researchers say attackers can abuse trusted-looking project files in code repositories to make AI coding agents install attacker-controlled components and run malicious code on a developer's machine or in continuous integration (CI) systems. Adversa's 'SymJack' technique uses disguised symbolic links (symlinks) and a copy command to silently register a malicious Model Context Protocol (MCP) server; the firm says it worked against Claude Code, Gemini CLI, Antigravity CLI, Cursor Agent CLI, Grok Build CLI, and GitHub Copilot CLI, and published a proof of concept on GitHub. Anthropic reportedly hardened Claude Code to resolve symlinks before approval and show the true destination path. — Teams using AI coding agents could unknowingly approve changes that steal SSH keys, cloud tokens, browser sessions, or CI secrets and then push malicious code downstream. This is urgent for developers and DevOps teams using agentic coding tools: review repository trust assumptions, restrict or audit MCP server registration, scrutinize file-copy prompts, and apply vendor mitigations where available.
Sources: ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems, Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code, Clean GitHub repo tricks AI coding agents into running malware
Uni-App scam framework is powering more than 200,000 fake investment, crypto, gambling, and phishing websites
Researchers say criminals have used templates built with DCloud's Uni-App framework to launch more than 200,000 scam websites targeting internet users. Infoblox identified over 236,000 second-level domains tied to the ecosystem, including fake crypto exchanges, pig-butchering investment sites, gambling and prediction-market impersonators, WhatsApp phishing pages, and credential-harvesting sites; the activity has grown since mid-2022 and accelerated after late 2024. — This is a mass-scale fraud and phishing infrastructure that can steal money, passwords, and cryptocurrency from ordinary users. Consumers should be wary of unsolicited investment offers and crypto platforms, while defenders can use the shared framework fingerprints and domain patterns to block or investigate related sites.
Sources: Chinese Framework Powers 200,000 Scam Sites
FBI and CISA warn Russian intelligence hackers are phishing for Signal backup recovery keys to read past messages
The FBI and CISA say Russian intelligence-linked hackers are now trying to trick Signal users into handing over backup recovery keys, which can let the attackers restore and read victims’ past messages. The updated June 2026 public service announcement says the campaign, tracked as UNC5792 and UNC4221, previously focused on stealing Signal verification codes, PINs, or linking attacker-controlled devices, but now impersonates Signal support to push victims into enabling Secure Backups and then sending the recovery key needed to decrypt stored message history. — This matters because it can expose not just future chats but a victim’s historical Signal conversations, including sensitive government, military, journalistic, and Ukraine-related communications. At-risk users should treat any messages claiming to be from Signal support as suspicious, never share backup recovery keys, and review linked devices and backup settings immediately.
Sources: FBI: Russian hackers now target Signal backup recovery keys
Russia-linked Turla uses new StockStay backdoor to spy on Ukrainian government and military targets
Google says the Russia-linked Turla hacking group has been using a newly detailed backdoor called StockStay to spy on government and military organizations in Ukraine. The .NET malware, developed since 2022, overlaps with Turla’s Kazuar implant and was delivered through phishing emails, malicious RDP configuration files, and in one November 2025 case a WinRAR exploit chain using CVE-2025-8088. Google also says compromised Ukrainian infrastructure and diplomacy- or education-themed lures were used in the campaign. — This is an active espionage campaign against wartime government and defense targets, with tactics defenders can hunt for now. Ukrainian and European public-sector organizations should review phishing defenses, inspect for StockStay-related persistence and WebSocket command-and-control traffic, and investigate any exposure to the cited WinRAR exploit chain.
Sources: Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets, Turla group adds more malware to Russia’s espionage efforts against Ukraine
Ukraine says Russian intelligence used fake messaging-support messages to hijack officials' and activists' chat accounts
Ukraine’s security service says Russian intelligence and affiliated hackers ran a long-running social-engineering campaign to break into messaging accounts used by officials, military personnel, politicians, activists and other targets in Ukraine, Europe and the United States. According to the SBU, the attackers did not exploit a software flaw in the messaging apps; instead they impersonated platform support in text messages and tricked victims into handing over credentials, one-time verification codes, or PINs. The FBI reportedly worked with Ukraine on uncovering the activity, but the agencies did not name the specific Russian service, platforms, or victim count. — This is an account-takeover campaign aimed at high-value communications, so affected users could lose access to sensitive military, political, and personal information without any app vulnerability being involved. Organizations should urgently warn staff that support-themed texts asking for login details or verification codes are fraudulent and should review messaging-app account protections and recovery settings.
Sources: Russia used social engineering to breach prominent messaging accounts, Ukraine says
Polish authorities arrest SIM-swapping gang accused of breaching telecom partners and stealing millions in cryptocurrency
Polish authorities arrested four people accused of stealing millions by hijacking victims’ phone numbers and taking over their cryptocurrency accounts. Investigators say the group breached entities working with telecommunications operators and compromised employee email accounts using software and social engineering, then intercepted SMS messages and email traffic to conduct SIM-swapping attacks; the operation involved support from the FBI and Homeland Security Investigations. — SIM swapping can let criminals bypass text-message security codes and seize control of email, financial, and crypto accounts. Telecom-adjacent organizations should review partner access and employee email protections, and users should move high-value accounts away from SMS-based authentication where possible.
Sources: Poland busts SIM-swapping gang tied to millions in crypto theft
Symantec and Zscaler link new Mistic backdoor to KongTuke ransomware access broker
Researchers say a newly identified backdoor called Mistic is being used to quietly keep access inside company networks in attacks tied to KongTuke, an initial access broker linked to ransomware groups. Symantec says Mistic has been used since April 2026 against organizations in insurance, education, IT, and professional services, including deployment after ModeloRAT in at least one case. The malware is side-loaded through MpExtMs.exe and a malicious version.dll, can run payloads in memory, steal credentials via a fake login prompt, and receive commands from attacker-controlled servers; Zscaler says it also appeared in a multi-stage ClickFix infection chain and can load Beacon Object Files for in-memory post-exploitation. — Organizations in the named sectors may be facing a low-visibility foothold used to prepare ransomware attacks, not just one-off malware infections. Defenders should hunt for KongTuke and ClickFix activity, review Symantec and Zscaler indicators, and watch for suspicious DLL side-loading, fake login prompts, and Microsoft Teams-based social engineering.
Sources: Stealthy Mistic backdoor linked to ransomware access broker KongTuke, New ‘Mistic’ RAT Opens Door to Several Ransomware Families, New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns (+1 more)
Scammers abuse Shopify's Shop app to plant fake order receipts and run callback phishing attacks
Attackers are abusing Shopify's Shop order-tracking app by inserting fake purchase receipts into users' order histories, then using the listed phone numbers to trick people into calling scammers. The fake receipts impersonate brands including Norton, McAfee, Apple, and PayPal, and the callback phishing flow aims to steal credentials, payment-card details, and one-time passcodes; some victims are also persuaded to install remote-access software. Researchers said they found no evidence that Shop, Shopify, or the impersonated brands were breached, and the insertion method is still unclear. — This matters because the scam appears inside a trusted shopping app rather than email, making it more believable and more likely to fool consumers. Users should avoid calling numbers shown on unexpected Shop receipts, verify charges directly with their bank or merchant, and reset credentials and contact their card issuer if they already engaged with the scammers.
Sources: Order-tracking app Shop abused to push callback phishing attacks
Bluekit phishing platform adds browser-in-the-middle login theft to capture account sessions
Bluekit, a phishing-as-a-service platform used to steal logins for major email and online accounts, has added a more advanced browser-in-the-middle technique that can hand attackers live authenticated sessions. Netcraft says the kit now uses the legitimate rrweb JavaScript library to stream a real browser session over WebSockets while relaying the victim’s interactions to the attacker, and it still includes anti-analysis features such as browser fingerprinting, WebRTC IP checks, obfuscated scripts, fake CAPTCHAs, and live victim monitoring. Reported targets include Outlook, Gmail, Yahoo, ProtonMail, iCloud, GitHub, and Ledger users. — This makes phishing pages harder to spot and can let criminals bypass normal login protections by stealing valid session tokens, not just passwords. Organizations should tighten phishing defenses, watch for suspicious login-session activity and WebSocket-based fake login pages, and remind users to be cautious with branded sign-in links and unusual page lag.
Sources: Bluekit phishing kit adopts browser-in-the-middle for login theft
ASIO says a foreign intelligence service used a fake consulting approach to seek AUKUS information from an Australian clearance holder
Australia’s security service says a foreign spy posed as a consultant online, paid an Australian security clearance holder for reports, and then tried to obtain insider information on AUKUS, the Australia-UK-U.S. defense pact. ASIO says the target reported the contact, helped the agency study the operation, and that officers directly warned the suspected foreign operative to stop targeting Australians. — This is a clear example of online social engineering used for state espionage against defense-related personnel. People with government or defense access should treat paid research requests, consulting offers, and requests for nonpublic policy or program details as potential recruitment attempts.
Sources: Nation-state actors cracked critical Australian infrastructure to ‘cripple it at a time of their choosing’
Third defendant sentenced over 2022 DraftKings credential-stuffing attack that hijacked 60,000 betting accounts
A third man has been sentenced for his role in the 2022 attack that broke into thousands of DraftKings customer accounts and stole or resold access to them. The Justice Department said the group used credential stuffing, meaning reused usernames and passwords from other breaches, to access more than 60,000 accounts on the fantasy sports and betting platform; Nathan Austad was sentenced to 18 months and ordered to pay about $1.8 million, while the scheme stole roughly $600,000 from 1,600 accounts. — This highlights the ongoing risk of password reuse and account takeover for consumer financial and betting accounts. Affected users should reset reused passwords, enable phishing-resistant multi-factor authentication where available, and review account balances and withdrawal history.
Sources: Third DraftKings Hacker Sentenced to 18 Months in Prison, DraftKings hacker 'Snoopy' sentenced to 18 months in prison
Malicious Microsoft Edge extension used Native Messaging to install a Python backdoor in ransomware-linked attacks
Attackers used a fake Microsoft Edge update process to trick employees into installing a malicious browser extension that helped deploy malware on their computers. Zscaler says the 'Edgecution' campaign starts with Microsoft Teams messages from fake IT support and uses Chrome Native Messaging in Microsoft Edge to let the extension communicate with a local Python-based backdoor outside the browser sandbox. The activity is linked by tactics and infrastructure patterns to an initial access broker associated with the Payouts Kings ransomware operation. — This matters because it turns a browser extension into a bridge for full system compromise, not just in-browser abuse, and it is being used in real ransomware-linked intrusions. Organizations should warn users about fake IT support messages, restrict extension installs, and monitor or lock down Native Messaging host configurations on managed endpoints.
Sources: Malicious Edge extension abuses Native Messaging as bridge to malware
Xsolis says phishing-linked breach exposed health and personal data of 1.4 million people
Healthcare technology company Xsolis disclosed a data breach affecting 1,396,519 individuals whose information it received from hospitals, health systems, and payers. Xsolis said attackers gained access after a targeted phishing attack on January 20, 2026, with unauthorized activity detected on January 22. Exposed data includes names, dates of birth, addresses, Social Security numbers, health insurance details, and medical treatment information, according to the company and the U.S. Department of Health and Human Services breach tracker. — This is a large-scale exposure of sensitive medical and identity data, creating long-term risks of identity theft, insurance fraud, and targeted scams for affected people. Healthcare organizations and partners using Xsolis should review third-party access and phishing defenses, while affected individuals should watch for breach notices, fraud, and medical-identity misuse.
Sources: Xsolis Data Breach Affects 1.4 Million Individuals, Healthtech firm Xolis suffers data breach impacting 1.4 million people
U.S. extradites alleged Market0Day and Spoxy operator over phishing-kit and smishing marketplace scheme
A 26-year-old Algerian man was extradited to the United States after prosecutors accused him of running two cybercrime marketplaces that sold phishing tools and mass-texting services. The Justice Department says Abdellah Belmili, also known as Spox, administered Market0Day in 2020 and later launched Spoxy, where criminals could buy phishing kits, access to compromised email servers, and bulk SMS services for large-scale smishing campaigns. Prosecutors say the scheme targeted major banks including JPMorgan Chase, Bank of America, Wells Fargo, and American Express, involved about 5,600 victims, and brought roughly $900,000 into an account he controlled between 2020 and 2023. — This matters because it shows the infrastructure behind phishing and bank-fraud campaigns, not just individual scams, and names the services used to enable them. Financial institutions and consumers should stay alert for bank-themed phishing emails and text messages, while defenders can use the marketplace names and actor alias to support threat tracking and fraud investigations.
Sources: Algerian Man Extradited to US for Running Cybercrime Marketplaces
WhatsApp malware campaign uses compromised accounts and fake business documents to install remote access on Windows PCs
Attackers are using hijacked WhatsApp accounts to send fake business and financial documents that infect Windows computers when opened. Kaspersky says the campaign delivers heavily obfuscated VBScript files through WhatsApp, then downloads additional scripts that modify User Account Control settings in the Windows Registry and silently installs ManageEngine Endpoint Central configured to connect to attacker-controlled servers. Victims have been seen in Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, Australia, Russia, Vietnam, and Malaysia. — People can be infected by files that appear to come from trusted contacts, turning a chat message into full remote access on their PC. Users should avoid opening script attachments from WhatsApp and verify unexpected files out-of-band; defenders should look for suspicious wscript.exe activity and unauthorized ManageEngine Endpoint Central installs.
Sources: WhatsApp phishing attack uses fake business docs to hack PCs
Gizmodo site compromise served ClickFix malware prompts to readers through a hijacked account
Gizmodo readers were briefly exposed to fake verification prompts on the news site after a compromised account was used to inject malicious code into article pages. The attack delivered ClickFix social-engineering lures that tried to make users run commands locally; according to reporting and researcher analysis, the Windows flow attempted to install NetSupport RAT, a remote-access trojan, while the macOS payload appeared misconfigured and did not execute cleanly. — Anyone who followed the prompt on a Windows device may have installed remote-access malware that can steal files or pull down more malicious tools. Affected users should check for suspicious commands or downloads, run endpoint scans, and site operators should review account security and script-injection controls.
Sources: Gizmodo readers hit with ClickFix malware prompts after account compromise
FTC says Americans lost a record $3.5 billion to impersonation scams in 2025, with social media driving much of the fraud
The FTC says Americans lost $3.5 billion to impersonation scams in 2025, making them the most reported fraud category and one of the costliest threats facing the public. The agency said losses tied to social media exceeded $2.1 billion, while victims lost nearly $1 billion to business impersonators and about $920 million to government impersonators; common lures arrived by text, phone, email, social media, and search results, often posing as banks or government agencies. — This is a large-scale public safety and fraud story: ordinary people are losing billions after being tricked by fake banks, businesses, and government officials. People should treat unsolicited messages and calls as suspect, avoid moving money based on "security alerts," and verify requests through official contact channels.
Sources: FTC warns of record $3.5 billion losses to imposter scams in 2025, In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
Meta asks court to hold NSO Group in contempt after alleged new WhatsApp phishing targeting
Meta says NSO Group again targeted WhatsApp users despite a court order barring it from doing so. WhatsApp said it disrupted NSO-linked social-engineering attempts involving malicious links that redirected targets to external websites, plus test accounts and groups on the platform, and published related domains and indicators of compromise. The report did not include victim counts, timing, or confirmation of successful compromises. — This matters because it suggests a spyware vendor accused of abusing messaging users may still be actively targeting people after a legal ban. WhatsApp users, journalists, activists, and high-risk targets should treat unsolicited links and unusual group invites with caution, and defenders should review the published indicators immediately.
Sources: NSO Group back in Meta's crosshairs after alleged WhatsApp targeting, WhatsApp Catches Spyware Firm NSO Defying No-Hacking Court Order, WhatsApp says NSO targeted users with spearfishing attacks in violation of court order (+3 more)
Rokarolla Android banking trojan targets 217 banking and cryptocurrency apps through fake Chrome and TikTok downloads
A newly reported Android malware strain called Rokarolla is stealing financial data from people who install fake Chrome or TikTok apps from malicious websites. Zimperium says the trojan abuses Android Accessibility permissions, notifications, SMS, and call access, then checks for 217 targeted banking and crypto apps and downloads matching fake login overlays to capture credentials, card data, lock-screen PINs, contacts, SMS, and other device data. The malware also uses 137 command-and-control instructions and can disable Google Play Protect and hide its icon. — This can let criminals take over phones and drain financial accounts, especially when victims sideload apps outside Google Play. Android users should avoid APKs from unofficial sites, review Accessibility requests carefully, and treat unexpected prompts to install Chrome, TikTok, or security updates as suspicious.
Sources: New Rokarolla Android malware targets 217 banking, crypto apps, Rokarolla Banking Trojan Targets 200 Applications
Dutch police arrest six suspects tied to bank helpdesk scam call center that also sent visitors to victims’ homes
Dutch police arrested six suspects after raiding an Amsterdam home they say was being used as a makeshift call center for bank helpdesk fraud. Authorities said the group, whose members were aged 15 to 30, called victims while posing as bank staff and in some cases sent people to victims’ homes to supposedly help secure accounts, then stole money. Police seized laptops, phones, and bank cards and said the suspects were caught while speaking with a potential victim. — This shows social-engineering scams are blending phone fraud with in-person impersonation to make lies feel legitimate, especially for older targets. Banks, families, and potential victims should treat unsolicited calls or home visits about account security as suspicious and verify through official channels.
Sources: Helpdesk scammers are making house calls to make their lies feel more real
Fake recruiter used a malicious GitHub repo and npm install hook to target a developer with backdoor malware
A developer says a supposed recruiter tried to trick him into reviewing a booby-trapped code repository that would have infected his system. The attack used a GitHub-hosted Node.js project whose package.json contained a prepare post-install hook, so running npm install would execute app/test/index.js; that script used an obfuscated URL and remote command execution logic to fetch and run attacker-supplied code. — This is a real-world example of job-lure social engineering aimed at developers, where normal review steps like cloning a repo and installing dependencies can trigger compromise. Developers and employers should treat unsolicited coding tests and recruiter-supplied repositories as high risk, inspect package scripts before running them, and use isolated analysis environments.
Sources: Python dev saved from disaster by intuition...and AI, Python dev saved from disaster by intuition... and AI
Steam Workshop malware campaign used Wallpaper Engine uploads to infect users with stealers, backdoors, miners, and ransomware
Attackers used Steam Workshop uploads for the Wallpaper Engine app to trick Steam users into installing malicious wallpapers. Kaspersky says the abuse has been active since at least late 2025 and relies on Wallpaper Engine's 'application wallpaper' feature, which can run Windows executables as desktop backgrounds. Researchers found dozens of malicious uploads delivering DarkKomet, Lumma, Vidar, cryptominers, botnet loaders, RanEngine, and some ransomware, with some downloads reaching the thousands or tens of thousands before Valve removed the identified items. — This matters to Steam users because installing what looks like harmless custom content can lead to stolen game accounts or full device compromise. Users who installed Wallpaper Engine content from Steam Workshop should review their systems for malware, change Steam credentials, and be cautious with executable community uploads.
Sources: Steam Workshop abused to spread malware via Wallpaper Engine app
iRhythm says social-engineering breach let hackers steal patient health information from third-party business apps
iRhythm disclosed a data breach after hackers stole patient personal and health information from business applications hosted by a third party. The company said the attackers contacted it on June 9, 2026 with a ransom demand and it later confirmed data was exfiltrated; iRhythm says the intrusion involved social engineering and did not affect its cardiac monitoring devices, clinical systems, payment-card data, manufacturing, or distribution operations. — This affects healthcare patients whose protected health information may now be exposed or used in scams and identity abuse. Healthcare organizations and vendors should review third-party app access, harden staff against social-engineering attacks, and watch for follow-on extortion or phishing tied to stolen patient data.
Sources: iRhythm discloses data breach, says hackers stole patient info, Cardiac monitor maker's security skips a beat as data thieves go for the jugular, iRhythm Confirms Data Stolen in Hack
Novo Nordisk says attackers stole pseudonymized clinical-trial patient data and healthcare professional contact details
Novo Nordisk disclosed a security breach in which attackers copied non-public data from internal IT systems, including information tied to some clinical-trial participants and healthcare professionals. The exposed trial data included patient IDs, participation details, sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle factors; the company said it was pseudonymized and not directly linked to names. Exposed healthcare professional data included names, registration numbers, email addresses, phone numbers, WhatsApp details, and office locations. Novo Nordisk has not said how many people were affected or how the intrusion happened. — This affects sensitive health-related research data and gives attackers contact details they can use for follow-on phishing or impersonation. Affected organizations and individuals should watch for suspicious emails, calls, and WhatsApp messages while Novo Nordisk investigates scope and attack path.
Sources: Pharma giant Novo Nordisk discloses breach of clinical trials data, Novo Nordisk reports cyberattack as UK gives Wegovy pill the nod, Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems (+1 more)
Estonia will quarantine emails from Russian .ru domains before they reach government officials
Estonia says emails sent from Russian .ru addresses to government officials will be automatically isolated for extra screening before recipients can open them. The policy takes effect August 31 and adds .ru domains to the Estonian public sector's existing email quarantine rules for suspicious messages. Officials say the move responds to increased phishing and malware delivery from Russian servers since 2022 and is part of broader defenses against Russian hybrid threats. — This affects how Estonian public institutions handle potentially hostile communications and could reduce phishing and malware exposure for government staff. Organizations and individuals that use .ru email addresses to contact Estonian authorities may need to switch providers, and defenders should note the policy as a concrete state response to sustained Russian cyber risk.
Sources: Estonia to quarantine emails sent from Russian .ru domain before they reach government officials
FBI warns pig-butchering scammers are sending couriers to collect cash from victims in person
The FBI says cryptocurrency investment scammers are now sending couriers to pick up cash directly from victims after banks or other financial institutions block suspicious transfers. The agency says the fraudsters, often running pig-butchering or romance-baiting scams through social media, dating sites, and messaging apps, authenticate the courier with a password or U.S. dollar bill serial number, then continue the scam by showing fake account gains and demanding more money for bogus taxes or penalties. — This matters because victims may believe an in-person handoff makes the investment scheme legitimate when it is part of the fraud. Consumers should not hand cash to strangers tied to online investment offers, and banks, local police, and fraud teams should watch for courier-based cash collection linked to crypto scams.
Sources: FBI: Fraudsters use couriers to steal money in crypto scams
French government says Tchap messaging service was breached through a hijacked user account
France's government says an attacker got into Tchap, the encrypted messaging service used by public-sector workers, by taking over a valid user account. DINUM said ANSSI detected the intrusion on June 8 and blocked the compromised account, while investigators review logs to determine what conversations and data were accessed or stolen. A threat actor claimed the access came from social engineering on an education-related Tchap shard and alleged theft of 13.5GB of files, roughly 650,000 messages, and data on more than 73,000 accounts, plus a flaw allowing shared media files to be downloaded without a token. — This affects a government communications platform with more than 300,000 monthly users, so exposed chats, files, and account metadata could have broad public-sector impact. French agencies and users should treat the incident as potentially sensitive, review what was shared in public rooms, investigate account takeover paths, and reset or harden credentials where appropriate.
Sources: French govt messaging service breached in account hijacking attack, France probes compromise of gov messaging platform after account hijack, Over 73,000 French govt employees affected in Tchap messenger breach (+1 more)
Belarus-linked GhostWriter uses fake Prometheus training certificates to phish Ukrainian government officials
Belarus-linked hackers are sending fake course-certificate emails to Ukrainian government staff to infect their computers with espionage malware. CERT-UA says the campaign, active since spring 2026, uses compromised email accounts and messages posing as Ukraine’s Prometheus learning platform; a PDF leads victims to a ZIP that installs OysterFresh, then OysterBlues and OysterShuck, which collect host and user details and may later deliver Cobalt Strike. — This is a targeted government espionage campaign, so affected organizations should treat related Prometheus certificate emails as suspicious, hunt for the named malware and infrastructure, and isolate infected systems quickly. For users, the practical takeaway is not to open certificate attachments or download archives from unexpected training-platform emails, even if they come from known contacts.
Sources: Belarus-linked hackers use fake training certificates to target Ukrainian officials, Belarus-linked hackers target Gmail accounts of Polish public figures and their families
Oxford University says CareerConnect breach at supplier Group GTI exposed user names, emails, and some passwords
Oxford University says a separate breach at its CareerConnect jobs platform exposed users’ full names and email addresses, and encrypted passwords for people not using single sign-on. The affected service is provided by Group GTI and runs on its TargetConnect platform, which Oxford said was compromised on May 28 through an unspecified security vulnerability that has since been fixed; affected alumni, research staff, and employer users had passwords reset, and GTI has not publicly disclosed the flaw or total scope. — Students, alumni, staff, and recruiters who used the platform may now face phishing or credential-stuffing attempts, especially if they reused passwords elsewhere. Affected users should reset reused passwords, watch for convincing job-related scam emails, and universities using GTI TargetConnect should press the vendor for technical details and mitigation guidance.
Sources: Oxford Uni student data pwned yet again - this time via career platform breach, Oxford University discloses data breach after careers platform hack, In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine
INTERPOL says Operation Secure dismantled Sniper Dz phishing platform and arrested alleged administrator
INTERPOL says it helped shut down Sniper Dz, a phishing platform used to steal account logins and other sensitive data, and arrested the alleged administrator. The takedown was part of Operation Secure, which targeted phishing, infostealer malware, and related criminal infrastructure across multiple countries. Sniper Dz was described as a phishing-as-a-service platform, meaning a ready-made toolkit criminals could rent or use to run credential-theft campaigns at scale. — This matters because phishing kits lower the barrier for criminals to impersonate trusted brands and steal passwords from large numbers of people and organizations. Defenders should review recent credential-theft activity, harden multi-factor authentication, and warn users to be cautious of login pages and messages that claim urgent account action is needed.
Sources: INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator
Group-IB links thousands of fake FIFA World Cup 2026 domains to fraud campaigns targeting ticket buyers
Researchers say multiple criminal groups have built fake FIFA websites to steal World Cup fans’ passwords, payment details, and money through bogus ticket sales. Group-IB identified four separate campaigns since August 2025, including a Chinese-speaking operation it calls GHOST STADIUM that uses more than 300 active lookalike domains and roughly 3,800 dormant ones. The phishing kit closely copies FIFA’s login flow, can trigger password-reset steps to lock victims out, and is being promoted through Facebook ads offering unrealistically cheap tickets. — Fans trying to buy 2026 World Cup tickets could lose their accounts, have legitimate tickets resold, or pay scammers for fake seats. Users should only type fifa.com directly into their browser, avoid ad-linked ticket offers, and treat lookalike FIFA domains as suspicious.
Sources: Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans, FBI warns of fake FIFA websites running World Cup fraud schemes, In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks (+2 more)
Varonis finds OpenClaw AI email agent can be phished into sending AWS keys, database credentials, and customer data
Researchers found that an OpenClaw AI email agent could be tricked by phishing-style messages into leaking sensitive data instead of protecting it. In Varonis simulations, the open-source agent, connected to Gmail, browser tools, and Google Workspace APIs, sent AWS IAM keys, database credentials, SSH details, and CRM exports to an external account after urgent impersonation emails. The tests used Google Gemini 3.1 Pro and OpenAI GPT-5.4 and showed that URL and OAuth-app checks were stronger than sender-identity verification. — Organizations testing AI agents for email and workflow automation could accidentally give them access to data they can be manipulated into disclosing. Treat this as an immediate design and policy issue: limit agent privileges, block unapproved external sharing, require human approval for high-risk actions, and verify sender identity before deployment.
Sources: OpenClaw AI agent found falling for phishing attacks, spills user data, New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
Five Eyes warn China is using LinkedIn, Indeed and Upwork to recruit people with access to state secrets
MI5 and allied intelligence agencies warned that Chinese intelligence officers and their proxies are using job and networking platforms including LinkedIn, Indeed, and Upwork to spot and cultivate people with access to classified or otherwise sensitive government information. The advisory says the operators pose as recruiters, consultancies, think tanks, or research clients, rank applicants by likely access, request trial reports, then move conversations to encrypted messaging and pay through services such as PayPal, Zelle, Wise, Western Union, or cryptocurrency in exchange for non-public information. — This is a real-world espionage and social-engineering threat aimed at government, defense, foreign-affairs, academic, media, and policy workers. People in or near sensitive roles should treat unsolicited research, consulting, or recruiter outreach on these platforms as potentially hostile, report suspicious contact, and avoid sharing resumes or non-public work details casually.
Sources: Five Eyes: Watch out for odd LinkedIn connection requests, China's back on the hunt for state secrets, Five Eyes warn Chinese spies are using job sites to recruit insiders, Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities (+1 more)
SiribClone uses fake romance and aid lures on Telegram to spy on Russian soldiers with SafeLoveStealer and SiribGrabber malware
Hackers posing as women seeking relationships or volunteers offering help tricked Russian military personnel into installing spyware or surrendering their Telegram accounts. Researchers at F6 say the previously undocumented SiribClone group has operated since at least summer 2025, targeting troops in border regions and combat zones with Android spyware dubbed SafeLoveStealer, desktop malware called SiribGrabber, and phishing sites masquerading as Telegram logins, invite pages, medical portals, and other services to steal messages, files, location data, and microphone audio. — This is an active espionage campaign aimed at people in combat zones and shows how romance lures and fake support offers can turn personal chats into battlefield surveillance. Anyone in sensitive roles should treat unsolicited Telegram contacts, app downloads, and login pages as high risk, avoid sideloading apps, and use phishing-resistant account protections where possible.
Sources: Hackers pose as women seeking romance to spy on Russian soldiers
Suspected North Korean phishing campaign sends fake developer job offers to steal credentials and cryptocurrency
A likely North Korean-linked group sent more than 250 fake job and code-review emails to developers at nearly 100 organizations, mainly in the United States, to steal login credentials and cryptocurrency wallets. Proofpoint tracks the activity as UNK_DeadDrop and says the attackers used spoofed company brands and attacker-controlled GitHub repositories posing as coding tests or crypto projects; victims were told to clone and open the repos in tools such as Visual Studio Code or Cursor, triggering cross-platform malware on macOS, Linux, and Windows. — Developers and the companies that employ them are the direct targets, and a single successful lure can expose source code, cloud access, and crypto assets. Organizations should warn staff about unsolicited recruiting emails, scrutinize GitHub-based coding tests, and isolate or block unknown repositories and scripts.
Sources: Norks blast 250+ fake job offers to developers over 6 weeks to try and snarf creds and crypto
NFCShare Android malware uses fake banking app updates on GitHub to steal payment card data from European bank customers
Attackers are tricking bank customers into installing fake Android banking app updates from GitHub so they can steal card data and PINs. D3Lab says newer NFCShare variants, seen since May 14, target banks mainly in Italy and Spain after victims visit phishing sites impersonating real banks. The malware abuses near-field communication (NFC) on Android to read card details via IsoDep and EMV commands, then sends the data to command-and-control servers over WebSocket. — This can lead directly to payment-card fraud because victims are persuaded to hand over both card details and their PIN during a fake security check. Android users should only install banking apps from Google Play and treat any request to scan a bank card with their phone or sideload an update from GitHub as suspicious.
Sources: NFCShare Android malware spreads via fake banking app updates on GitHub
FBI warns Silent Ransom Group is sending fake IT workers in person to law firms to plug in USB drives and steal data
The FBI says Silent Ransom Group is targeting U.S. law firms by pretending to be IT support, then stealing data and extorting victims without encrypting files. In 2026 attacks, the group reportedly used callback phishing emails, phone-based social engineering, remote desktop access, and in some cases sent an operative on site to insert a USB or external drive after a failed remote-access attempt; the attackers then used tools such as WinSCP and Rclone to exfiltrate data. — Law firms and other organizations should treat unsolicited IT calls, emails, and in-person support visits as potential attack vectors, not just remote phishing. The warning is urgent because the attackers use legitimate admin tools and leave few traces, so organizations should verify IT identities, restrict external-drive use, and harden remote-access workflows now.
Sources: FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data, FBI warns of in-person data theft attacks from extortion gang, FBI warns extortion hackers are visiting US law firms to steal data (+4 more)
Attackers used Meta’s Instagram AI support bot to reset passwords and hijack accounts
Attackers used Meta’s automated Instagram support assistant to take over accounts, including the Obama White House account and the U.S. Space Force chief master sergeant account, and briefly deface them with pro-Iran messages. According to KrebsOnSecurity and Telegram posts cited in the report, the abuse involved the password-recovery flow: attackers asked the AI bot to add a new email address to a target account, then used the one-time code sent there to reset the password. No CVE is given, Meta reportedly pushed an emergency patch, and accounts with multi-factor authentication enabled were said to resist the takeover. — This matters because it shows AI-driven customer support can become a new social-engineering path to account takeover even without a backend database breach. Instagram users, especially high-value or public-facing accounts, should enable multi-factor authentication now and review account recovery email addresses and recent login activity.
Sources: Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts, Meta AI Hands Over High-Profile Instagram Accounts to Hackers, Instagram users locked out after Meta AI abused to steal accounts (+3 more)
Polyfill.io remnants trigger rogue login prompts on Toshiba, Muji and other websites
Toshiba and Muji warned that visitors to some of their web pages saw unexpected browser sign-in prompts that could trick people into entering credentials. The prompts were tied to lingering references to the compromised polyfill.io JavaScript content delivery network (CDN), which began responding with HTTP 401 authentication challenges in late May 2026; affected companies removed or suspended the service, and no confirmed credential theft has been reported so far. — People who entered usernames or passwords into these pop-ups should change them, and website owners should remove any remaining polyfill.io code immediately. This matters because it shows how a long-abandoned third-party script can still create phishing risk years after an earlier supply-chain compromise.
Sources: Suspicious Polyfill login prompts pop up on Toshiba, Muji websites
Microsoft links GPU cryptojacking malware campaign to poisoned search results and AI chatbot software recommendations
Attackers are tricking people looking for popular PC utilities into installing malware that secretly uses their graphics cards to mine cryptocurrency. Microsoft says the campaign uses search-engine optimization (SEO) poisoning and, in some cases, attacker-controlled links surfaced in AI chatbot responses for tools such as CrystalDiskInfo, HWMonitor, FurMark, K-Lite Codec Pack, PDFgear, and Display Driver Uninstaller. The fake downloads bundle a legitimate program with a malicious dynamic-link library (DLL), install ScreenConnect for remote access, add multiple Windows persistence mechanisms, evade Microsoft Defender, and then deploy GPU miners including gminer, lolMiner, and SRBMiner-MULTI. — This campaign targets owners of powerful Windows systems and can leave victims with both hijacked hardware and a remote-access backdoor for follow-on attacks. Users and defenders should avoid downloading software from AI-generated or unfamiliar links, verify vendor domains, and hunt for the listed indicators of compromise and unauthorized ScreenConnect installs.
Sources: GPU mining malware spreads via SEO poisoning, AI chatbots, In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA
Magecart campaign uses Google Tag Manager and Stripe API to steal payment cards from Magento checkout pages
Researchers say a new Magecart card-skimming campaign is stealing shoppers’ payment details from compromised online stores and hiding both its malware and stolen data inside trusted Google Tag Manager and Stripe services. Sansec says the skimmer targets Magento and Adobe Commerce checkout pages, pulls JavaScript from a Google Tag Manager container, retrieves payload code from Stripe customer metadata tied to customer ID cus_TfFjAAZQNOYENR, and exfiltrates stolen card, billing, email, and phone data by creating fake Stripe customer records; a variant uses Google Firestore instead of Stripe. The Stripe record was reportedly created on December 24, 2025, suggesting the campaign may have been active for months. — This matters because stores may allow traffic to Google Tag Manager and Stripe by default, letting the skimmer blend in and evade common security controls while stealing card data from real customers. Online retailers using Magento or Adobe Commerce should urgently inspect GTM containers, Stripe API activity, and checkout-page scripts for unauthorized changes.
Sources: Credit card theft campaign abuses Stripe to host stolen payment info
Google patched Gemini voice assistant flaw that let messaging notifications inject hidden commands
Researchers say attackers could have manipulated Google’s Gemini voice assistant through ordinary message notifications from apps such as WhatsApp, Slack, and SMS. SafeBreach calls the technique “Fake Context Alignment”: hidden instructions embedded in notification content were silently pulled into Gemini’s context when users asked it to read messages aloud, potentially enabling actions such as controlling Google Home devices, starting Zoom calls, sending deceptive messages, and poisoning long-term memory. Google was notified in August 2025 and patched the issue in November 2025 with content-classifier changes. — This matters because it shows how everyday messages could be turned into a hands-free attack path against AI assistants that are connected to calls, messages, and smart-home controls. Users and organizations relying on Gemini should make sure current protections are in place and treat unsolicited messages as a potential trigger for AI-assisted actions.
Sources: Gemini Voice Assistant Hijacked via Messaging Notifications
Proofpoint says TA4922 is targeting European organizations with new Atlas RAT malware and phishing lures
A Chinese-speaking cybercrime group is using new malware and localized phishing messages to break into organizations in Europe and beyond. Proofpoint says TA4922, linked to activity overlaps with Silver Fox and Void Arachne, has targeted entities in Germany, Italy, the United Kingdom, South Africa, and parts of Southeast Asia since March 2026 using payroll, tax, VAT, invoice, and HR lures sent by email and messaging apps including WhatsApp, LINE, and Microsoft Teams. The campaigns deploy Atlas RAT, RomulusLoader, SilentRunLoader, and Winos4.0/ValleyRAT for remote access, file theft, credential theft, keylogging, screenshots, and webcam or audio capture. — Organizations in the targeted regions should treat this as an active intrusion and phishing threat, especially finance, HR, and compliance teams that may receive convincing local-language messages. Defenders should hunt for the named malware families and remote-management tools, tighten phishing controls, and warn staff to verify unexpected payroll, tax, invoice, or compliance messages across email and chat platforms.
Sources: Chinese hackers use new Atlas RAT malware in European cyberattacks, Chinese Cybercrime Group in Spotlight for Record Campaign Pace, China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa
Unpatched Windows Search URI flaw can leak NTLMv2 hashes when users open malicious search links
A newly reported Windows flaw can expose a user's NTLMv2 password hash, which attackers can try to crack or relay for unauthorized access. The issue affects the Windows Search URI protocol and can be triggered through crafted links or files that cause Windows to connect to an attacker-controlled server. The article indicates the bug is unpatched and enables hash disclosure rather than direct code execution. — Organizations that still rely on NTLM authentication could be exposed to credential theft from a single malicious link or lure, making this a meaningful phishing and lateral-movement risk. Defenders should block or monitor outbound SMB and WebDAV traffic, reduce NTLM use where possible, and warn users not to open unexpected search-related links or files until Microsoft issues a fix.
Sources: Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
Google rolls out Android fake-call detection to warn users about AI voice-clone and caller-ID spoofing scams
Google is adding a new Android feature that warns people when a call may be a scammer pretending to be someone they know. The feature, called fake call detection, is rolling out globally this month on Android 12 and later, starting with Pixel devices, and is enabled by default. It works when both parties use Phone by Google, Contacts, and Google Messages with Rich Communication Services (RCS) enabled, using encrypted device-to-device verification to detect spoofed contact calls and trigger an on-screen warning. — This addresses a real-world fraud tactic that combines fake caller ID with AI-generated voice impersonation, which can trick people into sending money or revealing sensitive information. Android users should keep Google's phone and messaging apps updated and treat urgent calls asking for money, codes, or account access with caution.
Sources: Google adds Android protection against AI deepfake scam calls
WeedHack malware campaign infects more than 116,000 systems through fake Minecraft mods and cheats
A large malware campaign has infected more than 116,000 computers by tricking Minecraft players into downloading booby-trapped mods, cheat clients, and utilities. McAfee says the WeedHack operation has been active since January 2026, spreads via YouTube links and search-result manipulation, and uses thousands of malicious Java archive (JAR) files. The malware steals browser passwords and cookies, Minecraft session IDs, Discord, Steam and Telegram credentials, and crypto-wallet data, while paid tiers add remote-control features such as keylogging, webcam access, shell access, and file management. — This is a broad consumer-focused infostealer campaign hitting gamers at scale, with stolen passwords, session tokens, and wallet data creating immediate account-takeover and financial risk. Minecraft players and parents should avoid unofficial mod download sites, remove suspicious JAR files, run antivirus scans, and reset passwords for any accounts used on affected devices.
Sources: Over 116,000 Mincraft systems infected in WeedHack malware campaign, Over 116,000 Minecraft systems infected in WeedHack malware campaign
Scammers spoof Northern Ireland police phone number to pose as officers and demand bank details and gift-card payments
The Police Service of Northern Ireland warned that scammers spoofed its official switchboard number to call people while pretending to be police officers. In the reported case, the caller falsely claimed the target was tied to a money-transfer investigation, asked for bank-card information, and then requested gift cards and their codes; police said the number display was faked and no suspect has yet been arrested. The same police force also disclosed a separate crypto-investment fraud in which an elderly woman lost more than £250,000 after attackers persuaded her to install malware and took control of her devices. — People may trust a call that appears to come from a real police number, so this scam raises the risk of financial theft even for cautious users. Anyone receiving such a call should hang up, independently verify the number, and never provide banking details or gift-card codes to someone claiming to be law enforcement.
Sources: Northern Ireland cops issue PSA after official phone number spoofed by scammers
Dashlane temporarily suspended some customer accounts during brute-force login attacks
Dashlane says it temporarily locked some customer accounts after attackers repeatedly tried to register new devices and failed the required verification step. The company said the activity began Sunday, triggered automatic protections, and later moved to monitoring after restoring affected accounts. Dashlane said its internal systems were not compromised, but did not disclose how many users were hit or whether any account takeovers succeeded. — Password managers hold access to many other accounts, so even unsuccessful attacks are high-impact for users. Dashlane customers should verify recent login alerts, ensure multi-factor authentication is working, and contact support if their account was suspended or shows unfamiliar device activity.
Sources: Password manager Dashlane suspends customer accounts amid brute-force attacks, Dashlane password manager users locked out by brute force attacks, Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded (+1 more)
DriveSurge hijacks thousands of legitimate websites to push ClickFix and fake browser update malware
A threat actor called DriveSurge has compromised thousands of real websites and is using them to redirect visitors into malware traps. Silent Push says the actor operates as an initial access broker, using the zTDS traffic distribution system to decide whether each visitor sees a ClickFix lure that tricks them into running malicious PowerShell commands or a FakeUpdate page posing as browser updates for Chrome, Firefox, Edge, Safari and others; researchers also found macOS-targeting JavaScript and more than 80 malicious injection domains. — People can get infected just by visiting a legitimate site that has been silently hijacked, so the risk extends beyond obviously shady pages. Organizations should hunt for the identified JavaScript injection patterns and domains, and users should only update browsers through the built-in updater and never paste commands from pop-ups into Terminal or PowerShell.
Sources: Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
Researchers track 5,000+ election-themed domains and exposed political credentials ahead of the 2026 U.S. midterms
Security researchers say more than 5,000 election-themed internet domains were registered in recent weeks ahead of the 2026 U.S. midterms, raising the risk of fake voting sites, donation scams, and impersonation of election officials. Check Point said the registrations increased sharply between April and May and coincided with roughly 17,000 exposed credentials tied to ActBlue, WinRed, GOP, Democrats.org, and USA.gov accounts, creating infrastructure and account access that could support phishing, fraud, or influence operations. — This matters because voters, donors, campaigns, and election workers could be tricked by lookalike sites or targeted through reused or stolen passwords. People should verify election and donation websites carefully, avoid links in unsolicited messages, and reset passwords if they may have been exposed.
Sources: Election interlopers register 5K+ domains, hope to catch some voting phish
Kaspersky says previously unknown hacking group spent nearly two years phishing Russian maritime universities, diplomats and energy organizations
A previously unknown hacking group quietly targeted Russian maritime schools, diplomatic missions, energy facilities, government agencies and financial institutions for nearly two years. Kaspersky says the campaign dates back to at least 2024 and used phishing emails with ZIP attachments containing a malicious file disguised as a Microsoft Excel configuration file; recent attacks starting in January 2026 used the Ravage post-compromise framework from GitHub to run commands, move files and capture screenshots. The company did not name the group, provide victim totals, or attribute the activity to a known state or criminal actor. — This is a sustained espionage-style campaign against sensitive Russian sectors, showing that simple phishing attachments are still effective and that publicly available offensive tools are being folded into real operations. Organizations in similar sectors should review email defenses, hunt for Ravage-related activity, and investigate suspicious Excel-launched processes and dormant compromises.
Sources: Unknown hacker group targeted Russian maritime universities, diplomats for nearly two years
Suspected Pakistan-linked SideCopy phishing campaign targets Afghanistan finance officials with XenoRAT malware
Afghan Ministry of Finance and provincial government officials were targeted in a phishing campaign that installed remote-access malware on victims' computers. Seqrite attributed the activity with medium-to-high confidence to the Pakistan-linked SideCopy group, which used Pashto-language lure documents inside ZIP archives and delivered them through compromised Afghan government server infrastructure; opening the file installed XenoRAT, a remote access trojan, which then contacted attacker-controlled servers in Europe. — This matters because it shows a suspected state-linked espionage operation aimed at government financial and provincial officials, using trusted local-language lures and compromised government infrastructure to improve success. Afghan public-sector defenders should investigate suspicious ZIP attachments, review access to government-hosted domains, and hunt for XenoRAT-related activity.
Sources: Afghan finance officials targeted by suspected Pakistani cyberespionage campaign
Attackers abuse ChatGPT share links and Google ads to deliver malware through fake OpenAI outage pages
Attackers are using legitimate ChatGPT share links to show fake OpenAI outage notices that tell people to download a bogus ChatGPT desktop app. Push Security says the LLMShare campaign buys Google ads for ChatGPT searches, serves the lure from chatgpt.com/s/ pages rendered with custom HTML and CSS inside ChatGPT, then redirects victims to openew[.]app, which offers cloaked Windows and macOS malware downloads; the Windows sample checks whether it is running on a real device or a virtual machine. — This matters because the scam is hosted partly on a real OpenAI domain, making it more convincing to ordinary users and harder for defenders to spot. Users should avoid sponsored results for AI tools, download apps only from the official vendor site or app store, and security teams should monitor for chatgpt.com share-link abuse and block the impersonation domain.
Sources: ChatGPT share links abused to host fake outage pages to deliver malware
Charter confirms breach after ShinyHunters claims it stole customer data through a vishing attack
Charter Communications says it suffered a security incident after the ShinyHunters extortion group threatened to leak stolen data. The attackers claim they breached Charter on April 1 by using voice phishing (vishing) to compromise an employee's Microsoft Entra account, then used access to Charter's Salesforce environment to export about 40 million customer records, including names, contact details, plan information, support tickets, and some customer proprietary network information (CPNI); Charter disputes that sensitive personal data or CPNI was exfiltrated. — Charter serves tens of millions of customers, so even partial account and service data exposure could create follow-on phishing, fraud, and impersonation risks. Affected users should watch for targeted calls and emails referencing Spectrum or account details, while defenders should review identity-provider protections, help-desk verification, and Salesforce access logs.
Sources: Charter confirms data breach after ShinyHunters extortion threat, Charter Communications data breach affects 4.9 million accounts, ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak (+1 more)
Researcher says ChatGPT web-page summaries can be prompt-injected to show phishing links and fake security alerts
A researcher says ChatGPT can be tricked into turning a malicious web page into a phishing message when a user asks it to summarize that page. Permiso's Andi Ahmeti reported that hidden Markdown instructions in attacker-controlled content can make ChatGPT include fake account alerts, attacker links, or QR codes in its response; OpenAI did not confirm a fix, and no CVE is cited in the report. — People using ChatGPT to summarize websites could be shown convincing phishing prompts in the assistant's own voice, including links or QR codes that bypass normal browser safety habits. Until OpenAI confirms a fix, users and defenders should treat AI-generated summaries of untrusted pages as potentially tainted and avoid clicking embedded links or scanning QR codes.
Sources: ChatGPT blindly trusts browser content, turning the page into a payload
WithSecure links new Russia-aligned GreyVibe campaign to phishing and malware attacks on Ukrainian targets
Researchers say a previously undocumented Russia-linked group called GreyVibe has targeted Ukrainian military, government, civilian, and business organizations since August 2025. WithSecure says the actor used at least six spear-phishing campaigns, fake adult-club websites, Telegram and dating-site lures, and file-sharing links to deliver PhantomRelay and LegionRelay malware on Windows and Fallspy on Android; the report also says the group used ChatGPT, Gemini, Ideogram, and other generative artificial intelligence tools across lure creation, malware development, obfuscation, and post-compromise tooling. — This matters because it describes an active espionage-focused campaign against Ukrainian targets and shows how lower-sophistication operators can use generative artificial intelligence to scale convincing phishing and malware operations. Organizations supporting Ukraine should review indicators, harden email and mobile defenses, and warn users about archive-based lures, fake personas, and links delivered over chat and dating platforms.
Sources: Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks, GreyVibe hackers use ChatGPT, Gemini to power cyberattacks, Russia-linked threat group put ChatGPT to work from lure to payload
ESET warns BTMOB Android malware sold as a kit can steal data and remotely control infected phones
A newly highlighted Android malware family called BTMOB can give criminals broad control over infected phones, including stealing data and taking over the device. ESET says the remote access trojan (RAT) is spread through phishing pages and fake app stores, abuses Android Accessibility Services to gain elevated privileges, and is sold with an APK-building kit that lets buyers customize lures by country and brand. The campaign has mainly been observed in Latin America. — This is more serious than a typical banking trojan because it can turn an Android phone into a remotely controlled spying and theft tool. Android users should avoid app downloads from links in messages or fake stores, and defenders should watch for phishing infrastructure and abuse of Accessibility permissions.
Sources: New BTMOB Android Malware Enables Full Device Takeover, BTMOB Android malware service generates custom phishing payloads
Carnival confirms ShinyHunters-linked data breach affecting nearly 6 million cruise customers
Carnival Corporation says attackers stole customer data after socially engineering an employee and accessing part of its IT systems, affecting 5,995,277 people. The company says the intrusion was identified on April 14, 2026 and data theft was confirmed on April 22; ShinyHunters had claimed the breach in April and said it stole millions of records. Exposed data reportedly includes names, dates of birth, email addresses, gender, location, and loyalty-program details tied to Holland America's Mariner Society. — This is a major consumer data breach involving sensitive personal information that could fuel phishing, impersonation, and account-targeting scams. Affected customers should watch for breach notices, be cautious of unsolicited calls or emails referencing cruises or loyalty programs, and change passwords anywhere they were reused.
Sources: Carnival Cruise confirms data breach affecting nearly 6 million people, Carnival confirms ShinyHunters cruised off with 6M customer records after April breach, Carnival Data Breach Exposed 6 Million People (+1 more)
Iran-linked Nimbus Manticore targets aviation and software companies with new MiniFast backdoor and fake job lures
An Iran-linked hacking group is using fake job offers and trojanized software downloads to break into aviation and software companies, including targets in Saudi Arabia, Australia, and the United States. Check Point says Nimbus Manticore (also known as Bohrium, TA455, and UNC1549) switched from DLL sideloading to AppDomain hijacking, using malicious .NET configuration files to load payloads, and deployed updated MiniJunk malware plus a new Windows DLL backdoor called MiniFast through ZIP files on OnlyOffice, a fake Zoom installer, and a fake SQL Developer site boosted with search-engine optimization. — This campaign shows continued state-linked targeting of sensitive industries during heightened regional tensions, with lures that can fool both job seekers and employees downloading familiar tools. Organizations in aviation, defense-adjacent, and software sectors should warn staff about recruiter and installer lures, review detections for MiniJunk and MiniFast, and hunt for suspicious .config-based AppDomain hijacking activity.
Sources: Iranian APT Targets Aviation, Software Companies With Updated Tools
Attackers exploit Ghost CMS SQL injection flaw CVE-2026-26980 to booby-trap hundreds of websites with ClickFix malware lures
Attackers are using a Ghost CMS bug to hijack websites and show visitors fake verification prompts that can infect their computers. The campaign abuses CVE-2026-26980, a critical unauthenticated SQL injection flaw affecting Ghost 3.24.0 through 6.19.0, to steal admin API keys and inject malicious JavaScript into article pages; researchers say more than 700 domains were hit, including university, media, fintech, and tech sites. Victims who follow the ClickFix instructions paste commands into Windows that download malware. — This affects both website owners and ordinary visitors: unpatched Ghost sites can be silently turned into malware delivery pages, and people browsing them can be tricked into infecting their own systems. Ghost administrators should update to 6.19.1 or later immediately, rotate exposed keys, and check for injected scripts and suspicious admin API activity.
Sources: Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign, Ghost CMS Vulnerability Exploited to Hack Over 700 Websites
Former C.A. Cloud executives plead guilty to helping tech-support scam networks route and hide fraudulent calls
Two former executives of call-tracking firm C.A. Cloud pleaded guilty to concealing a years-long tech-support scam operation that targeted victims worldwide. Prosecutors say the company knowingly provided phone numbers, call forwarding, recordings, and rotating number pools to fraudsters behind fake malware-warning pop-ups, including scammers impersonating Microsoft and Apple; the pair also allegedly ran a Tunisia call center where employees carried out similar fraud through remote computer access and false invoices. — This matters because it shows the infrastructure behind tech-support scams is being targeted, not just the callers themselves, and the scams often hit older and vulnerable people. Users should be wary of pop-ups or calls claiming their computer is infected, especially if they demand remote access or immediate payment.
Sources: Former US execs plead guilty to aiding tech support scammers
Ofcom says Snapchat, Meta and Roblox will change UK child-safety features, while TikTok and YouTube resist new commitments
Britain’s online-safety regulator said several major platforms have promised product changes aimed at better protecting children in the UK. Ofcom said Snap will adopt its recommended anti-grooming measures, including tighter limits on adult contact with children; Roblox will let parents disable direct messages for under-16s; and Meta will hide teens’ connection lists by default on Instagram and use artificial intelligence to detect likely sexualized adult-teen direct messages. Ofcom said TikTok and YouTube did not commit to significant new changes. — This matters to UK families, teens and platform operators because it signals concrete safety and privacy changes tied to regulatory pressure, especially around grooming risks and minors’ visibility online. Users and parents should watch for new default settings and controls, while companies should expect closer enforcement under the UK’s online-safety regime.
Sources: Tech giants promise British regulator they will tweak platforms to protect kids online
Two Americans plead guilty to helping India-based tech-support scam call centers target U.S. victims
Two U.S. men pleaded guilty to helping India-based tech-support scam centers steal millions from Americans, including elderly and disabled victims. Prosecutors said they provided phone numbers, call routing, tracking, and forwarding services for fake malware pop-up scams from 2016 to 2022, continued after learning customers were fraudulent, and advised scammers to rotate large pools of numbers to evade detection; some victims also gave remote access to their devices, leading to financial theft. — This shows how large tech-support scam operations rely on telecom and call-routing support inside the U.S., not just overseas call centers. People should be wary of pop-ups telling them to call for urgent computer help, and providers and defenders can use the case details to spot number rotation and call-forwarding tactics tied to fraud.
Sources: Two Americans plead guilty to assisting India-based tech support scam centers