social engineering

Agentic Browsers Rewind Web Security by 20 Years

Security researchers have uncovered a new class of vulnerabilities called “PleaseFix” in agentic browsers—tools that autonomously perform web tasks—which compromise fundamental browser security mechanisms like cross-origin restrictions. These flaws allow attackers to socially engineer zero-click attacks, resulting in account takeovers, browser escapes, and remote code execution. The findings highlight that recent agentic browsers have effectively reversed two decades of web security advances, exposing users and systems to significant risks.

https://www.darkreading.com/endpoint-security/agentic-browsers-rewind-web-security-20-years

Warning: Scammers Are Using FaceTime to Empty Bank Accounts

Scammers are exploiting FaceTime to conduct social engineering attacks, impersonating Apple Support or banks to trick users into revealing sensitive information or installing remote-access software, potentially leading to drained bank accounts. Apple urges users to avoid sharing personal data during unsolicited calls, keep devices updated, and report suspicious FaceTime calls to help mitigate these threats.

https://www.malwarebytes.com/blog/news/2026/07/warning-scammers-are-using-facetime-to-empty-bank-accounts

Entra Passkey Enrollment Vishing Targets Microsoft 365 Users

A threat actor tracked as O-UNC-066 has been conducting vishing campaigns targeting Microsoft 365 users across multiple industries by impersonating Microsoft Entra passkey enrollment processes. Attackers use phishing sites mimicking legitimate enrollment portals to trick victims into registering passkeys controlled by the attacker, enabling account takeover and data theft from SharePoint and OneDrive. The extortion group Pink, associated with this campaign, exfiltrates stolen data and pressures victims for ransom payments.

https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/

‘Deepfake as a Service’ Sees 39% Spike in Dark Web Conversations — and Experts Fear It Will Fuel the Next Wave of “Fake Boss” Scams

Discussions about “deepfake as a service” have surged by 39% on dark web forums, raising concerns among experts that this trend could intensify “fake boss” scams, where attackers impersonate executives to deceive employees. The rise of easily accessible deepfake technology lowers barriers for cybercriminals to conduct sophisticated social engineering attacks. Experts warn that this development may lead to more convincing and frequent fraud attempts targeting organizations.

https://www.techradar.com/pro/security/deepfake-as-a-service-sees-39-percent-spike-in-dark-web-conversations-and-experts-fear-it-will-fuel-the-next-wave-of-fake-boss-scams

A Backdoor in a LinkedIn Job Offer

A LinkedIn message from a recruiter at a crypto startup led Roman Imankulov to analyze a suspicious GitHub repo purportedly needing a Node modules review. The repo contained a hidden backdoor in a test file that executed arbitrary code fetched from a remote server whenever dependencies were installed, triggered by an npm lifecycle script. The repo and recruiter used stolen identities, highlighting the risk of supply-chain and social engineering attacks via seemingly legitimate job offers.

https://roman.pt/posts/linkedin-backdoor/

Scam Compounds Hiring “AI Models” to Seal the Deal in Deepfake Video Calls

Scam compounds in Southeast Asia are increasingly employing so-called “AI models”—real individuals who use deepfake technology during live video calls to charm victims and seal scams involving romance and cryptocurrency investments. These scam operations exploit trafficked individuals forced to work as chat operators and now use AI models with altered appearances to convincingly impersonate characters in video chats, significantly enhancing the scale and effectiveness of fraud. The growth of these scams is linked to regional instability, and the advancing deepfake technology is making it progressively harder to detect such deceptive calls.

https://www.malwarebytes.com/blog/news/2026/03/scam-compounds-hiring-ai-models-to-seal-deal-in-deepfake-video-calls

The Company Paid to Protect Your Identity Just Got Hacked

Aura, a major U.S. identity protection company serving over a million customers, suffered a data breach after an employee fell victim to a phone phishing attack, allowing hackers to access and steal around 900,000 records within an hour. The stolen data, primarily names and contact details, was released online by the hacking group ShinyHunters after Aura declined to pay a ransom, highlighting the risks of social engineering even for firms specializing in security.

https://gizmodo.com/the-company-paid-to-protect-your-identity-just-got-hacked-2000735410

Hackers Target Cybersecurity Firm Outpost24 in 7-Stage Phish

Security firm Outpost24 recently thwarted a sophisticated phishing attack targeting a C-level executive that used a complex seven-stage redirect chain involving trusted brands like Cisco and JP Morgan. The attackers employed legitimate services and expired domains to bypass email security, ultimately leading to a Microsoft Office credential phishing page, highlighting the increasing use of layered, evasive phishing tactics even against cybersecurity providers. This incident underscores the need for layered defenses and zero-trust principles, as compromising vendor credentials can grant attackers trusted access to multiple organizations.

https://www.darkreading.com/threat-intelligence/hackers-target-cybersecurity-firm-outpost24-phish

Hackers Target Microsoft Entra Accounts in Device Code Vishing Attacks

Hackers are targeting Microsoft Entra accounts using device code phishing and voice vishing, compromising accounts through legitimate Microsoft OAuth flows without needing traditional phishing methods. This allows attackers to gain valid authentication tokens and access victims' accounts, enabling corporate data theft. The ShinyHunters gang is suspected to be behind these attacks, with recommendations for organizations to monitor OAuth apps, revoke suspicious consents, and consider disabling device code flows when unnecessary.

https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/

How Global Cybercrime Syndicates Are Stealing Hearts — and Billions

Global cybercrime syndicates are exploiting romance scams, using AI to create convincing online identities to deceive victims, particularly during Valentine's season. In 2024, Americans lost over $16 billion to cybercrime, with one in seven adults affected by romance schemes. These scams, targeting older demographics, leverage trust and urgency to manipulate victims, often moving conversations off safer platforms. Law enforcement faces challenges due to the international nature of these operations, but agencies like the FBI are forming global partnerships to combat them. Vigilance is necessary for online daters, as pressure tactics are common indicators of scams.

https://www.politico.com/news/2026/02/14/how-global-cybercrime-syndicates-are-stealing-hearts-and-billions-00780481

Apple Pay Phish Uses Fake Support Calls to Steal Payment Details

Apple Pay phishing campaign hijacks user information through fake support calls. Victims receive emails mimicking Apple alerts about unauthorized transactions, prompting them to call provided numbers. Scammers impersonate Apple agents, extracting sensitive data like Apple ID verification codes and payment details under false pretenses. Users are advised to avoid sharing 2FA codes, scrutinize sender addresses, and verify communications independently.

https://www.malwarebytes.com/blog/news/2026/02/apple-pay-phish-uses-fake-support-calls-to-steal-payment-details

Are Criminal Hacking Organizations Recruiting Teenagers to Do the Dirty Work?

Criminal hacking organizations are recruiting teenagers in Western countries by offering fake jobs and cryptocurrency payments. These groups use social media and gaming platforms to groom young individuals for illegal activities, including ransomware attacks. Parents should watch for signs of unusual income or expensive items and be aware that law enforcement, including the FBI, is actively prosecuting young offenders.

https://www.pandasecurity.com/en/mediacenter/are-criminal-hacking-organizations-recruiting-teenagers-to-do-the-dirty-work/

The Biggest Catch: How Whaling Attacks Target Top Executives

Whaling attacks target senior executives, exploiting their time constraints, online visibility, and access to sensitive information. Attackers often use phishing tactics, enabling them to execute large financial frauds. AI enhances these threats by facilitating data gathering and creating convincing communication. Mitigation strategies include personalized training, strong approval processes for fund transfers, and robust email security measures. Protecting against whaling not only safeguards financial assets but also corporate reputations.

https://www.welivesecurity.com/en/business-security/big-catch-how-whaling-attacks-target-top-executives/

Impersonation as a Service’ Next Big Thing in Cybercrime

Cybercrime is evolving with “impersonation-as-a-service,” where criminals hire English-speaking social engineers on underground forums. Job ads for these skills doubled from 2024 to 2025, indicating a rise in social engineering attacks. Criminals combine social engineering with ransomware, leveraging AI and collaboration for more sophisticated operations. Examples include Scattered Spider and ShinyHunters targeting organizations like Dior and Google through voice-phishing to access credentials. The trend reflects increased tactics seen in nation-state cyber attacks, indicating a troubling future for digital security.

https://www.theregister.com/2025/08/21/impersonation_as_a_service/

Scroll to Top