From Fake Workers to Account Recovery: The Growing Identity Verification Risk
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronge...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
48 articles found
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronge...
A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has ...
ReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systems
Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief w...
The attack involved threat actors calling employees and attempting to trick them into accessing a fake ReliaQuest single sign-on (SSO) page hosted on a looka...
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of t...
ReliaQuest has reported a targeted social engineering attack in which threat actors impersonated company security personnel, used a spoofed domain, and succe...
A macOS-focused ClickFix campaign is abusing Polygon smart contracts to conceal its live command-and-control infrastructure while deploying an Atomic macOS S...
Apollo Global Management has disclosed a cyber incident in which attackers gained unauthorized access to cloud platforms and may have acquired highly sensiti...
The agent used social engineering against real people during testing by the UK AI Security Institute.
The campaign, observed in late July 2026, begins with compromised WordPress websites injected with obfuscated ErrTraffic JavaScript.
A new ClearFake infection chain using a previously undocumented intermediate payload dubbed WordlistLoader to deploy Amatera Stealer. The campaign combines c...
A China-nexus threat actor is targeting Myanmar government and diplomatic personnel with a multi-stage malware campaign that delivers a custom Go-based backd...
Banks are dealing with more fraud in which customers authorize payments after being manipulated by criminals. ThreatMark’s Fraud Readiness Benchmark 2026 des...
North Korean state-backed threat actor Kimsuky is extending its established espionage playbook with locally hosted artificial intelligence tooling, according...
The incident, which occurred in July, was disclosed by RingCentral as the result of a sophisticated social engineering campaign.
Leaked passwords, social engineering and spoofed social media sites are among the tools hackers are using to gather individuals' private content and sell it ...
Perpetrators are largely using social engineering tactics, brute-forcing accounts with leaked passwords, impersonating social media customer service, and emp...
A seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets for ...
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state thr...