Tag Archives: Social engineering
Signal Linked Devices: Security Audit and 2026 Mitigation Guide
Recent espionage campaigns have targeted Signal Linked Devices to bypass encryption through social engineering. Perform a manual security audit today to secure your private messages and digital arsenal from unauthorized access. Continue reading
CalPhishing Campaign: Hijacking M365 via Outlook Calendar Invites
Security researchers have identified the CalPhishing campaign, a new threat using Outlook calendar invites and the EvilTokens kit to bypass MFA and hijack accounts. Continue reading
ClickFix macOS Campaign Exploits AI Lures to Deploy Infostealers
A sophisticated ClickFix macOS campaign has been identified using sponsored AI-themed search results and shared chat interfaces to trick users into installing the MacSync infostealer. Continue reading
Canvas LMS Attacks: ShinyHunters Escalates Campaign with Personalized Phishing
New reports reveal that Canvas LMS attacks have escalated to include sophisticated phishing and portal defacements, targeting students and faculty through stolen institutional data. Continue reading
MuddyWater Social Engineering: Teams and MFA Manipulation Tactics
A recent report details a MuddyWater social engineering campaign that leverages Microsoft Teams and MFA manipulation to bypass security controls using false flag tactics. Continue reading
MuddyWater APT Uses Microsoft Teams for False-Flag Ransomware Attacks
Cybersecurity researchers have revealed a new campaign where the MuddyWater APT leverages Microsoft Teams and social engineering to deploy Chaos ransomware as a cover for state-sponsored espionage. Continue reading
AccountDumpling Phishing Operation Hijacks 30,000 Facebook Accounts
The AccountDumpling phishing operation exploits Google AppSheet infrastructure to bypass security filters and compromise thousands of Facebook Business accounts globally. Continue reading
AI Repository Security: Social Engineering Attacks Targeting Developers
A major security alert warns of a surge in social engineering attacks on Hugging Face and ClawHub, highlighting the critical need for robust AI repository security measures. Continue reading
KRYBIT Data Leak Site: New Double Extortion Risks and Metrics
Cyfirma researchers report the emergence of the KRYBIT Data Leak Site, which utilizes a double extortion model and maintains a rapid 2.7-day delay between compromise and leak. Continue reading