
Phishing Link Could Plant a Rogue ChatGPT Agent
Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…
The article describes multiple real-world suspected social engineering attempts that begin with friendly LinkedIn messages and quickly move to an off-platform meeting invite (often via Calendly). On the video call, the attacker refuses to turn on camera, uses a personal email address, asks the target to share their screen, and ultimately appears to aim at sending fraudulent links that push the victim to install software or run code.
This attack breakdown describes a pattern observed across four suspected social engineering attempts, all starting with a friendly LinkedIn message. The conversation feels professional and legitimate at first, which lowers the target's guard. From there, the attacker moves quickly to schedule a meeting, often using a scheduling platform such as Calendly, shifting the interaction off LinkedIn and into a video call.
Once on the call, several suspicious behaviors emerge. The caller frequently refuses to turn on their camera, claiming unspecified technical issues. Communication often comes from a personal email address, such as Gmail, rather than a corporate domain. The attacker then asks the target to share their screen, but when asked to reciprocate, they decline, again citing technical problems. The suspected end goal is to direct the victim to fraudulent websites and encourage them to install code or software.
The approach works because it exploits trust built through a familiar platform. LinkedIn is widely used for legitimate professional networking, so an incoming message does not immediately trigger suspicion. Excessive praise and flattery during the conversation can further disarm the target before the request to move off-platform is made. By the time screen sharing or a link is requested, the target has already invested time in what feels like a normal business interaction.
When one target confronted the caller about a suspicious website, the caller ended the meeting immediately, a behavior worth noting as a possible confirmation signal.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It begins with a seemingly legitimate professional conversation on LinkedIn that transitions off-platform, often through a Calendly meeting invitation.
The attacker typically refuses to turn on their camera citing technical issues, communicates from a personal email like Gmail instead of a corporate domain, and asks the target to share their screen.
The suspected end goal is to send the victim fraudulent website links and encourage them to install code or software.
The author reported being made aware of four cases of suspected social engineering attempts initiated through LinkedIn messaging.
Over just two weeks, four people here got the same sketchy pattern from LinkedIn “leads.” It starts as a normal LinkedIn chat, then they rush you to a Calendly link, and suddenly you’re on a video call with a blank screen and a Gmail address asking you to share your screen. The playbook: get your screen, drop a link to a fake website, then pressure you to install software or run code. One target called out the site as fraudulent, the caller hung up instantly. Your move: if a new LinkedIn contact pushes you to a call and asks you to share your screen, stop and end the meeting, then report it to security.

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

Researchers report a real North Korea–linked social engineering campaign where attackers posed as recruiters and sent fake job offers and coding assessments.…

A legal-sector threat intel report says adversary-in-the-middle (AiTM) phishing is now the most common way attackers gain initial access to law firms, because…

A North Korea-linked group is running fake recruitment campaigns to trick people into taking “online assessments” for jobs that don’t exist. The goal is to…

Researchers documented a real phishing operation that used Telegram “secret chats” to send fake security warnings to specific people, including an exiled…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…