Recent Technology Cyber Attacks

Attacks targeting software companies, SaaS platforms, and internet services, including the vendor impersonations aimed at their customers. Each entry is broken down with an original video explainer, key findings, and the red flags your team should watch for. How we produce these.

DPRK Poses as Recruiters to Malware IT Pros

DPRK Poses as Recruiters to Malware IT Pros

Australian and allied agencies warned that North Korean-linked actors are impersonating recruiters and fake AI/crypto/NFT companies to lure IT professionals into a hiring process that installs malware. The goal is to steal sensitive information and drain cryptocurrency wallets, with reporting…

September 22, 2026
Fake AI Recruiters Hit 30K Devices Worldwide

Fake AI Recruiters Hit 30K Devices Worldwide

A weekly threat bulletin highlights a North Korea–linked campaign where attackers posed as AI or blockchain employers to trick IT professionals into getting infected and losing cryptocurrency. It also notes a phishing kit that abuses Microsoft’s legitimate device login flow to gain long-lasting…

September 22, 2026
Fake LastPass Download on GitHub Drops Stealer

Fake LastPass Download on GitHub Drops Stealer

Researchers found attackers impersonating LastPass with a fake GitHub “LastPass Authenticator” download page that tricks people into downloading a large ZIP and running a fake installer. The installer uses a Microsoft-signed Windows driver to shut down antivirus/EDR tools, then runs a password…

September 21, 2026
“Contagious Interview” Job Scam Hits 30K Devices

“Contagious Interview” Job Scam Hits 30K Devices

A North Korea-linked operation known as “Contagious Interview” posed as recruiters and employers to lure developers into completing “job assessments” or “coding tests,” which led to malware infection. Investigators say at least 30,000 devices were compromised across 100+ countries, and…

September 21, 2026
Fake AI Subscription Sites Push $2,000 Plans

Fake AI Subscription Sites Push $2,000 Plans

Researchers found a network of 100+ polished look‑alike subscription websites that impersonate real products (and invent new ones) to sell expensive “AI” plans. The sites rely on professional landing pages and a real Google sign-in flow to appear legitimate, then steer visitors into paid…

September 21, 2026
Fake LastPass App on GitHub Drops Rapuncel Stealer

Fake LastPass App on GitHub Drops Rapuncel Stealer

Attackers used fake “LastPass Authenticator” and fake macOS LastPass pages on GitHub to trick people into downloading a malicious installer. The campaign relied on SEO so the fraudulent GitHub page appeared near the top of search results, then redirected victims through multiple pages to a download…

September 21, 2026
Fake Cloudflare Check Tricks Users Into Running PowerShell

Fake Cloudflare Check Tricks Users Into Running PowerShell

Researchers observed real-world infections where compromised WordPress sites showed a fake “Cloudflare Turnstile” verification and instructed visitors to press Win+R and run a PowerShell command. The attacker’s page guides victims step-by-step (and reports progress back to the operator) to execute…

September 21, 2026
Google Doc “Fix” Trick Delivers Malware

Google Doc “Fix” Trick Delivers Malware

A real-world social engineering attempt used a legitimate Google Doc to trick a target into manually running commands that installed malware. The attacker posed as a crypto marketing executive and used a fake “decryption failure” message and a “manual update” button as the lure, leading to an…

September 21, 2026
Fake Job Video Calls Target Rust Developers

Fake Job Video Calls Target Rust Developers

The Rust project warned of an active social engineering campaign targeting Rust team members and popular crate maintainers. Attackers pose as recruiters or contractors, lure developers into video calls, then trick them into installing software or running pasted code to steal credentials and publish…

September 21, 2026
NK Fake Recruiters Trick Job Seekers Into Malware

NK Fake Recruiters Trick Job Seekers Into Malware

Authorities say a North Korean group posed as recruiters and ran fake technical interviews to convince job seekers to execute malicious code. The operation infected over 30,000 devices, led to thousands of compromised cryptocurrency wallets, and allegedly generated over $10 million for North Korea.

September 21, 2026
Fake Rust Job Interviews Push Malware on Devs

Fake Rust Job Interviews Push Malware on Devs

The Rust Project warned that attackers are approaching Rust contributors and crate maintainers with believable recruiter outreach and “company” profiles, then using interview video calls to trick targets into installing malware or running commands. The activity is described as similar to North…

September 21, 2026
ClickFix Lures Spread ChainScript RAT

ClickFix Lures Spread ChainScript RAT

Researchers describe real-world “ClickFix” social-engineering lures that trick people into installing malware by downloading fake apps (like Spotify/Zoom/Teams) or copying commands into Terminal. One campaign abused a compromised, verified HBO Max Reddit account to run malicious ads, while another…

September 21, 2026
Fake Job Interview Repo Tricks DevOps Into Malware

Fake Job Interview Repo Tricks DevOps Into Malware

North Korea–linked "Jade Sleet" used job interview-style coding projects to trick developers into running malicious infrastructure code. The lure involved GitHub repositories that contained a weaponized Terraform file, leading to downloads from attacker-controlled domains and installation of macOS…

September 21, 2026
Brevo Breach Spread Malware via ‘Prove You’re Human’

Brevo Breach Spread Malware via ‘Prove You’re Human’

Attackers breached Brevo and used a stolen Cloudflare API key to inject malicious code into Brevo-hosted scripts that thousands of customer websites load. Visitors saw a fake “prove you’re human” prompt meant to trick them into running a command, and logged-in WordPress admins risked having a…

September 18, 2026
Fake Recruiters Hit Job Seekers With Malware Files

Fake Recruiters Hit Job Seekers With Malware Files

An alleged North Korean operation called “WaterPlum” targeted job seekers by posing as AI and blockchain companies and using the interview process to trick applicants into downloading malicious files. Authorities say the campaign infected tens of thousands of devices worldwide and led to theft from…

September 18, 2026
Fake Job Interviews Backdoor 30,000 Devices

Fake Job Interviews Backdoor 30,000 Devices

An international advisory says North Korea–linked actors posing as recruiters tricked jobseekers into downloading “coding assignments” during fake interview processes. Opening the files installed backdoors and malware, enabling theft from over 7,000 crypto wallets and supporting at least $10.71M in…

September 18, 2026
Fake ChatGPT Invoice Email Steals Logins

Fake ChatGPT Invoice Email Steals Logins

Attackers are sending fake ChatGPT billing emails that pressure people to “update payment” within 48 hours to avoid service interruption. The message links to a convincing look‑alike ChatGPT login page via a Google redirect, aiming to steal OpenAI credentials.

September 18, 2026
Prompt Injection Steals Agent Vault Secrets

Prompt Injection Steals Agent Vault Secrets

Unit 42 showed that default AWS AgentCore Harness settings can let an attacker use prompt injection to trick an AI agent into running shell commands and exposing plaintext credentials from AgentCore Identity at runtime. In their demo, a malicious support ticket embedded instructions (via hidden…

September 18, 2026
Brevo Hack Served ClickFix Malware to 100K Sites

Brevo Hack Served ClickFix Malware to 100K Sites

Brevo suffered a supply-chain compromise where attackers injected malicious JavaScript into Brevo-hosted pages and customer-embedded website scripts, affecting over 100,000 sites. Visitors were shown a fake “Cloudflare, verify you are human” prompt designed to trick them into running a command on…

September 18, 2026
Handala Uses Fake “Support” Chats to Drop Malware

Handala Uses Fake “Support” Chats to Drop Malware

Researchers linked the Iran-aligned Handala Hack persona to a Telegram-controlled backdoor (HEAVYGRAM) that can steal passwords and exfiltrate chat data. The campaign reportedly starts with social engineering on messaging apps (Telegram, WhatsApp, Instagram), where the attacker pretends to offer…

September 18, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo