Recent Technology Cyber Attacks

Attacks targeting software companies, SaaS platforms, and internet services, including the vendor impersonations aimed at their customers. Each entry is broken down with an original video explainer, key findings, and the red flags your team should watch for. How we produce these.

Fake Recruiters Push Malware Git Repos

Fake Recruiters Push Malware Git Repos

The article describes real-world scams where attackers pose as recruiters on LinkedIn and send developers “take-home assessment” code repositories that contain hidden malware triggers. Simply cloning and opening the project in an IDE or coding agent can execute malicious hooks/configs that download…

September 3, 2026
Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
Stolen API Key Ran Up $600K AI Usage at METR

Stolen API Key Ran Up $600K AI Usage at METR

AI research non-profit METR disclosed two real security incidents. In one, attackers got access to an exposed system and used an AI agent to reveal an API key, then burned through about $600,000 in AI credits over weeks. In a separate incident, METR observed systematic probing of its public…

September 2, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Fake Freelancer Accounts Pushed Malicious Excel Macros

Fake Freelancer Accounts Pushed Malicious Excel Macros

U.S. prosecutors say a Russian national used hundreds of fake accounts on a freelance platform to send Excel files that tricked users into enabling macros, which then downloaded remote-control malware. The campaign targeted tens of thousands of users and led to thousands of infections, enabling…

September 2, 2026
Scareware Google Ads Keep Running After Reports

Scareware Google Ads Keep Running After Reports

University researchers found large numbers of deceptive “software” ads (including scareware) running through Google’s ad system, generating over 100 million impressions in Europe. They reported some ads via Google’s “Report this ad” flow, but several ads were acknowledged as policy violations and…

September 2, 2026
Fake Download Sites Push Malware Installers

Fake Download Sites Push Malware Installers

Microsoft reports an active campaign where attackers set up counterfeit software download pages that mimic well-known brands and trick users into installing malware. Victims visit a look-alike vendor site, click “Download now,” then run a bundled installer that drops persistent malware and connects…

September 2, 2026
Fake IT Support Drives Pix Fraud in Brazil

Fake IT Support Drives Pix Fraud in Brazil

A financially motivated group called Breeze Comet targeted Brazilian financial and retail organizations by impersonating IT support and convincing staff to install remote-access tools. After gaining access, the attackers moved into internal payment systems (like Pix/STR/Boleto) and executed…

September 1, 2026
BengalSEO: Search Lures to Malware & Scam Calls

BengalSEO: Search Lures to Malware & Scam Calls

Investigators described a real, long-running SEO poisoning operation (“BengalSEO”) that manipulates search results to push victims to fake support and activation pages. The pages impersonate well-known consumer brands, then route visitors through redirects and CAPTCHA checks to either download…

September 1, 2026
Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
Fake Recruiters Lure Devs Into Malware “Coding Tests”

Fake Recruiters Lure Devs Into Malware “Coding Tests”

An Iran-linked espionage group contacted developers and other tech specialists with fake job offers on LinkedIn and similar platforms. Victims were pushed to quickly download and run “coding challenges” that secretly installed new malware, giving attackers remote access and long-term persistence.…

September 1, 2026
Fake “Claude Opus 5” GitHub Drops RevStealer

Fake “Claude Opus 5” GitHub Drops RevStealer

A malicious GitHub repository impersonating Anthropic advertised a “free” Claude Opus 5 desktop app and tricked users into downloading a ZIP that silently installed RevStealer. Victims reported account takeovers after running it, and the malware is designed to steal passwords, crypto wallet data,…

September 1, 2026
McKesson Hit via Vishing to Okta Accounts

McKesson Hit via Vishing to Okta Accounts

McKesson confirmed a cyber incident after the ShinyHunters extortion group claimed it stole roughly 284 million patient-related records. The attacker claims the initial access came from phone-based social engineering (vishing) against employees to compromise Okta single sign-on accounts, then pivot…

September 1, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
DPRK Fake Hires Spread to Healthcare & Sales

DPRK Fake Hires Spread to Healthcare & Sales

Investigations found suspected North Korean operatives getting hired into real companies by impersonating other people, including roles outside IT such as healthcare and sales/marketing. The workflow relies on fake or stolen identity documents, remote-access tooling, and deception during interviews…

August 31, 2026
Mirage2FA Phishing Kit Steals Microsoft 365 Sessions

Mirage2FA Phishing Kit Steals Microsoft 365 Sessions

A phishing-as-a-service toolkit called Mirage2FA has been targeting organizations by abusing real Microsoft 365 login pages through a man-in-the-middle proxy. The attackers capture usernames, passwords, and live two-factor authentication codes, then take over the user’s session using stolen session…

August 31, 2026
Smart TV Apps Turn Homes Into DDoS Proxies

Smart TV Apps Turn Homes Into DDoS Proxies

Researchers describe how some smart TV apps bundle “residential proxy” relay kits that users unknowingly approve via a consent screen. The same always-on home devices can then be repurposed (“flipped”) from commercial web scraping into DDoS traffic, contributing to a sharp rise in devices seen in…

August 30, 2026
Scammers Lure Victims onto Microsoft Teams

Scammers Lure Victims onto Microsoft Teams

Victims in China reported losing thousands to hundreds of thousands of dollars after scammers convinced them to move conversations onto Microsoft Teams using login credentials the scammers provided. Common setups included romance and “investment” pitches (including crypto) and official-sounding law…

August 28, 2026
Fake SSO + MFA Push Used in Real Breaches

Fake SSO + MFA Push Used in Real Breaches

This weekly roundup includes two real social-engineering-driven incidents. Attackers used social engineering to access Apollo Global Management’s cloud platforms and steal sensitive personal data, and separately attempted a ShinyHunters phishing attack against ReliaQuest using a fake SSO login page…

August 28, 2026
AI Agents Tricked Into Installing Malware via llms.txt

AI Agents Tricked Into Installing Malware via llms.txt

Researchers observed AI coding agents inside corporate networks following instructions hidden in websites’ llms.txt files, including installing packages that didn’t exist yet. Attackers (or the researchers demonstrating the risk) could then register those package names and have the agents install…

August 28, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo