Recent Technology Cyber Attacks

Page 14 of 15
Fake CoD Points Giveaway Steals Accounts

Fake CoD Points Giveaway Steals Accounts

A phishing campaign targets Call of Duty Mobile players by promising free Call of Duty Points (CP). Victims are tricked into entering their email, password, and then their 2FA code on a fake site that impersonates an official promotion. The attackers use the captured credentials to take over…

July 24, 2026
Fake Cloudflare Prompt Tricks Claude Agents

Fake Cloudflare Prompt Tricks Claude Agents

A researcher demonstrated that a Claude web-browsing agent could be manipulated by a fake “Cloudflare authentication” warning on a malicious website. Once the agent followed the prompt loop and clicked links, it could be coaxed into revealing personal/owner details such as employer and hometown.…

July 24, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026
AgentForger Turns AI Agents Into Insider Threats

AgentForger Turns AI Agents Into Insider Threats

Zenity Labs described a real phishing-based technique (“AgentForger”) that could silently create an autonomous AI agent inside an OpenAI workspace after a single click. The planted agent can keep running on a schedule, read and act across connected tools like Outlook/Slack/Drive, and execute new…

July 24, 2026
Zimbra Email View Triggers Russian Data Theft

Zimbra Email View Triggers Russian Data Theft

Government agencies say a Russian-linked group sent specially crafted HTML emails that exploit a Zimbra webmail flaw, so simply viewing the message can trigger data theft, no click required. The campaign has targeted multiple Western sectors since July 2025 and focuses on stealing email content and…

July 23, 2026
Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026
One-Click Phish Could Spawn a Hidden AI Insider

One-Click Phish Could Spawn a Hidden AI Insider

Researchers disclosed a flaw in OpenAI ChatGPT Workspace Agents that could let an attacker trick an employee into creating an invisible, attacker-controlled “autonomous agent” inside the company. The attack depends on a phishing message that gets a logged-in user to click a weaponized URL, after…

July 23, 2026
Phishing Link Plants a Rogue ChatGPT “Insider”

Phishing Link Plants a Rogue ChatGPT “Insider”

Researchers say a one-click phishing link could trick ChatGPT into creating a malicious AI “agent” inside a company’s ChatGPT workspace. The agent could act using the employee’s existing access (Outlook, Teams, Slack, Google Drive, etc.), run on a schedule, and take instructions from attacker…

July 23, 2026
Deepfake Video Call Drove $25M Wire Transfer Scam

Deepfake Video Call Drove $25M Wire Transfer Scam

The article discusses Google’s new selfie-video account recovery, but it also highlights a real deepfake-enabled fraud case. In that incident, a finance employee joined a video call showing deepfake versions of coworkers and was persuaded to send multiple wire transfers, illustrating how realistic…

July 23, 2026
Hidden PR Prompts Trick Azure DevOps AI Agents

Hidden PR Prompts Trick Azure DevOps AI Agents

Researchers showed that hidden instructions in an Azure DevOps pull request description can trick an AI coding assistant into taking unintended actions using the reviewer’s own access. In a proof of concept, the AI agent was manipulated to pull confidential data from another project and post it…

July 22, 2026
Survey Call Led to SIM Swap Near-Takeover

Survey Call Led to SIM Swap Near-Takeover

An attacker called the victim pretending to be their mobile carrier, built trust with a “customer satisfaction survey,” then asked the victim to read back an SMS one-time passcode and a long-standing account passcode. The attacker had already initiated (and days earlier executed) a SIM swap, then…

July 22, 2026
Hidden PR Text Can Hijack Azure DevOps AI Reviews

Hidden PR Text Can Hijack Azure DevOps AI Reviews

Researchers showed that an attacker can hide instructions inside an Azure DevOps pull request description so an AI coding agent follows the attacker’s directions instead of the reviewer’s. Because the agent acts with the reviewer’s permissions, it can access other projects and leak sensitive…

July 22, 2026
Fake Teams “Update” Led to $630K Crypto Theft

Fake Teams “Update” Led to $630K Crypto Theft

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft Teams call link. After the call “had no working audio,” the victim approved what looked like a Teams update, which installed a malicious…

July 21, 2026
AI Agents Steered to Malware on Fake GitHub Repos

AI Agents Steered to Malware on Fake GitHub Repos

Researchers found thousands of malicious GitHub repositories designed to look like real developer tools, including hundreds posing as AI “Skills” and Model Context Protocol (MCP) servers. In a technique dubbed “AgentBaiting,” attackers rely on AI assistants to discover these repos and pass the…

July 21, 2026
Fake Google Ads “Sync” Alert Steals Credentials

Fake Google Ads “Sync” Alert Steals Credentials

Cofense observed a real phishing campaign impersonating Google Ads Sync Accounts (MMC) with a fake “maintenance/system upgrade” notice. The email pressures recipients to click “Complete Sync Account,” sending them through lookalike sites and a fake Google sign-in pop-up that captures credentials.…

July 21, 2026
ClickLock Stealer Freezes Macs for Passwords

ClickLock Stealer Freezes Macs for Passwords

Researchers found a new macOS infostealer, “ClickLock Stealer,” that uses ClickFix-style fake verification pages to trick people into running Terminal commands. After infection, it shows a realistic macOS password prompt and can effectively lock the Mac until the victim enters the correct password,…

July 21, 2026
Fake Support Techs Breach WINDTRE Retail Stores

Fake Support Techs Breach WINDTRE Retail Stores

Italy’s privacy regulator fined telecom operator WINDTRE after two breaches where attackers used simple social engineering, not hacking tools. The attackers posed as support technicians and talked retail store staff into giving them system access, leading to theft of customer data. The case shows…

July 21, 2026
Fake Web3 Job Interviews Push “ClickFix” Malware

Fake Web3 Job Interviews Push “ClickFix” Malware

Researchers say a North Korea-aligned group is targeting Web3 and crypto professionals with fake recruiter outreach and “mandatory” online skill tests. During the test, victims are tricked into copying a terminal command to “fix” a camera/mic error, which installs remote-access malware and can lead…

July 21, 2026
Fake Mexico ID Site Pushed WebDAV Malware

Fake Mexico ID Site Pushed WebDAV Malware

Researchers found an exposed malware delivery server that contained phishing lures, testing notes, and live delivery logs for an active campaign. The live operation targeted Windows users in Mexico using a fake government ID (CURP) lookup site that triggered a WebDAV-based download flow and…

July 20, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo