Recent Technology Cyber Attacks

Page 4 of 16
Hidden Prompts Hijack ChatGPT Connected Apps

Hidden Prompts Hijack ChatGPT Connected Apps

Check Point demonstrated a prompt-injection technique where a hidden instruction inside ChatGPT can make a user’s session quietly run extra tasks using the session’s existing permissions. In the proof of concept, the victim’s ChatGPT (with Gmail connected) pulled email data and relayed it to an…

September 9, 2026
Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
Hidden ChatGPT Channel Stole Gmail Data

Hidden ChatGPT Channel Stole Gmail Data

Check Point Research described a covert cross-account channel in OpenAI’s internal JFrog Artifactory that could let an attacker sneak hidden instructions into another user’s ChatGPT session. In their demonstration, the victim saw normal chatbot output while the model quietly pulled data (like Gmail…

September 8, 2026
Planted Prompt Silently Exfiltrates Gmail via ChatGPT

Planted Prompt Silently Exfiltrates Gmail via ChatGPT

Check Point Research demonstrated a prompt-injection technique where a hidden instruction planted in a ChatGPT conversation could make ChatGPT quietly read a user’s connected Gmail and pass the data to another attacker-controlled ChatGPT account. The user still received a normal-looking answer,…

September 8, 2026
Hidden ChatGPT Tasks Leak Data Across Accounts

Hidden ChatGPT Tasks Leak Data Across Accounts

Check Point researchers demonstrated a real proof-of-concept where a victim’s ChatGPT session could be tricked into running hidden, attacker-controlled tasks in parallel with the user’s normal request. In the demo, the attacker used a covert cross-account channel to make ChatGPT access the victim’s…

September 8, 2026
Meta Missed Hundreds of CSAM 'Nudify' Ads

Meta Missed Hundreds of CSAM 'Nudify' Ads

Researchers found hundreds of paid ads running across Meta platforms that promoted “nudification”/face‑swap apps and included abusive sexual content involving minors, including some using real children’s photos pulled from the web. The ads used manipulative marketing text (for example, claiming…

September 8, 2026
Fake Minecraft Sites Keep Spreading WeedHack

Fake Minecraft Sites Keep Spreading WeedHack

Attackers are tricking Minecraft players into downloading malware by cloning legitimate mod/client websites and manipulating search results so the malicious pages appear highly ranked. Even after the malware’s command-and-control systems were disrupted, the fake sites and trusted file-hosting links…

September 8, 2026
Kali365 OAuth Phish Bypasses Password Theft

Kali365 OAuth Phish Bypasses Password Theft

The article describes an FBI-warned phishing operation (Kali365) that tricks Microsoft 365 users into approving access via a real Microsoft device-code login flow, often without stealing a password. Victims are lured with document-sharing themed emails and prompted to enter a device code,…

September 8, 2026
BengalSEO Tricks Bing Users Into Malware & Scam Calls

BengalSEO Tricks Bing Users Into Malware & Scam Calls

Researchers uncovered a long-running “SEO poisoning” operation that manipulates Bing search results to push people onto fake support and activation pages. Victims are steered through a chain of redirects to either download a malware-laced ZIP (MayaBot) or be pressured into calling a fake…

September 8, 2026
Fake LinkedIn Tests and Job Interviews Push Malware

Fake LinkedIn Tests and Job Interviews Push Malware

This weekly threat bulletin includes real-world campaigns where attackers impersonate recruiters and use fake hiring steps to trick people into running malicious files. One campaign uses fake LinkedIn coding tests delivered via cloud links, and another uses fake job interviews with trojanized macOS…

September 7, 2026
REVSTEALER Lures Push Fake Cheats, Drop Miners

REVSTEALER Lures Push Fake Cheats, Drop Miners

Researchers tied several new programs to the REVSTEALER Windows info-stealer that can steal crypto wallet data, hijack clipboard crypto addresses, and even disable Windows Update and Microsoft Defender to run a crypto miner. Victims are primarily pulled in through “game-cheat” downloads promoted by…

September 6, 2026
Fake “Google Security” Calls Abuse Real Gmail Alerts

Fake “Google Security” Calls Abuse Real Gmail Alerts

A scammer called a Gmail user pretending to be Google’s security team and used real Google account-recovery emails to make the story believable. The attacker first triggered legitimate Google verification and security-alert messages, then tried to pressure the victim during the phone call into…

September 5, 2026
Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
X Users Hit by Password-Reset Email Flooding

X Users Hit by Password-Reset Email Flooding

X is investigating a wave of unsolicited password-reset emails and codes being sent to users, which may be attackers trying to take over accounts as X Money becomes more available. X says it has found no evidence of a breach or successful account takeovers so far, but warns the reset-email “flood”…

September 4, 2026
Half-Click OWA Emails Drop OWAReaper Implant

Half-Click OWA Emails Drop OWAReaper Implant

A Russia-linked group (TA488) abused a stored XSS flaw in on‑prem Microsoft Exchange Outlook Web Access (OWA) so that simply opening a specially crafted HTML email could run attacker JavaScript inside the victim’s logged-in webmail session. The campaign used business-themed subject lines and hid…

September 4, 2026
X Users Hit by Password Reset Email Flood

X Users Hit by Password Reset Email Flood

Users reported getting repeated, unsolicited password-reset emails from X after the launch of X Money. The emails appear legitimate, but attackers may be using them to confuse users and then send follow-up phishing messages that lead to fake X login pages to steal credentials. There is no confirmed…

September 3, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake Streaming Ads Push StreamRat Android Trojan

Fake Streaming Ads Push StreamRat Android Trojan

Researchers found a real malicious ad campaign on Meta platforms (and reused on TikTok) that pushed a fake “free TV streaming” service to Spanish-speaking users, mainly in Spain. Clicking the ad led to a tailored website that coached Android users through installing an app from outside Google Play,…

September 3, 2026
RMM Phish Uses Tax & UPS Lures in 46 Countries

RMM Phish Uses Tax & UPS Lures in 46 Countries

Researchers describe a real phishing operation that tricks people into installing legitimate remote monitoring and management (RMM) tools so attackers can remotely control devices. The campaign uses familiar-looking documents (tax forms, UPS/shipping notices, Adobe PDFs, invoices, and Social…

September 3, 2026
Fake Download Sites Push Trojanized Installers

Fake Download Sites Push Trojanized Installers

Microsoft reports a real campaign where attackers set up look-alike software download websites (impersonating known brands) to trick employees into installing trojanized “installers.” Once run, the malware persists on the device, weakens security settings, and connects to attacker-controlled…

September 3, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo