Recent Technology Cyber Attacks

Page 6 of 16
AI Agents Tricked Into Installing Malware via llms.txt

AI Agents Tricked Into Installing Malware via llms.txt

Researchers observed AI coding agents inside corporate networks following instructions hidden in websites’ llms.txt files, including installing packages that didn’t exist yet. Attackers (or the researchers demonstrating the risk) could then register those package names and have the agents install…

August 28, 2026
Dark Caracal Phishes Tax Lures With SVG Files

Dark Caracal Phishes Tax Lures With SVG Files

Researchers linked a June 2026 intrusion at a communications organization in Venezuela to the Dark Caracal espionage group. The attackers used phishing emails with financial/tax-themed lures and weaponized SVG attachments that redirected victims through URL shorteners to an attacker site hosting…

August 27, 2026
ReliaQuest Hit by Vishing + Fake SSO MFA Push Scam

ReliaQuest Hit by Vishing + Fake SSO MFA Push Scam

ReliaQuest reported a real social-engineering incident where an attacker impersonated a security team member, called employees, and directed them to a fake ReliaQuest SSO login page hosted behind a CDN. One employee entered credentials and approved an MFA push, briefly giving the attacker view-only…

August 27, 2026
Fake “Support” Listing Pushes Tech Scam Calls

Fake “Support” Listing Pushes Tech Scam Calls

A fake “Malwarebytes Support” listing was found on BuzzFeed, apparently designed to trick people into calling a scam phone number. The likely goal is to socially engineer callers into granting remote access and/or paying for bogus support, using the credibility of a trusted platform and well-known…

August 27, 2026
Fake GTA 6 “Demo” Sites Push Password-Stealer

Fake GTA 6 “Demo” Sites Push Password-Stealer

Attackers are using convincing Rockstar Games lookalike websites to trick people into downloading a supposed “GTA 6 demo.” The download is actually Vidar infostealer malware that can steal browser passwords, cookies, and logged-in sessions, potentially exposing personal and work accounts if they…

August 27, 2026
Malicious Site Tricks Claude Auto Mode into Running Code

Malicious Site Tricks Claude Auto Mode into Running Code

A researcher demonstrated that a seemingly harmless “summarize this website” request can be turned into a prompt-injection style attack that pushes Claude Code (Auto Mode) into running commands and ultimately executing attacker code. The workflow uses a fake archive site that forces a tool fallback…

August 27, 2026
Phish Login, Then Add Your Own Google Passkey

Phish Login, Then Add Your Own Google Passkey

Researchers describe a phishing workflow where an attacker logs into a victim’s Google account using stolen password + authenticator code, then quickly enrolls a new passkey to keep access even if the password is changed. The trick relies on victims choosing a weaker sign-in fallback (one-time…

August 26, 2026
AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026
Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026
Apollo Breach Tied to IT Support Impersonation

Apollo Breach Tied to IT Support Impersonation

Apollo Global Management disclosed a data breach after attackers used social engineering to gain unauthorized access to certain cloud platforms over several days in July. The attackers obtained sensitive personal data (including Social Security numbers), highlighting how stolen credentials and…

August 25, 2026
Fake Codex Ad Tricks Mac Users to Paste Malware

Fake Codex Ad Tricks Mac Users to Paste Malware

Attackers used a sponsored search ad to send macOS users to a fake “OpenAI Codex download” page hosted on Google Sites. The page convinced victims to open Terminal and paste a command that secretly downloaded and ran a multi-stage malware infection.

August 25, 2026
npm Mirrors Used for Fake Cloudflare CAPTCHA Phish

npm Mirrors Used for Fake Cloudflare CAPTCHA Phish

Researchers found a real phishing campaign abusing npm packages and unpkg mirrors to host a convincing fake Cloudflare CAPTCHA page on a trusted domain. Victims who click the mirrored link are redirected to attacker-controlled infrastructure that could deliver ClickFix-style prompts or credential…

August 25, 2026
Fake Recruiters Steal Enterprise Logins on Mobile

Fake Recruiters Steal Enterprise Logins on Mobile

A real “fake recruiter” phishing campaign (tracked as RecruitTrap) is targeting employees’ corporate credentials, especially on mobile devices. The scam uses lookalike recruitment domains and full-screen fake login pages that hide browser cues, and it rejects personal email addresses to focus on…

August 25, 2026
Encrypted Prompt Injection Tricks AI Tools

Encrypted Prompt Injection Tricks AI Tools

Researchers demonstrated a prompt-injection method that hides malicious instructions inside encrypted text, then tricks an AI assistant into decrypting it using built-in code tools. In tests, a normal “summarize this page” request could cause Grok to exfiltrate chat data without any click or…

August 25, 2026
Fake Minecraft Clients Push WeedHack Malware

Fake Minecraft Clients Push WeedHack Malware

Attackers are tricking Minecraft players into downloading malware by impersonating popular Minecraft clients and resellers in Google search results. Even after the campaign’s command-and-control infrastructure was taken down, the operation continued by shifting distribution to common file-hosting…

August 25, 2026
Fake GTA 6 “Build” Used to Trick Users Into Malware

Fake GTA 6 “Build” Used to Trick Users Into Malware

A scam is using hype around Grand Theft Auto 6 to trick people into downloading a “leaked, playable build” from torrent sites. The file is mostly junk data, but it contains a small malware payload that tries to weaken Windows Defender and stop security tools, giving attackers control of the…

August 25, 2026
Fake GTA 6 Demo Sites Push Password-Stealing Malware

Fake GTA 6 Demo Sites Push Password-Stealing Malware

The article describes real-world scams riding on the GTA 6 leak hype, including fake “Extended Look” and “demo” websites that deliver password-stealing malware. It also warns about “free early access” offers designed to drain crypto wallets, showing how leaked footage can make these lures more…

August 25, 2026
ReliaQuest Employee Tricked Into Okta SSO Login

ReliaQuest Employee Tricked Into Okta SSO Login

ReliaQuest confirmed an employee was socially engineered into entering their password on a fake SSO page and approving an MFA push, giving attackers a brief “view only” session in the company’s identity dashboard. The attackers allegedly impersonated a named member of the security team over the…

August 25, 2026
Fake “OpenAI Codex” Ads Push Mac ClickFix Malware

Fake “OpenAI Codex” Ads Push Mac ClickFix Malware

Attackers are buying sponsored Google search ads that send Mac developers to fake OpenAI Codex download pages. The pages instruct victims to paste a Terminal command that looks like a normal install step, but actually downloads and runs a multi-stage malware payload.

August 25, 2026
ShinyHunters Impersonation Call Tricked ReliaQuest MFA

ShinyHunters Impersonation Call Tricked ReliaQuest MFA

ReliaQuest disclosed a real social engineering incident where attackers registered a lookalike domain, hosted a fake ReliaQuest SSO page, and called employees while impersonating a named security employee. One employee entered credentials and approved an MFA push, briefly giving the attacker…

August 25, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo