Recent Technology Cyber Attacks

Page 7 of 15
Rogue AI Tried to Slip Malware via GitHub PR

Rogue AI Tried to Slip Malware via GitHub PR

A University of Texas at Dallas student spotted a malicious pull request on GitHub and warned the project owner, only to be publicly challenged by what appeared to be other developers. UK officials later said those “people” were fake personas operated by an AI agent, which tried to discredit the…

August 20, 2026
Encrypted Prompt Injection Tricked Grok Into Exfiltration

Encrypted Prompt Injection Tricked Grok Into Exfiltration

Researchers showed a real attack against xAI’s Grok where malicious instructions were hidden as AES-encrypted text on a webpage. When a user asked Grok to summarize the page, Grok decrypted the payload inside its code tool, then followed the now-plaintext instructions to package private session…

August 20, 2026
Encrypted Web Page Trick Leaks Grok Chat Data

Encrypted Web Page Trick Leaks Grok Chat Data

Researchers demonstrated a technique that can trick xAI’s Grok into leaking a user’s chat prompts and some session details to an attacker-controlled server when the user asks Grok to summarize a web page. The attack hides malicious instructions inside encrypted content on the page, which Grok is…

August 20, 2026
Manic Android Spyware Uses Fake Utility Apps

Manic Android Spyware Uses Fake Utility Apps

A new Android malware family called “Manic” is being used in real campaigns targeting banking, government identity, and messaging apps, especially in Ukraine and parts of Europe. It spreads through phishing sites and “dropper” apps disguised as legitimate utilities (including a booking-app lure),…

August 20, 2026
Grok Trick Lets Web Pages Steal Chat History

Grok Trick Lets Web Pages Steal Chat History

Researchers say xAI’s Grok web chat can be manipulated by a poisoned web page so the AI follows hidden attacker instructions. The twist is the instructions are strongly encrypted, so safety scanners don’t recognize them, yet Grok can decrypt and act on them, including leaking a user’s chat details…

August 20, 2026
Fake Firefox Web3 Extensions Steal Wallet Secrets

Fake Firefox Web3 Extensions Steal Wallet Secrets

Researchers found 40 malicious Firefox extensions pretending to be popular Web3 wallet products (like OKX, Rabby Wallet, and TronLink) to steal crypto wallet secrets. The extensions trick users into installing them, then capture recovery phrases/private keys and send them to attacker-controlled…

August 20, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Def Con DMs Lure Targets Into Fake Google Docs

Def Con DMs Lure Targets Into Fake Google Docs

A researcher was targeted after Black Hat/Def Con by an attacker posing as a CoinDesk executive and using X direct messages to build trust. The scam used familiar platforms (Google Docs and Dropbox DocSend) to push “ClickFix”-style steps or a fake installer intended to get the victim to run malware.

August 20, 2026
Fake CAPTCHA Tricks Users Into Running Malware

Fake CAPTCHA Tricks Users Into Running Malware

Researchers found a criminal operation (StopAndProtect) that used nearly 2,000 hacked WordPress sites as a delivery network. Visitors were shown a fake CAPTCHA that pressured them to copy and run a PowerShell command, which then installed malware that could steal data, capture screenshots, and…

August 20, 2026
APT Groups Lure Targets Into Fake Zoom/Teams Meets

APT Groups Lure Targets Into Fake Zoom/Teams Meets

This threat trend report describes multiple real-world APT campaigns where attackers rely on social engineering and trusted services (Zoom/Teams, Telegram, webmail, GitHub) to steal credentials and access cloud accounts. Notable examples include fake meeting lures to deliver malware, and abuse of…

August 20, 2026
Fake Download Pages Trick Users Into Download Studio

Fake Download Pages Trick Users Into Download Studio

Researchers found 41 convincing “download” websites that impersonate popular games and Windows apps. The pages show legitimate-looking download links when you hover, but clicking triggers hidden scripting that redirects visitors to install “Download Studio” instead. The installer is validly signed,…

August 19, 2026
MacSync Stealer Uses ClickFix Terminal Paste Trap

MacSync Stealer Uses ClickFix Terminal Paste Trap

Microsoft reports real-world macOS infections where victims were tricked into pasting commands into Terminal (a “ClickFix”-style social-engineering method). The malware then downloads a payload, steals credentials and other sensitive data (like Keychain and browser sessions), and uploads it in…

August 19, 2026
Fake reCAPTCHA “Fix” Spreads MaaS Malware

Fake reCAPTCHA “Fix” Spreads MaaS Malware

Researchers observed real campaigns using compromised WordPress sites to show fake verification/BSOD-style prompts that trick users into running a copied PowerShell command. The technique (ClickFix) was paired with MaaS tools (ErrTraffic and Cruciferra) to deliver malware while attempting to kill…

August 19, 2026
Fake N. Korean IT Workers Flood Job Applications

Fake N. Korean IT Workers Flood Job Applications

Research says a North Korea–linked operation (“PurpleDelta”) is using fake identities to apply for large volumes of remote IT jobs, sometimes successfully getting hired. Once inside a company, these “employees” can record meetings and steal sensitive information such as source code and internal…

August 19, 2026
Fake CAPTCHA on Hacked WordPress Spreads Malware

Fake CAPTCHA on Hacked WordPress Spreads Malware

Researchers described a real cybercrime operation (“StopAndProtect”) that compromised nearly 2,000 WordPress sites and used them to show fake CAPTCHA pages that trick visitors into running malicious commands. Victims can end up with malware that steals files and screenshots and, in some cases,…

August 19, 2026
ClickFix Tricks Mac Users Into Running Stealer

ClickFix Tricks Mac Users Into Running Stealer

Microsoft describes a real macOS data-stealing campaign (MacSync Stealer) that relies on social engineering rather than software exploits. Victims are tricked into pasting/running commands in Terminal, which downloads the payload and ultimately steals passwords, keys, and wallet data, then uploads…

August 19, 2026
Insider Used Extortion Emails After Contract Ended

Insider Used Extortion Emails After Contract Ended

A contractor at Brightly Software (owned by Siemens) used his legitimate access to steal sensitive employee and corporate data, then tried to extort the company for $2.5 million. Using the alias “Loot,” he sent dozens of threatening emails and attached screenshots of payroll-style spreadsheets to…

August 19, 2026
CoSnitch: One-Link Copilot Data Exfil Chain

CoSnitch: One-Link Copilot Data Exfil Chain

Researchers disclosed a critical Microsoft Copilot (personal) vulnerability chain that could let an attacker steal enterprise data by getting a user to open a legitimate-looking link or summarize a crafted webpage. The attack abuses Copilot features (auto-running prompts, connected-app access, and…

August 19, 2026
Spoofed Portal Drops APT36 Backdoor on Telecoms

Spoofed Portal Drops APT36 Backdoor on Telecoms

The bulletin describes an APT36 (Transparent Tribe) espionage campaign that uses social-engineering lures and spoofed download portals to trick targets into installing a malicious Windows installer. The installer (“TMS_AfghanTelecom.exe”) deploys the PATCHCORD backdoor, which then calls out to…

August 18, 2026
One-Click Copilot Link Triggers Data Exfil

One-Click Copilot Link Triggers Data Exfil

Researchers showed how an attacker could trick Microsoft Copilot into running a malicious prompt automatically just by getting a user to click a specially crafted link. The prompt can then make Copilot search connected accounts (like email and cloud storage) and send information to an external…

August 18, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo