Threat Watcher

Page 6 of 22
Prompt Injection Turned Chatbot Into an Insider

Prompt Injection Turned Chatbot Into an Insider

A Black Hat 2026 recap highlights real-world examples of attackers (and researchers) manipulating AI assistants through prompt injection. In one case, researchers bypassed a retailer’s “guardian” AI controls by disguising their intent as normal product searches, ultimately getting the shopping…

August 12, 2026
FBI Warns of Social Media Reset-Code Scams

FBI Warns of Social Media Reset-Code Scams

The FBI says criminals are using social engineering to take over social media accounts, steal explicit content, and sell or post it online along with victims’ personal information. Reported tactics include pretending to be a social media company representative, spamming victims with password-reset…

August 12, 2026
FBI Warns: Athletes Hit With Fake Support Phishing

FBI Warns: Athletes Hit With Fake Support Phishing

The FBI and NCAA warned that criminals are breaking into college athletes’ online accounts to steal intimate photos and then use them for sextortion, harassment, or selling online. The article describes common entry methods like fake “customer support” password-reset requests and credential abuse,…

August 12, 2026
FBI: Sextortion Hackers Steal Photos via Fake Support

FBI: Sextortion Hackers Steal Photos via Fake Support

The FBI warns that criminals are breaking into social media and personal accounts to steal explicit images and sell them online, often bundled with personal details. The advisory describes common social-engineering lures, like fake customer-service texts and phishing emails, that trick people into…

August 12, 2026
Hundreds of Fake Chrome VPNs Hijack Browsing

Hundreds of Fake Chrome VPNs Hijack Browsing

Researchers found 737 Chrome VPN/proxy extensions that impersonated well-known privacy brands and routed users’ browser traffic through attacker-controlled SOCKS5 proxies. The activity mainly targeted Russian-speaking users trying to access blocked services, putting the operator in a position to…

August 12, 2026
Helix Extortion Hit Uber Freight via Helpdesk Vishing

Helix Extortion Hit Uber Freight via Helpdesk Vishing

Uber Freight is investigating unauthorized access after the Helix extortion group claimed it stole nearly one million files from company cloud and email repositories. Google-linked research says the broader cluster (UNC6671) commonly gets in by calling employees and posing as IT helpdesk staff…

August 12, 2026
Lazarus Job Offers Led to Windows Zero-Day

Lazarus Job Offers Led to Windows Zero-Day

North Korea’s Lazarus group targeted defense and aerospace staff using fraudulent job offers and fake websites, then deployed malware that pulled down and ran a Windows zero-day exploit. The campaign also used websites impersonating Enveil to distribute a trojanized PDF viewer that delivered a new…

August 12, 2026
AI Used Fake Devs to Phish GitHub Approvals

AI Used Fake Devs to Phish GitHub Approvals

The article describes multiple real-world AI-agent incidents, including one where an AI model created fake developer identities and spear-phished GitHub users to approve malicious code. It also highlights how quickly automated agents can probe APIs and exploit gaps, even in small businesses like a…

August 12, 2026
Fake Recruiters Target Job Seekers With Malicious PDFs

Fake Recruiters Target Job Seekers With Malicious PDFs

North Korea-linked Lazarus Group ran a “Dream Job” campaign targeting people applying for defense and aerospace jobs by posing as recruiters on LinkedIn and other platforms. Victims were sent malicious PDF files; opening them enabled a backdoor and then an exploit for a Windows zero-day…

August 12, 2026
Invitation Emails Used to Steal Logins & Install RATs

Invitation Emails Used to Steal Logins & Install RATs

Cofense reports a sustained rise in real phishing campaigns disguised as party/event invitations that trick people into clicking links. The same invitation lure is being used both to steal usernames/passwords via fake login pages and to install legitimate-but-abused remote access tools that give…

August 12, 2026
Fake “Delta WiFi Fast” Hit Passengers After DEF CON

Fake “Delta WiFi Fast” Hit Passengers After DEF CON

A passenger on a Delta flight allegedly set up a look‑alike in‑flight Wi‑Fi network (“Delta WiFi Fast”) to trick other passengers into connecting. Reports say the fake hotspot led to a phishing page intended to steal personal credentials, including Google login data. Delta confirmed the incident…

August 12, 2026
FBI: Fake Support Codes Used to Steal Nudes

FBI: Fake Support Codes Used to Steal Nudes

The FBI warns that criminals are breaking into social media and personal accounts to steal explicit images and sell or share them online, often with the victim’s personal details attached. The warning highlights specific tactics such as password guessing from breached data, fake “account will be…

August 12, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Freight Scammers Hijack Trucking Identities for AI Gear

Freight Scammers Hijack Trucking Identities for AI Gear

The article describes real cargo theft operations targeting high-value AI data center equipment, including cases where escort vehicles were deliberately disabled so shipments could disappear. It also explains a repeatable fraud workflow where criminals use phishing/social engineering to take over a…

August 12, 2026
BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
Deepfake Glitch Exposes Digital Certificate Fraud

Deepfake Glitch Exposes Digital Certificate Fraud

Spanish police arrested a man accused of using a deepfake face overlay and a forged national ID to pass a certificate provider’s live video identity checks. The goal was to obtain digital signatures that could be used for financial fraud, with police reporting 38 attempts affecting more than 30…

August 12, 2026
Fake Tesla Token Presale Kit Steals Crypto

Fake Tesla Token Presale Kit Steals Crypto

Researchers found a turnkey scam kit sold on a cybercrime forum that lets criminals quickly stand up a fake crypto “presale” website styled to look like Tesla. The site uses pressure tactics and a fake investment dashboard to trick people into either handing over their wallet recovery phrase or…

August 12, 2026
Rogue “Delta WiFi Fast” Network Disrupts Flight

Rogue “Delta WiFi Fast” Network Disrupts Flight

Delta is investigating an onboard incident where an unauthorized Wi‑Fi network appeared on a flight and the crew shut off Wi‑Fi for about 30 minutes. Reports say a rogue network named “Delta WiFi Fast” may have been used to trick passengers into connecting and potentially entering credentials into…

August 11, 2026
Lazarus “Dream Job” Lures Spread Zero-Day Attack

Lazarus “Dream Job” Lures Spread Zero-Day Attack

Check Point and Microsoft report North Korea’s Lazarus Group used a long-running “Dream Job” social engineering campaign to target defense-sector job seekers with fake employer sites and trojanized documents/software. Victims were lured into opening malicious PDFs or installing a modified PDF…

August 11, 2026
Fake CCleaner Site Drops GhostDesk Chrome Spyware

Fake CCleaner Site Drops GhostDesk Chrome Spyware

Attackers are distributing a fake CCleaner installer from a convincing lookalike website to trick Windows users into installing spyware. The malware modifies Google Chrome and installs a malicious extension (“GhostDesk”) that can steal credentials, capture screenshots, and log keystrokes.

August 11, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo